← All resources

NIS2 Netherlands: transport and logistics, who is in scope?

Published September 29, 2026 · 9 min read · CyberNovaLabs.io

The Dutch NIS2 implementing act entered into force on 15 August 2026. Against expectations, most road hauliers are not directly in scope. Here are the exact criteria, the competent authority, the reporting deadlines, the fines, and the supply chain route that catches you anyway.

The short answer

Since 15 August 2026 the Cyberbeveiligingswet (Cbw), the Dutch implementation of the NIS2 directive, has been in force[1]. Here is what surprises most operators: NIS2 in the Netherlands does not cover the majority of road hauliers and logistics providers. Annex I of the directive limits road transport to road authorities responsible for traffic control and to operators of intelligent transport systems[9]. A standard freight carrier, a freight forwarder or a contract logistics provider is not on that list.

Annex I does cover railway undertakings and infrastructure managers, inland, coastal and maritime passenger and freight water transport companies, port managing bodies, air carriers and airport managing bodies[9]. Postal and courier services sit in Annex II[9]. And if you tick none of those boxes, the customers who do will put their supplier security questionnaire in front of you. More on that below.

Are you in scope? The criteria

Two conditions apply together: activity and size.

Activity. First check whether you carry out a listed activity:

Size. According to the NCSC, an organisation is large enough if it has 50 or more staff measured in full-time equivalents, or fewer than 50 staff but both an annual turnover and a balance sheet total above 10 million euros. Partner and linked undertakings, including parents and subsidiaries, count towards that calculation[2].

Essential or important? A large company in an Annex I sector, meaning more than 250 staff, or more than 50 million euros turnover and more than 43 million euros balance sheet total, is in principle an essential entity. A medium-sized Annex I company, or a company in an Annex II sector such as postal and courier services, is an important entity[2][9]. The practical difference is supervision: proactive for essential entities, after the fact for important ones[9].

What the law requires in the Netherlands

The supervisory authority differs by sub-sector. For transport falling under the Ministry of Infrastructure and Water Management, meaning road, rail, water, aviation and public transport, it is the Inspectie Leefomgeving en Transport (ILT)[5]. For postal and courier services it is the Rijksinspectie Digitale Infrastructuur (RDI)[7]. The national CSIRT is the NCSC.

ObligationWhat it meansWhere and when
RegistrationEnrol in the national entity registerVia Mijn.NCSC.nl; mandatory since 15 August 2026[3]
Duty of careRisk analysis, technical and organisational measures, supply chain security, business continuityOngoing[1]
Early warningFirst flag of a significant incident24 hours from becoming aware[4]
NotificationInitial assessment of severity and impact72 hours[4]
Final reportClosing report, or a progress report if the incident is still running1 month[4]
Informing customersWarn the recipients of your serviceCase by case[8]

One practical piece of good news: the MijnNCSC portal is a single desk. One submission reaches both the relevant CSIRT and the competent supervisory authority[4].

Fines. Article 87 of the Cbw caps the administrative fine at 10 million euros or 2% of total worldwide annual turnover for an essential entity, and at 7 million euros or 1.4% for an important entity, whichever is higher; other breaches are capped at 1 million euros[8]. For directors, the law provides personal enforcement measures: a penalty payment order, an administrative fine, and for essential entities the option of requesting the temporary suspension of a director[4].

What changes in practice for a carrier or a logistics provider

The systems that hurt when they stop: the TMS and planning, EDI flows with shippers and customs, the warehouse WMS, on-board telematics and tracking units, port community portals, and the mailbox through which transport orders arrive. In this sector an outage is not recovered the next day: the docks are congested within hours.

The recent Dutch examples are documented. In 2024 AB Texel and Schneider Logistics were hit by the Cactus ransomware group; Klarenbeek Transport was hit in November 2024 by the Blacksuit group, with data theft; in the same month an attack on Blue Yonder software disrupted the logistics systems used by Jumbo and Hema[12]. That last case is the NIS2 supply chain clause made visible: the attack was not at your premises, the shutdown was.

