Back to knowledge base

Dutch Cybersecurity Act final: NIS2 applies in the Netherlands from 15 August 2026

Published on July 7, 2026 · Updated on August 4, 2026

This article is general information about laws and regulations, not legal advice.

It is final. On 7 July 2026 the Dutch Senate adopted the Cybersecurity Act (Cyberbeveiligingswet) and the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten), and the government has set the entry into force at 15 August 2026. The era of target dates and caveats is over: NIS2 becomes enforceable law in the Netherlands, with 15 August as a hard date. Still seeing 1 July 2026 mentioned somewhere? That target date has lapsed: the Cybersecurity Decree sets the entry into force at 15 August.

What exactly enters into force?

Two acts at the same time:

  • The Cybersecurity Act (Cbw) implements the European NIS2 directive and replaces the Network and Information Systems Security Act (Wbni). The act affects more than 8,000 organisations across 18 sectors, including energy, drinking water, digital infrastructure, healthcare, government and transport.
  • The Critical Entities Resilience Act (Wwke) implements the European CER directive and focuses on the physical resilience of around 500 critical entities.

The Cybersecurity Act distinguishes two categories: essential entities (large organisations in the most critical sectors, subject to proactive supervision) and important entities (supervised mainly after the fact, following an incident or signal). Roughly: large organisations in the most critical sectors (Annex I) are essential; medium-sized organisations in those sectors and organisations in the remaining sectors are important, although the government's self-assessment tool ultimately determines your own classification. The act in principle applies to organisations in the designated sectors from 50 employees or more than 10 million euros in annual turnover or balance-sheet total, but some categories are covered regardless of size, such as DNS service providers, trust services and government organisations. So even a small organisation can be in scope.

Alongside the act, the Cybersecurity Decree (Cyberbeveiligingsbesluit) enters into force (Staatsblad 2026, 189, published on 10 July 2026). That governmental decree fleshes out the duty of care in concrete terms: which risk-management measures you must take at a minimum and how the reporting procedure works. So anyone who wants to know what "appropriate and proportionate" means in practice should read above all the decree, alongside the act itself.

With more than 8,000 organisations under the Cbw versus around 500 critical entities under the Wwke, the Cybersecurity Act is by far the relevant act for most organisations (and certainly for their suppliers).

Which obligations apply from 15 August?

From the entry into force, organisations under the Cybersecurity Act must comply with:

  • Registration obligation. Register in the entity register via the NCSC (mijn.ncsc.nl). Registration is already open; see the registration obligation at the NCSC.
  • Duty of care. Appropriate and proportionate measures to manage security risks and prevent incidents, explicitly including supply-chain security. The Cybersecurity Decree fleshes this out in concrete categories of measures, including:
    • risk analysis, assessment and treatment;
    • incident handling (detection, analysis and recovery);
    • business continuity, backups and crisis management;
    • supply-chain security, including vetting of suppliers;
    • basic cyber hygiene and staff training, plus policies for encryption and access control.
  • Reporting obligation. Report significant incidents to the CSIRT and the competent authority, via a single central portal at mijn.ncsc.nl. As a general rule: an early warning within 24 hours, an incident notification within 72 hours and a final report no later than one month after that incident notification (the deadlines from Article 23 of the NIS2 directive, as implemented in the Cbw); for a few categories, including the financial sector and trust services, deviating and in part shorter deadlines apply. See also the reporting obligation at the NCSC.
  • Board accountability. The board approves the measures, oversees them and follows appropriate training.
  • Supervision and enforcement. Supervision is organised by sector: among others the RDI (digital infrastructure and various other sectors), the IGJ (healthcare), the ILT (transport) and DNB and the AFM (financial sector). The NCSC operates the central reporting portal at mijn.ncsc.nl; a report filed there is passed on in one go to the sectoral CSIRT and the competent supervisor (the NCSC itself is not a supervisor). Supervisors are authorised to inspect from the entry into force.

There is no general transition period: the Cybersecurity Decree sets the entry into force of the act and the decree at 15 August 2026. One exception: publicly funded higher education is expected to be formally designated in the winter of 2026. Most obligations then take effect; the duty of care follows three years after that designation. Registration and voluntary reporting are already possible today.

What is at stake?

