Home / Cybersecurity / NIS2 in Netherlands
NIS2 in the Netherlands: what applies and what to do now
Cyberbeveiligingswet (Cbw — Cybersecurity Act) — applies since 15 August 2026. Authority: the National Cyber Security Centre (NCSC) runs the register; supervision by the Rijksinspectie Digitale Infrastructuur (RDI) and the sector supervisors. Around 8,000 Dutch organisations are expected to fall under the Act, according to Dutch press reports.
→ Talk to a cybersecurity advisor
The essentials
- The Act entered into force on 15 August 2026, together with the Critical Entities Resilience Act (Wwke).
- Registration in the national register (Mijn.NCSC.nl) is mandatory since 15 August 2026: name, address, sector, EU countries served, contact details and, where relevant, IP ranges.
- Cloud, data-centre, DNS and managed-service providers register where their head office is; other entities register in every EU country where they operate.
- The duty of care (risk management) and the duty to report significant incidents apply from the same date.
- Non-compliance can lead to fines and to orders subject to a penalty payment (last onder dwangsom).
Registration. Register in the national entity register through Mijn.NCSC.nl — mandatory since 15 August 2026.
Obligations once in scope
- 01 Risk analysis and information-security policies
- 02 Incident handling
- 03 Business continuity, backups and crisis management
- 04 Supply-chain security (your suppliers and service providers)
- 05 Security in buying, developing and maintaining systems, including vulnerability handling
- 06 Policies to assess whether the measures work
- 07 Basic cyber hygiene and staff training
- 08 Cryptography and encryption
- 09 HR security, access control and asset management
- 10 Multi-factor authentication and secured communications
Significant incidents: early warning within 24 hours, notification within 72 hours, final report within one month.
Fines set by the directive: up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities (whichever is higher).
NIS2 by sector in Netherlands
Not in scope yourself?
If you supply companies that are, you will receive their requirements. See the 30 questions of a supplier security questionnaire →
Other countries
Frequently asked questions
Does NIS2 apply to my company in Netherlands?
It applies to medium and large companies in the sectors listed by the directive, and to some providers whatever their size. Use our free NIS2 check to get an answer for Netherlands in two minutes.
Who is the authority in Netherlands?
The National Cyber Security Centre (NCSC) runs the register; supervision by the Rijksinspectie Digitale Infrastructuur (RDI) and the sector supervisors.
What if we missed the registration deadline?
Register now and document the reason. Authorities look at good faith and at what you do next; staying unregistered is the worst option.
Sources
- NCSC — Cyberbeveiligingswet (NIS2)
- RDI — Registration duty
- Rijksoverheid — in force from 15 August 2026
Last checked: 28 September 2026. This page is general information, not legal advice.
NIS2 in Netherlands: where do you stand?
Tell us where you stand. An English-speaking advisor replies within one business day with a first view and, if useful, a written quote. No commitment.
- Reply within one business day
- Written scope and price before any work
- Netherlands · Belgium · Luxembourg