NIS2 Netherlands: transport and logistics, who is in scope?
The Dutch NIS2 implementing act entered into force on 15 August 2026. Against expectations, most road hauliers are not directly in scope. Here are the exact criteria, the competent authority, the reporting deadlines, the fines, and the supply chain route that catches you anyway.
The short answer
Since 15 August 2026 the Cyberbeveiligingswet (Cbw), the Dutch implementation of the NIS2 directive, has been in force[1]. Here is what surprises most operators: NIS2 in the Netherlands does not cover the majority of road hauliers and logistics providers. Annex I of the directive limits road transport to road authorities responsible for traffic control and to operators of intelligent transport systems[9]. A standard freight carrier, a freight forwarder or a contract logistics provider is not on that list.
Annex I does cover railway undertakings and infrastructure managers, inland, coastal and maritime passenger and freight water transport companies, port managing bodies, air carriers and airport managing bodies[9]. Postal and courier services sit in Annex II[9]. And if you tick none of those boxes, the customers who do will put their supplier security questionnaire in front of you. More on that below.
Are you in scope? The criteria
Two conditions apply together: activity and size.
Activity. First check whether you carry out a listed activity:
- Air: air carriers, airport managing bodies, air traffic management operators.
- Rail: infrastructure managers and railway undertakings.
- Water: maritime, coastal and inland passenger and freight transport companies, port managing bodies, vessel traffic services.
- Road: road authorities responsible for traffic control, operators of intelligent transport systems.
- Annex II: postal and courier services.
Size. According to the NCSC, an organisation is large enough if it has 50 or more staff measured in full-time equivalents, or fewer than 50 staff but both an annual turnover and a balance sheet total above 10 million euros. Partner and linked undertakings, including parents and subsidiaries, count towards that calculation[2].
Essential or important? A large company in an Annex I sector, meaning more than 250 staff, or more than 50 million euros turnover and more than 43 million euros balance sheet total, is in principle an essential entity. A medium-sized Annex I company, or a company in an Annex II sector such as postal and courier services, is an important entity[2][9]. The practical difference is supervision: proactive for essential entities, after the fact for important ones[9].
What the law requires in the Netherlands
The supervisory authority differs by sub-sector. For transport falling under the Ministry of Infrastructure and Water Management, meaning road, rail, water, aviation and public transport, it is the Inspectie Leefomgeving en Transport (ILT)[5]. For postal and courier services it is the Rijksinspectie Digitale Infrastructuur (RDI)[7]. The national CSIRT is the NCSC.
| Obligation | What it means | Where and when |
|---|---|---|
| Registration | Enrol in the national entity register | Via Mijn.NCSC.nl; mandatory since 15 August 2026[3] |
| Duty of care | Risk analysis, technical and organisational measures, supply chain security, business continuity | Ongoing[1] |
| Early warning | First flag of a significant incident | 24 hours from becoming aware[4] |
| Notification | Initial assessment of severity and impact | 72 hours[4] |
| Final report | Closing report, or a progress report if the incident is still running | 1 month[4] |
| Informing customers | Warn the recipients of your service | Case by case[8] |
One practical piece of good news: the MijnNCSC portal is a single desk. One submission reaches both the relevant CSIRT and the competent supervisory authority[4].
Fines. Article 87 of the Cbw caps the administrative fine at 10 million euros or 2% of total worldwide annual turnover for an essential entity, and at 7 million euros or 1.4% for an important entity, whichever is higher; other breaches are capped at 1 million euros[8]. For directors, the law provides personal enforcement measures: a penalty payment order, an administrative fine, and for essential entities the option of requesting the temporary suspension of a director[4].
What changes in practice for a carrier or a logistics provider
The systems that hurt when they stop: the TMS and planning, EDI flows with shippers and customs, the warehouse WMS, on-board telematics and tracking units, port community portals, and the mailbox through which transport orders arrive. In this sector an outage is not recovered the next day: the docks are congested within hours.
The recent Dutch examples are documented. In 2024 AB Texel and Schneider Logistics were hit by the Cactus ransomware group; Klarenbeek Transport was hit in November 2024 by the Blacksuit group, with data theft; in the same month an attack on Blue Yonder software disrupted the logistics systems used by Jumbo and Hema[12]. That last case is the NIS2 supply chain clause made visible: the attack was not at your premises, the shutdown was.