For scale: the Cybersecuritybeeld Nederland 2025 records at least 121 unique ransomware incidents in the Netherlands in 2024, across all sectors[10]. At European level, the ENISA Threat Landscape 2025 attributes 7.5% of recorded incidents to transport, of which 20.8% fall on logistics within that sector[11]. These are not Dutch sector figures: treat them as orientation, not as your own risk rate.

Out of scope does not mean off the hook

This is the part most carriers discover too late. Your customers who are in scope of the Cbw, a port, a hospital, a manufacturer, a rail shipper, are obliged to manage the security of their supply chain[9]. In practice that reaches you as a supplier security questionnaire, an incident notification clause in the transport contract, or a requirement for strong authentication on customer portal access. A weak answer to that questionnaire costs you a tender, not a fine.

Three other rules apply to you regardless: the AVG, the Dutch GDPR, for driver data, geolocation and customer data, supervised by the Autoriteit Persoonsgegevens; the Wet weerbaarheid kritieke entiteiten, in force from the same 15 August 2026, for entities designated as critical, which covers several port operators[1]; and existing sector security rules.

The first five actions

  1. Settle the scope question in writing. One page: your activity against Annexes I and II, your headcount in FTE, your turnover and balance sheet, linked undertakings included. Dated and signed. That is the document the ILT or a customer will ask for.
  2. If you are in scope, register on Mijn.NCSC.nl. The obligation has been running since 15 August 2026[3].
  3. Write the notification procedure before you need it. Who decides an incident is significant, who logs into the portal, who calls the customer. The 24 hours are not negotiable and start when you become aware of the incident[4].
  4. Treat TMS and WMS backups like rolling stock. One offline copy, a dated restore test, a recovery time quantified per system. In the Blue Yonder case, backups are what limited the damage[12].
  5. Prepare your supplier questionnaire answer once and for all. Multi-factor authentication, access management for subcontractors and temporary staff, a list of your critical IT providers, a contractual notification deadline. You will reuse it at every tender.

At CyberNovaLabs.io

Start with the free NIS2 check: a few questions about your activity and size, and you know whether the Cyberbeveiligingswet applies to you. The NIS2 Netherlands page for transport goes into the sector, and NIS2 Netherlands for postal and courier services covers the Annex II case. If the pressure is coming from your customers, our supplier security questionnaire template will save you a week.

On the commercial side of the Dutch market, two useful reads: B2B prospecting and the GDPR in France, Belgium and the Netherlands, and what a qualified B2B appointment really costs. Our B2B appointment setting in Amsterdam covers the Dutch market directly.

Unsure about your scope, or stuck on a customer questionnaire? Write to us and we will look at your actual case, with no commitment.

Sources

  1. Rijksoverheid — Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf vandaag van kracht (15/08/2026)
  2. NCSC — Valt mijn organisatie onder de Cyberbeveiligingswet (NIS2)?
  3. NCSC — Registratieplicht Cyberbeveiligingswet
  4. NCSC — Meld incidenten onder de Cyberbeveiligingswet (meldplicht)
  5. Inspectie Leefomgeving en Transport (ILT) — Digitale weerbaarheid
  6. RDI — Veelgestelde vragen Cyberbeveiligingswet
  7. RDI — Toezicht RDI op de Cyberbeveiligingswet
  8. Tweede Kamer — Kamerstuk 36764 nr. 8 (Cyberbeveiligingswet, sancties art. 87)
  9. Directive (UE) 2022/2555 (NIS2) — annexes I et II
  10. NCTV — Cybersecuritybeeld Nederland 2025
  11. ENISA Threat Landscape 2025
  12. ABN AMRO — Cyberveiligheid in de sector Transport en Logistiek
CyberNovaLabs.io

Qualified meetings, no lock-in.

Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.

→ Get meetings booked

Read next

Newsletter · CyberNovaLabs.io

Security Briefing

One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.

→ Get meetings booked