Home / Cybersecurity

Netherlands · Belgium · Luxembourg

NIS2 and cybersecurity, made practical.

NIS2 now applies in the Netherlands (15 August 2026), Belgium (since October 2024) and Luxembourg (10 May 2026). Thousands of companies must register, manage cyber risk and report incidents within 24 hours — and many more receive security questionnaires from customers who are in scope. We help you find out where you stand and fix what matters, in English.

→ Talk to a cybersecurity advisor

What changed, country by country

CountryLawApplies sinceAuthorityRegistration
NetherlandsCyberbeveiligingswet (Cbw — Cybersecurity Act)15 August 2026the National Cyber Security Centre (NCSC) runs the registerMijn.NCSC.nl — mandatory since 15 Aug 2026
BelgiumNIS2 Law of 26 April 202418 October 2024the Centre for Cybersecurity Belgium (CCB)Safeonweb@Work — deadline was 18 Mar 2025
LuxembourgLaw of 5 May 2026 transposing NIS210 May 2026the Institut Luxembourgeois de Régulation (ILR)ILR self-registration — deadline was 10 Jul 2026

Fines set by the directive: up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities (whichever is higher).

Who is concerned

Medium company: 50 to 249 staff, or more than €10 million annual turnover and balance sheet. Large company: 250+ staff, or more than €50 million turnover and €43 million balance sheet.

NIS2 by sector

Netherlands

Belgium

Luxembourg

The ten minimum measures

  1. 01 Risk analysis and information-security policies
  2. 02 Incident handling
  3. 03 Business continuity, backups and crisis management
  4. 04 Supply-chain security (your suppliers and service providers)
  5. 05 Security in buying, developing and maintaining systems, including vulnerability handling
  6. 06 Policies to assess whether the measures work
  7. 07 Basic cyber hygiene and staff training
  8. 08 Cryptography and encryption
  9. 09 HR security, access control and asset management
  10. 10 Multi-factor authentication and secured communications

More resources

Frequently asked questions

Is my company in scope of NIS2?

It depends on your sector, your size and your country. Our free NIS2 check answers in two minutes for the Netherlands, Belgium and Luxembourg.

We are not in scope, but a customer sends us a security questionnaire. What now?

That is the most common case for small and medium companies. We help you answer with evidence, not promises, and fix the gaps that block the deal.

Do you work in English?

Yes. Our cybersecurity advisory is delivered in English for the Netherlands, Belgium and Luxembourg.

What does a first call cost?

Nothing. You get a first view and, if you want to go further, a written scope and price before any work starts.

Free first call · English

Talk to a cybersecurity advisor

Tell us where you stand. An English-speaking advisor replies within one business day with a first view and, if useful, a written quote. No commitment.

  • Reply within one business day
  • Written scope and price before any work
  • Netherlands · Belgium · Luxembourg

Prefer email? Write to contact@cybernovalabs.io

→ Free cybersecurity call