For scale: the Cybersecuritybeeld Nederland 2025 records at least 121 unique ransomware incidents in the Netherlands in 2024, across all sectors[10]. At European level, the ENISA Threat Landscape 2025 attributes 7.5% of recorded incidents to transport, of which 20.8% fall on logistics within that sector[11]. These are not Dutch sector figures: treat them as orientation, not as your own risk rate.
Out of scope does not mean off the hook
This is the part most carriers discover too late. Your customers who are in scope of the Cbw, a port, a hospital, a manufacturer, a rail shipper, are obliged to manage the security of their supply chain[9]. In practice that reaches you as a supplier security questionnaire, an incident notification clause in the transport contract, or a requirement for strong authentication on customer portal access. A weak answer to that questionnaire costs you a tender, not a fine.
Three other rules apply to you regardless: the AVG, the Dutch GDPR, for driver data, geolocation and customer data, supervised by the Autoriteit Persoonsgegevens; the Wet weerbaarheid kritieke entiteiten, in force from the same 15 August 2026, for entities designated as critical, which covers several port operators[1]; and existing sector security rules.
The first five actions
- Settle the scope question in writing. One page: your activity against Annexes I and II, your headcount in FTE, your turnover and balance sheet, linked undertakings included. Dated and signed. That is the document the ILT or a customer will ask for.
- If you are in scope, register on Mijn.NCSC.nl. The obligation has been running since 15 August 2026[3].
- Write the notification procedure before you need it. Who decides an incident is significant, who logs into the portal, who calls the customer. The 24 hours are not negotiable and start when you become aware of the incident[4].
- Treat TMS and WMS backups like rolling stock. One offline copy, a dated restore test, a recovery time quantified per system. In the Blue Yonder case, backups are what limited the damage[12].
- Prepare your supplier questionnaire answer once and for all. Multi-factor authentication, access management for subcontractors and temporary staff, a list of your critical IT providers, a contractual notification deadline. You will reuse it at every tender.
At CyberNovaLabs.io
Start with the free NIS2 check: a few questions about your activity and size, and you know whether the Cyberbeveiligingswet applies to you. The NIS2 Netherlands page for transport goes into the sector, and NIS2 Netherlands for postal and courier services covers the Annex II case. If the pressure is coming from your customers, our supplier security questionnaire template will save you a week.
On the commercial side of the Dutch market, two useful reads: B2B prospecting and the GDPR in France, Belgium and the Netherlands, and what a qualified B2B appointment really costs. Our B2B appointment setting in Amsterdam covers the Dutch market directly.
Unsure about your scope, or stuck on a customer questionnaire? Write to us and we will look at your actual case, with no commitment.
Sources
- Rijksoverheid — Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf vandaag van kracht (15/08/2026)
- NCSC — Valt mijn organisatie onder de Cyberbeveiligingswet (NIS2)?
- NCSC — Registratieplicht Cyberbeveiligingswet
- NCSC — Meld incidenten onder de Cyberbeveiligingswet (meldplicht)
- Inspectie Leefomgeving en Transport (ILT) — Digitale weerbaarheid
- RDI — Veelgestelde vragen Cyberbeveiligingswet
- RDI — Toezicht RDI op de Cyberbeveiligingswet
- Tweede Kamer — Kamerstuk 36764 nr. 8 (Cyberbeveiligingswet, sancties art. 87)
- Directive (UE) 2022/2555 (NIS2) — annexes I et II
- NCTV — Cybersecuritybeeld Nederland 2025
- ENISA Threat Landscape 2025
- ABN AMRO — Cyberveiligheid in de sector Transport en Logistiek
Qualified meetings, no lock-in.
Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.
Read next
Data breach at FWB: three weeks before it was confirmed (05/10)
Flagged from outside in mid-September, confirmed on 5 October 2026: the EAD-online.be data breach shows where the GDPR's 72 hours are really lost, and why the weak link is so often a supplier.
Read the article →October 7, 2026 · 7 min readNIS2 France: are hotels and tourism in scope?
Tourist accommodation is absent from the NIS2 annexes, and France's transposition was still in parliament on 7 October 2026. Yet in May 2026 three French tourism operators lost their reservation databases within 72 hours. Here is what actually applies to you.
Read the article →October 6, 2026 · 7 min readDGFiP breach: stolen logins, no MFA, no detection (29/09/2026)
On 29 September 2026 France's cyber agency ANSSI published its incident report on the cyberattacks against the tax administration. No rare technique: passwords stolen from personal computers, a second factor sent by email, sensitive applications reachable without segmentation, and a portal nobody was watching. All four links exist in most SMEs.
Read the article →