The Dutch cybersecurity act is here. Now what?
August 18, 2026
On 15 August 2026 the Dutch cybersecurity act, the Cyberbeveiligingswet, took effect. It is the Dutch implementation of the European NIS2 directive. There is no transition period. The law simply applies.
If you are reading this and wondering whether it applies to you, that is a fair question. According to the Dutch NCSC the law covers just over eight thousand organisations directly. The number of companies that will feel it is a lot higher, because those eight thousand have to bring their suppliers along.
Are you in scope?
Two things decide it, and both have to be true.
Your sector. The law lists eighteen sectors across two annexes. Annex 1 holds eleven highly critical sectors such as energy, drinking water, digital infrastructure, healthcare and transport. Annex 2 holds seven more, including postal services, waste, chemicals, food and digital providers.
Your size. The NCSC puts it plainly: you are in scope if you have fifty or more staff in FTE, or if you have fewer than fifty but both your annual turnover and your balance sheet total exceed ten million euro.
There is an exception to that second rule that often gets missed. Several kinds of organisation are in scope regardless of size: providers of public electronic communications networks and services, trust service providers, top-level domain name registries, DNS service providers, domain name registration services and government bodies. So a three-person outfit registering domain names is in scope.
If you are covered, you land in one of two buckets. Essential entities are under proactive supervision, meaning compliance is actively checked even without any sign that something is wrong. Important entities fall under reactive supervision, so someone looks only after a signal or an incident. The difference is in the supervision, not in what you have to do. Those duties are identical.
Working out which bucket you are in is harder than it sounds, especially with a group structure. The Dutch regulator RDI publishes a self-assessment for exactly this, and the NCSC calls it the fastest route to an answer. Run that before you start reasoning internally.
The duty of care is ten measures
This is the part people find vague, while it is simply written down. The NCSC lists ten measures.
Two things stand out. Measure four covers your supply chain, and that is why this law reaches far beyond those eight thousand organisations. Measure ten asks you to assess whether your measures actually work, which is a different thing from setting them once.
What the list does not say is how to do any of it. That is deliberate. You decide which implementation fits, and the basis for that is your risk assessment. Which is not by accident measure one.
Reporting happens in three steps
This is where I see the most confusion. It is not one report within 24 hours, it is three.
- Within 24 hours, an early warning. You state whether the incident is likely malicious and whether there is cross-border impact.
- Within 72 hours, the actual report. You update the warning with a first assessment of severity and impact.
- Within one month, a final report covering the incident, the cause and the measures you took. If the incident runs longer than a month, you submit a progress report at that point instead.
Reporting goes through MijnNCSC, which is friendlier than it sounds: one report reaches both your sector CSIRT and your regulator at once. So you do not have to work out who to call first.
The clock starts when you become aware of the incident. Twenty-four hours is short. It is not a deadline you want to be figuring out in the moment, so write down now who calls and where.
Nobody registers for you
If you are in scope, you register your organisation in the national entity register through MijnNCSC. That registration duty has applied since 15 August 2026. No letter is coming, no reminder is coming, and it is your own responsibility.
And if you fall just outside
Then you are probably a supplier to someone who is in scope. That customer has to have a grip on their chain, and the only way they can show it is by asking you. The next article is about exactly that.
What you can do this month
Four things, none of which needs a consulting engagement.
- Run the RDI self-assessment and keep the outcome. "We are not in scope" is also an outcome you want to be able to show.
- If you are in scope, register. It is the one item with a deadline that has already passed.
- Put on one page who calls during an incident, who decides, and which three deadlines are running. That is your first piece of duty of care and it takes half an hour.
- Look at what is actually switched on in your own environment. Not what your policy says, but what the settings say. That gap is usually the real work, and it is exactly what we measure continuously against NIS2 and four other standards.
Compliance is not really about writing a manual. It is about being able to show that what you say you do is genuinely switched on.
Sources
All sources were consulted on 8 September 2026. The Dutch government sources are published in Dutch only.
Nationaal Coördinator Terrorismebestrijding en Veiligheid. (2026). Welke organisaties vallen onder de Cyberbeveiligingswet? https://www.nctv.nl/onderwerpen/c/cyberbeveiligingswet/welke-organisaties-vallen-onder-de-cyberbeveiligingswet
Nationaal Coördinator Terrorismebestrijding en Veiligheid. (2026). Registratieplicht. https://www.nctv.nl/onderwerpen/c/cyberbeveiligingswet/registratieplicht
Nationaal Cyber Security Centrum. (2026). Cyberbeveiligingswet (NIS2). https://www.ncsc.nl/cyberbeveiligingswet-nis2
Nationaal Cyber Security Centrum. (2026). Valt mijn organisatie onder de Cyberbeveiligingswet (NIS2)? https://www.ncsc.nl/cyberbeveiligingswet-nis2/valt-mijn-organisatie-onder-de-cyberbeveiligingswet-nis2
Nationaal Cyber Security Centrum. (2026). Zorgplicht. https://www.ncsc.nl/cyberbeveiligingswet-nis2/zorgplicht
Nationaal Cyber Security Centrum. (2026). Meldplicht. https://www.ncsc.nl/cyberbeveiligingswet-nis2/meldplicht
Rijksinspectie Digitale Infrastructuur. (2026). NIS2-Zelfevaluatie NL. https://regelhulpenvoorbedrijven.nl/NIS-2-NL/
Rijksoverheid. (2026, July 7). Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf 15 augustus 2026 van kracht. https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht
