Back to knowledge base

What is actually required under the NIS2 supply-chain duty of care (and what is not)?

Published on June 16, 2026 · Updated on August 16, 2026

This article is general information about laws and regulations, not legal advice.

A lot of half-truth circulates around NIS2. That there is a "government-mandated, official tool". That you should have been compliant since some already-passed date. That a single SaaS subscription makes you "NIS2-proof" in one click. None of those three are true, and precisely because they are not, organisations sometimes make decisions out of fear.

This article sets the record straight. What does NIS2, and the supply-chain duty of care specifically, actually require of you? What is the status of the law in the Netherlands? And where does continuous monitoring fit into that picture as a defensible building block?

In short

  • NIS2 does not mandate any specific, named tool or "official SaaS". The law requires appropriate and proportionate measures. How you implement them is up to you.
  • The Dutch law enters into force on 15 August 2026. The Senate adopted the Cybersecurity Act (Cyberbeveiligingswet) on 7 July 2026. From 15 August 2026 the registration, duty-of-care and incident-reporting obligations apply in full; there is no transition period.
  • The supply-chain duty of care affects many more organisations than you think. Even if you do not fall directly under NIS2, you can be pulled in via your customers.
  • Compliance is an organisation-wide package of policy, processes, technology, governance and chain agreements. Continuous vulnerability monitoring is one important, demonstrable building block of it.

NIS2 and the Cybersecurity Act: what is what

It helps to keep two things apart.

NIS2 is the European directive (Network and Information Security Directive 2). A directive does not apply directly; each member state transposes it into its own legislation. At EU level, NIS2 has applied since 17 October 2024, the directive's transposition deadline.

The Cybersecurity Act (Cyberbeveiligingswet, Cbw) is the Dutch implementation of it. It replaces the current Network and Information Systems Security Act (Wbni). The Netherlands missed the original EU deadline of October 2024. The bill was submitted in 2025, adopted by the House of Representatives in April 2026 and by the Senate on 7 July 2026. The act enters into force, together with the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten), on 15 August 2026. What that means in practice is covered in our overview of the entry into force.

In short: the obligations are concrete in substance and now also have a hard date. What remains untrue is that this makes any specific tool mandatory. Anyone claiming that is selling urgency.

What exactly is the supply-chain duty of care?

This is the core of why NIS2 fans out so much more broadly than many organisations expect.

Essential and important entities that fall under NIS2 must have their own security in order and factor the security of their suppliers and supply chain into their risk management. That is the supply-chain duty of care: managing risks that enter via third parties. Its legal basis is NIS2 Article 21(2)(d), which explicitly names "supply chain security" as a measure.

The result is a cascade. Do you not fall directly under NIS2 yourself, but supply software, infrastructure, data or services to an organisation that does? Then that customer will want to be able to demonstrate that you have your basic security in order. In practice that comes back in contract requirements, supplier questionnaires and audits. If you do not comply, you run a real risk of losing the contract: your customer has to be able to substantiate its own duty of care.

That does not mean a large customer may demand everything without limit. Article 21(2)(d) calls for appropriate and proportionate measures, geared to the actual risk and to your role in the chain. A supplier of non-critical marketing services should face a lighter request than a party that hosts core systems or processes sensitive data. Proportionality thus cuts both ways: it justifies what a customer may reasonably ask, and it bounds what you have to provide without cause.

That is why NIS2 indirectly affects an estimated tens of thousands of SME suppliers that formally fall outside the direct scope. How this plays out in practice for suppliers, and what your large customer expects of you exactly, is covered in NIS2 supply-chain duty of care for suppliers.

What NIS2 does require

For organisations within scope, it essentially comes down to a number of obligations:

  • Duty of care (risk management). Appropriate and proportionate technical, operational and organisational measures. Think of risk analysis, access security and MFA, incident handling, business continuity, supply-chain security, and dealing with vulnerabilities.
  • Reporting obligation. Report significant incidents within tight deadlines: an early notification within 24 hours, a fuller report within 72 hours and a final report within a month.
  • Registration obligation. Entities covered by the law must register with the competent authority (in the Netherlands this runs via the NCSC).
  • Board accountability. The board must approve the measures and oversee them, with a training obligation and personal accountability.

Important: the law prescribes goals, not products. You are free in how you implement the measures.

What NIS2 does not require: the persistent myths

Myth 1: "There is an official, government-mandated tool or SaaS."

Incorrect. NIS2 and the Cybersecurity Act do not name any commercial product as a mandatory standard. You may choose for yourself how you meet the requirements: self-host open source, take a service, or a combination. A provider that presents itself as "the official platform of the ministry" makes a claim the law does not support.

