Home / Cybersecurity / NIS2 in Netherlands / Waste management

Netherlands · Waste management · Annex II

NIS2 for waste-management companies in the Netherlands

Waste management is listed in Annex II of the NIS2 directive. Medium and large companies are important entities (lighter supervision, after the fact). In Netherlands, the rules come from the Cyberbeveiligingswet (Cbw — Cybersecurity Act), applicable since 15 August 2026; the authority is the National Cyber Security Centre (NCSC) runs the register; supervision by the Rijksinspectie Digitale Infrastructuur (RDI) and the sector supervisors.

→ Talk to a cybersecurity advisor

Who is covered in this sector

Companies for which waste management is not the principal activity are excluded.

The threats we see most in waste management

Five priority measures

  1. 01 Continuity plan for collection rounds without IT
  2. 02 MFA and patching on plant and office systems
  3. 03 Backups of weighing and billing data
  4. 04 Supplier register with access rights
  5. 05 Staff awareness on phishing and payment fraud

What Netherlands requires

Registration. Register in the national entity register through Mijn.NCSC.nl — mandatory since 15 August 2026.

Significant incidents: early warning within 24 hours, notification within 72 hours, final report within one month. Fines set by the directive: up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities (whichever is higher).

Tools and guides

Waste management in other countries

Other sectors in Netherlands

Frequently asked questions

Is my waste-management companie company in scope of NIS2 in Netherlands?

Waste management is an Annex II sector. Medium and large companies are important entities (lighter supervision, after the fact). Small companies are generally out of scope unless designated. Our NIS2 check gives you the answer in two minutes.

What should we do first?

Register if you are in scope, name an owner, run a short risk assessment, and fix the basics: MFA, tested backups, patching, incident routine.

We are a supplier to this sector. Does it affect us?

Yes, indirectly: your customers must secure their supply chain and will ask you for evidence. See our supplier questionnaire guide.

Sources

Last checked: 28 September 2026. This page is general information, not legal advice.

Free first call · English

Waste management in Netherlands: a first view, free

Tell us where you stand. An English-speaking advisor replies within one business day with a first view and, if useful, a written quote. No commitment.

  • Reply within one business day
  • Written scope and price before any work
  • Netherlands · Belgium · Luxembourg

Prefer email? Write to contact@cybernovalabs.io

→ Free cybersecurity call