Direct naar inhoud
Back to Insights
Security

The Dutch Cybersecurity Act has applied since 15 August 2026: what to arrange now

4 June 2026Updated on 5 October 2026Mohammad MoghtaderMohammad Moghtader

Mohammad Moghtader — CTO of Virtual Computing

Cyberbeveiligingswet NIS2 geldt sinds 15 augustus 2026: verplichtingen en voorbereiding voor het MKB

Update 5 October 2026: the Cyberbeveiligingswet entered into force on 15 August 2026 and we have updated this article accordingly.

It took a long time, but then things moved fast. On 15 April 2026 the Dutch House of Representatives passed the Cyberbeveiligingswet (Cybersecurity Act), the Dutch implementation of the European NIS2 directive. The Senate approved it on 7 July 2026 and the law has applied since 15 August 2026. No more "that law will arrive someday": this is happening now.

In this article we cover what the law entails, how to determine whether your organisation falls under it (the answer is "yes" more often than you might think) and the five measures you want in place regardless — law or no law.

We covered the basics of NIS2 — which sectors, which company sizes — in does your business fall under the NIS2 directive? This article focuses on the current status and practical preparation.

From European directive to Dutch law

NIS2 is a European directive and does not apply directly: each member state must transpose it into national legislation. That should have happened by 17 October 2024 — the Netherlands is over eighteen months late. That delay lulled many businesses to sleep: the obligations always seemed like something for later.

That postponement is now over. The law has passed both the House and the Senate and has applied since 15 August 2026. Businesses that waited for "final clarity" now have it, but no preparation time left: the duty of care has applied from day one.

Does it apply to you? The two questions to ask

Question 1: are you in a designated sector and large enough? The law applies to organisations in sectors such as healthcare, transport, energy, digital infrastructure, government, postal services, waste, food, chemicals and manufacturing — from 50 employees, or with fewer employees an annual turnover and balance sheet total of more than 10 million euro each. Larger organisations in critical sectors become "essential entities", the rest "important entities". The difference is mainly supervision: essential entities face proactive oversight, important entities are checked after the fact.

Question 2 — and this one is often missed: do you supply businesses that fall under it? The law obliges entities to manage the security of their *suppliers*. Are you a software vendor, installation company, logistics provider or accounting firm serving a hospital, energy company or food producer? Then the requirements get passed down to you — in supplier requirements, audits and contract annexes. Formally you are not covered; practically you are.

For healthcare there is an extra dimension: organisations already working with NEN 7510 (the Dutch standard for information security in healthcare) have a head start — the duty-of-care measures largely overlap.

What the law requires

The Cybersecurity Act has three core obligations:

  • Duty of care — appropriate technical and organisational measures: risk management, incident handling, backups and recovery, supplier management, MFA, encryption and security awareness for staff. The board approves the measures and every board member must be demonstrably trained within two years.
  • Reporting duty — give early warning of significant incidents to the CSIRT and the supervisory authority within 24 hours, submit a notification with an initial assessment within 72 hours and a final report no later than one month after that.
  • Registration duty — register your organisation in the national register at mijn.ncsc.nl.

The fines are serious: up to 10 million euro or 2% of global annual revenue for essential entities. But honestly: the fine should not be the real motivation. The measures the law requires are the same ones that prevent a ransomware attack from shutting your business down for weeks.

The five measures to arrange now (law or no law)

These five form the foundation of the duty of care. They are not everything the law requires, but they are where you start:

  1. MFA on everything. Multi-factor authentication on email, workspace and all business applications. Still the measure that stops most attacks.
  2. Backups you have actually tested. Daily, automated, and a restore test at least once a quarter. A backup you have never restored is an assumption, not a certainty.
  3. A one-page incident plan. Who do you call, who decides, who communicates — reporting within 24 hours only works if those questions are answered in advance.
  4. Visibility on your suppliers. Which parties can access your systems and data, and what agreements cover that?
  5. Staff who recognise phishing. Awareness training and periodic phishing simulations — people remain the most attacked link.

If you work on a managed online workspace, the first two points are already part of the service: MFA, daily backups, monitoring and patching are included in the management. That is not full NIS2 compliance — the organisational side remains your job — but the technical foundation is in place.

How to start today

Do not start with a heavyweight compliance project; start by knowing where you stand. Take the NIS2 check to see whether and how the law affects your organisation, or request the free IT check — seven questions, and you receive a personal roadmap with the gaps to close first. Prefer to talk to a specialist directly? Schedule a consultation — no obligations, via Teams or by phone.

*Virtual Computing is ISO 27001 certified. We apply the measures in this article daily in managing our own infrastructure and that of our customers.*

Written by

Questions about this topic?

Contact our team for personal advice.