Myth 2: "It has been mandatory since [a fixed, early date]."

Incorrect for any date before 15 August 2026. The Dutch law enters into force on 15 August 2026; anyone naming an earlier domestic deadline is wrong. At EU level NIS2 has indeed applied since 17 October 2024, but that is something other than a domestic tool obligation as of a specific date.

Myth 3: "One tool makes you compliant."

Incorrect. Compliance is an organisation-wide package: policy, processes, technology, governance and chain agreements. No single standalone product covers all of that. Anyone who sells it that way is selling false security. Why even a good scan does not make you compliant (and is indispensable nonetheless) is explained in scanning is not NIS2 compliance.

Myth 4: "ISO 27001 automatically makes you NIS2-compliant."

Incorrect. A certification like ISO 27001 can help demonstrate that your measures are in order and saves work when a request comes in, but in itself it is not a legal capstone: NIS2 grants no automatic equivalence. Also stay alert to quality marks or "NIS2 certificates" that have no legal status.

The pattern behind these myths is always the same: a real obligation is inflated into a ready-made product with a deadline. The antidote is simple: ask exactly what the claim is based on.

So where does continuous monitoring fit in?

If no tool makes you "compliant", why invest in vulnerability monitoring at all? Because it is one of the most concrete, demonstrable ways to fulfil the risk-management and supply-chain parts of your duty of care.

The duty of care requires that you know and manage your vulnerabilities. You cannot tick that off once; your attack surface changes continuously. Continuous monitoring shows that you do this structurally, and that is exactly what an auditor, a customer or an insurer wants to see.

The difference lies in evidence. Being able to show in a forensically substantiated way how and when a vulnerability was detected and followed up. This is where paper meets measurement: a completed questionnaire or a certificate shows on paper that you have arranged something, whereas an external measurement technically proves that it actually holds right now. That burden of proof makes a duty of care defensible. If you receive such a request from a customer yourself, answering a NIS2 supplier questionnaire helps you put that evidence concretely on the table.

Exposentry is built for this: EU-hosted, forensically substantiated monitoring based on OpenKAT, the open-source security scanner from the Dutch government, for your own domains and your supplier chain. Founder Edward Hasekamp contributes to OpenKAT itself as a collaborator. It is a necessary building block for your vulnerability management and supply-chain duty of care; compliance itself remains a broader, organisation-wide package. That honesty is deliberate: anything that presents itself as a total solution deserves extra suspicion.

Practical: how to substantiate your supply-chain duty of care with evidence

  1. Determine your position. Do you fall directly under NIS2 (sector + usually 50+ employees), or indirectly via customers that fall under it themselves? Both require action, but at a different level.
  2. Map your attack surface. Which domains, systems and assets are visible from the outside? Protection begins with knowing what of yours is exposed to the internet: start with what an attacker sees of your domain.
  3. Monitor continuously and record evidence. Continuous visibility, with a record of what was found and when.
  4. Include your chain. Monitor the basic security of suppliers for which you bear responsibility, and make agreements you can substantiate.
  5. Document and report. Translate technical results into clear reports you can present to the board, an auditor or a customer.

Frequently asked questions

Is NIS2 already mandatory in the Netherlands? The European NIS2 directive has applied at EU level since 17 October 2024. The Dutch Cybersecurity Act, which transposes the directive into national obligations, was adopted by the Senate on 7 July 2026 and enters into force on 15 August 2026. From that date the registration, duty-of-care and incident-reporting obligations apply in full.

Does NIS2 prescribe a specific tool or SaaS? No. NIS2 and the Cybersecurity Act require appropriate and proportionate measures, but name no mandatory product. You decide for yourself how you meet the requirements.

My organisation does not fall under NIS2. Do I still have to do something? Possibly. If you supply organisations that do fall under it, they can, via their supply-chain duty of care, require you to demonstrably have your basic security in order. Failing to comply can cost a contract.

Does one scan or one tool make me compliant? No. Compliance is an organisation-wide package of policy, processes, technology, governance and chain agreements. Continuous monitoring is an important, demonstrable building block of it.

What is the difference between NIS2 and the Cybersecurity Act? NIS2 is the European directive; the Cybersecurity Act is the Dutch law that implements this directive. The Dutch law can be more specific or stricter than the directive on certain points.

When should I start? Now. The law enters into force on 15 August 2026 and organisations often need several months to bring their security and supplier management up to standard. Those months are no longer available, so start with the basics today.

Written by Edward Hasekamp, founder of Exposentry and collaborator on the open-source OpenKAT project. See the project on GitHub and the profile at github.com/hasecon. Exposentry provides EU-sovereign, forensically substantiated vulnerability monitoring based on OpenKAT. More articles in the Knowledge base.