Skip to content

NIS2 and the Dutch Cybersecurity Act

NIS2: know where you stand and what to arrange

Since 15 August 2026 the Cyberbeveiligingswet, the Dutch implementation of the European NIS2 directive, has applied in the Netherlands. Does NIS2 apply to you, or is a customer asking about it? We help you step by step, from risk analysis to incident reporting.

What is NIS2?

A European directive for digital resilience

NIS2 stands for Network and Information Security Directive 2. It is a European directive that makes organisations in important sectors digitally stronger. The first NIS directive covered a small group of vital providers. NIS2 covers 18 sectors and medium-sized organisations as well. In the Netherlands the directive has been transposed into the Cyberbeveiligingswet (Cbw), which replaces the previous Dutch act on network and information systems. As a result, thousands of organisations now have legal requirements for their cybersecurity. The good news: many of those requirements are simply good IT management, and you can arrange them step by step.

  • Clarity on whether your organisation falls under the Dutch act
  • A risk analysis and a plan that fits your organisation
  • Measures we set up, manage and maintain ourselves
  • A reporting procedure, so everyone knows what to do in an incident
An Infodatek Group consultant standing in the office, between the workstations.

At a glance

In force
The Cyberbeveiligingswet has applied in the Netherlands since 15 August 2026.
Three duties
Registration, duty of care and incident reporting, with a clear role for the board.
Our help
Smart Compliance: from the first check to management, documentation and reporting.

Who does it apply to?

Does NIS2 apply to my organisation?

Whether NIS2 applies to you depends on two things: your sector and the size of your organisation. The law covers 18 sectors, such as energy, transport, healthcare, drinking water, digital infrastructure, ICT service management, public administration, postal and courier services, waste management, chemicals, food and part of the manufacturing industry.

Broadly speaking, it concerns medium-sized and large organisations: from 50 employees, or with an annual turnover and balance sheet total above 10 million euros. For a few types of organisation, size does not matter. The exact test has its complications, for example in a group with several legal entities. Each organisation has to determine this for itself. The RDI, the Dutch digital infrastructure inspectorate and one of the supervisors, offers a self-assessment on its website.

Not covered yourself? You may still deal with it as a supplier. Organisations covered by NIS2 also have to secure their supply chain, and they increasingly ask suppliers to show that their security is in order.

The three duties

What do you need to arrange under NIS2?

The Dutch act revolves around three duties. They sound heavy, but in practice they cover things many organisations already partly do. The difference is that you now record them, keep them up to date and can show them.

  • Registration: you enter your organisation in the national entity register of the NCSC, the Dutch National Cyber Security Centre, through the MijnNCSC portal with eHerkenning. You then keep your details up to date.
  • Duty of care: you carry out a risk analysis and take appropriate measures, from incident handling and backup to secure suppliers, secure sign-in and an encryption policy.
  • Incident reporting: you report a significant incident to your CSIRT and the supervisor within 24 hours of discovering it. Not every small problem needs to be reported.
  • Board: management approves the measures, oversees their implementation and takes appropriate training.

Smart Compliance

From risk analysis to reporting: how we help

With Smart Compliance we guide you through the entire Dutch act. You do not need a lawyer or security specialist in house. We translate the law into concrete steps for your organisation and carry out many of those steps ourselves.

Infodatek is itself ISO 27001 and NEN 7510 certified. So we know from our own experience how to document information security, put it into practice and keep improving it.

  • Check: does the law apply to your organisation, directly or through the supply chain?
  • Registration: we prepare the details for the entity register with you
  • Risk analysis: we map out what matters most and where the risks are
  • Measures: from MFA and updates to backup, monitoring and supplier agreements
  • Reporting procedure: a clear incident plan, including who reports what within 24 hours
  • Board: explanation and training, so management knows what is going on

NIS2 as an opportunity

A solid foundation for your organisation

NIS2 gives you more than a tick in a box. You know better what is happening in your IT, your supplier agreements are clear and your team knows what to do when something happens. That brings peace of mind, for management too.

Customers and supply chain partners notice it as well. Demonstrably good security strengthens your position in tenders. And because we can also manage your IT, it does not stop at a report: the measures are actually carried out and maintained. If you want everything in one agreement, you end up at Digital Care, where management and security come together.

Who is affected

Organisations that deal with NIS2

The Dutch act affects many more organisations than the previous law. A few examples, directly or through their customers.

Healthcare

Healthcare providers of medium size and larger fall under the healthcare sector. Infodatek is NEN 7510 certified, the Dutch standard for information security in healthcare. That foundation also helps with NIS2.

Manufacturing and food

Manufacturers of machinery, electronics, electrical equipment, vehicles and medical devices, among others, fall under the law, as do companies in chemicals and food. Both the office and production then need demonstrably good security.

Energy, water and waste

Organisations in energy, drinking water, waste water and waste management provide services that many people rely on every day. For them, the continuity of systems and IT is at the heart of the duty of care.

ICT and digital services

Managed service providers, data centres, cloud providers and digital providers such as online marketplaces fall under the law. They often manage other organisations' IT, so their security counts for even more.

Suppliers

Even if the law does not apply to you, a customer can still set requirements. Organisations covered by NIS2 have to secure their supply chain. A supplier that can demonstrate its security is then a welcome partner to work with.

Frequently asked questions

Frequently asked questions about NIS2

How can I be sure whether NIS2 applies to my organisation?

Start with your sector and your size. If your activity falls within one of the sectors in the law and you have 50 or more employees, or a turnover and balance sheet total above 10 million euros, the law very likely applies to you. The RDI offers a self-assessment on its website. If you are unsure, for example in a group structure, we are happy to go through it with you.

What is the difference between an essential and an important entity?

That depends on your sector and your size. Large organisations in the most critical sectors are usually essential, and the other organisations covered by the law are important. The duties are largely the same for both: register, ensure appropriate security and report significant incidents. The difference lies mainly in supervision. For essential entities the supervisor also checks in advance, for important entities mainly afterwards.

What should I do first?

Establish whether the law applies to you and, if so, register your organisation through MijnNCSC. Then carry out a risk analysis: what are your most important systems and data, and what is needed to protect them properly? Present the outcome to the board and draw up a plan with priorities. That way you work in manageable steps rather than doing everything at once.

When do I have to report an incident?

Only significant incidents fall under the reporting duty: incidents that seriously disrupt your services or have a considerable impact on others. Thresholds have been set for this per sector. You make an initial report to your CSIRT and the supervisor within 24 hours of discovery. After reporting, you can also count on help and information. We set out the procedure in advance, so everyone knows what to do.

Does ISO 27001 help with NIS2?

Yes, considerably. ISO 27001 is a standard for information security built on a risk analysis, policy and measures that you keep improving. That fits well with the duty of care. The law does not require an ISO certificate, and you can meet NIS2 without ISO too. Infodatek is itself ISO 27001 and NEN 7510 certified and knows how to keep such a system practical and workable.

Can you carry out the measures yourselves as well?

Yes, we do not stop at advice. Because we also provide IT management and Cybersecurity, we can set up, monitor and maintain the measures. Think of MFA, updates, backup and recovery, logging and access management. You get the documentation with it, so you can show customers, auditors and supervisors what has been arranged.

Wondering what Infodatek can do for you?

A thirty-minute call with one of our specialists. Your environment, your questions. An honest conversation.

An Infodatek Group colleague picking up the handset of a desk phone.