Standards & legislation

NIS2 and the Dutch Cybersecurity Act

NIS2 (Directive (EU) 2022/2555) obliges essential and important entities to a duty of care, incident reporting and board-level accountability for cybersecurity. In the Netherlands, NIS2 is implemented through the Cyberbeveiligingswet.

NIS2 and the Dutch Cybersecurity Act in brief

NIS2 affects far more organisations than its predecessor: from energy and healthcare to digital service providers and suppliers. The core is a duty of care (appropriate risk management measures), an obligation to report significant incidents and personal accountability of the board.

The Audirium library links the NIS2 articles to concrete controls, so you can navigate from statutory article to measure. With the free NIS2 Scanner you assess where your organisation stands in fifteen minutes.

Who falls under NIS2?

In the Netherlands NIS2 has applied since 15 August 2026 through the Cyberbeveiligingswet, without a transition period, for an estimated eight thousand organisations. Whether you are in scope depends on two things: your sector and your size.

  • Sector Annex I of NIS2 (energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space) or Annex II (post and courier services, waste management, chemicals, food, manufacturing, digital providers and research).
  • Size From the ceilings for medium-sized enterprises in Recommendation 2003/361/EC: in practice from fifty employees, or more than ten million euro in both annual turnover and balance sheet total (Art. 2(1)).
  • Regardless of size Providers of public electronic communications networks and services, trust services, top-level domain name registries and domain name registration services. Also any entity that is the sole provider in a Member State of a service essential to critical societal or economic activities (Art. 2(2)).

Essential or important entity?

The distinction determines supervision and the maximum fine, not the duty of care itself: that is identical for both categories.

  • Essential Annex I organisations exceeding the ceilings for medium-sized enterprises, plus qualified trust service providers, TLD name registries and DNS service providers regardless of size (Art. 3(1)).
  • Important All other in-scope Annex I or II organisations that are not essential entities (Art. 3(2)).
  • What it changes Supervision of essential entities is proactive: the authority may inspect on its own initiative. For important entities it is reactive, after an incident or a signal (Art. 32 and 33).

The duty of care: ten categories of measures

Article 21(2) lists ten categories an organisation must cover at a minimum, based on an all-hazards approach. It is a floor, not a menu.

  • a. Risk analysis and security policy Policies on risk analysis and information system security.
  • b. Incident handling Detecting, handling and closing security incidents.
  • c. Business continuity Backup management, disaster recovery and crisis management.
  • d. Supply chain security Including the security aspects of the relationship with each direct supplier and service provider.
  • e. