Home / Cybersecurity / NIS2 in Netherlands / Transport
NIS2 for transport operators in the Netherlands
Transport is listed in Annex I of the NIS2 directive. Large companies are essential entities; medium companies are important entities. In Netherlands, the rules come from the Cyberbeveiligingswet (Cbw — Cybersecurity Act), applicable since 15 August 2026; the authority is the National Cyber Security Centre (NCSC) runs the register; supervision by the Rijksinspectie Digitale Infrastructuur (RDI) and the sector supervisors.
→ Talk to a cybersecurity advisor
Who is covered in this sector
- Air carriers, airports and air-traffic control
- Rail infrastructure managers and railway undertakings
- Inland, sea and coastal shipping companies, port operators and vessel traffic services
- Road authorities and operators of intelligent transport systems
Ordinary road haulage and logistics companies are not in scope as transport; but they often receive security requirements from in-scope customers — see the supplier questionnaire page.
The threats we see most in transport
- Ransomware on planning, ticketing and warehouse systems
- Attacks on operational systems in ports, rail and aviation
- Fraud and account takeover in booking and payment flows
- Supplier compromise (IT, OT, maintenance)
Five priority measures
- 01 Map the systems that stop operations if they fail
- 02 Segment operational networks from office IT
- 03 MFA and privileged-access control for suppliers
- 04 Continuity plans with manual fall-back procedures
- 05 Incident reporting routine for the 24-hour early warning
What Netherlands requires
- The Act entered into force on 15 August 2026, together with the Critical Entities Resilience Act (Wwke).
- Registration in the national register (Mijn.NCSC.nl) is mandatory since 15 August 2026: name, address, sector, EU countries served, contact details and, where relevant, IP ranges.
- Cloud, data-centre, DNS and managed-service providers register where their head office is; other entities register in every EU country where they operate.
- The duty of care (risk management) and the duty to report significant incidents apply from the same date.
- Non-compliance can lead to fines and to orders subject to a penalty payment (last onder dwangsom).
Registration. Register in the national entity register through Mijn.NCSC.nl — mandatory since 15 August 2026.
Significant incidents: early warning within 24 hours, notification within 72 hours, final report within one month. Fines set by the directive: up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities (whichever is higher).
Tools and guides
Transport in other countries
Other sectors in Netherlands
Frequently asked questions
Is my transport operator company in scope of NIS2 in Netherlands?
Transport is an Annex I sector. Large companies are essential entities; medium companies are important entities. Small companies are generally out of scope unless designated. Our NIS2 check gives you the answer in two minutes.
What should we do first?
Register if you are in scope, name an owner, run a short risk assessment, and fix the basics: MFA, tested backups, patching, incident routine.
We are a supplier to this sector. Does it affect us?
Yes, indirectly: your customers must secure their supply chain and will ask you for evidence. See our supplier questionnaire guide.
Sources
- NCSC — Cyberbeveiligingswet (NIS2)
- RDI — Registration duty
- Rijksoverheid — in force from 15 August 2026
Last checked: 28 September 2026. This page is general information, not legal advice.
Transport in Netherlands: a first view, free
Tell us where you stand. An English-speaking advisor replies within one business day with a first view and, if useful, a written quote. No commitment.
- Reply within one business day
- Written scope and price before any work
- Netherlands · Belgium · Luxembourg