The maximum fines are substantial: for essential entities up to 10 million euros or 2% of global annual turnover (whichever is higher), for important entities up to 7 million euros or 1.4%. Fines are not the only instrument, either: the supervisor can also issue binding instructions and impose an order subject to periodic penalty payments, and for essential entities it can, as a last resort, request the suspension of board members (the latter does not apply to government bodies). In addition, the act places responsibility explicitly with the board, which must approve the measures and can be held to account for them. See NIS2 and director liability.

What does this mean for suppliers?

For many SMEs, this is the real news. The duty of care explicitly covers the supply chain: the more than 8,000 organisations under the act must be able to demonstrate that they manage the risks posed by their suppliers. In practice, that often translates into supplier questionnaires, contract requirements and audits. Bear in mind the difference between these forms of evidence: a completed questionnaire is a supplier's own declaration, a certificate is a snapshot established by an auditor, and an external measurement shows what an attacker sees right now. That measurement complements the questionnaire and the certificate.

If you supply software, hosting, data or services to an organisation covered by the act, chances are that request will land on your desk, even if you formally fall outside the scope yourself. What is expected of you is covered in what is actually required under the NIS2 supply-chain duty of care and, specifically for suppliers, in NIS2 supply-chain duty of care for suppliers. Already receiving questionnaires? Then answering a NIS2 supplier questionnaire helps.

What the act does not do

Even with a hard date, what we wrote earlier still holds: the act mandates no specific tool or SaaS whatsoever. Anyone using the entry into force to sell a product as "legally required" is selling urgency instead of facts. The act requires goals: know your risks, take measures, report incidents and be able to demonstrate all of it. How you meet those goals is up to you. Why even a good scan does not make you compliant is explained in scanning is not NIS2 compliance.

Five things to arrange before 15 August

  1. Determine your position. Do you fall directly under the act (sector plus size), or indirectly via customers that do? Use the Dutch government's self-assessment tool, check which sectors and organisations are covered at the NCSC, or start with our self-check do I fall under NIS2.
  2. Register. If you fall under the act, register your organisation in the entity register via mijn.ncsc.nl. The obligation applies from 15 August; registration is already open.
  3. Map your attack surface. You cannot manage risks you do not see. Start with what an attacker sees of your domain.
  4. Include your chain. Inventory critical suppliers and record which baseline requirements you set for them. See how to monitor this at Monitor my suppliers.
  5. Make it demonstrable. Make sure you can show what was found, when, and what happened with it. There are two ways to demonstrate compliance: administratively (certificates, statements) and technically (dated external measurements). That evidence is what a regulator, auditor or customer wants to see.

Exposentry helps with steps 3 to 5: continuous, demonstrable monitoring of your own domains and your supplier chain. Exposentry builds on OpenKAT, the open-source security scanner that originated within the Dutch government; Edward Hasekamp himself contributes to OpenKAT. Not a compliance guarantee, but a demonstrable building block for your duty of care. You can see where you stand today: start a scan of your organisation.

Sources

  • Rijksoverheid, "Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf 15 augustus 2026 van kracht", 7 July 2026, rijksoverheid.nl
  • Dutch Senate (Eerste Kamer), legislative proposal 36.764 (Cyberbeveiligingswet), eerstekamer.nl
  • Cybersecurity Act (Cyberbeveiligingswet), Staatsblad 2026, 187, 10 July 2026, officielebekendmakingen.nl
  • Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten), Staatsblad 2026, 188, 10 July 2026, officielebekendmakingen.nl
  • Cybersecurity Decree (Cyberbeveiligingsbesluit), Staatsblad 2026, 189, 10 July 2026 (Article 35 also sets the date of entry into force of the Cybersecurity Act), officielebekendmakingen.nl
  • Houthoff, "Cyberbeveiligingswet vanaf 15 augustus van kracht", July 2026, houthoff.com
  • SURF Security Expertise Centrum, "Cyberbeveiligingswet: stand van zaken, planning en gevolgen voor hoger onderwijs", sec.surf.nl

Written by Edward Hasekamp, founder of Exposentry and collaborator on the open-source OpenKAT project. See the project on GitHub and the profile at github.com/hasecon. Exposentry provides EU-sovereign, forensically substantiated vulnerability monitoring based on OpenKAT. More articles in the Knowledge base.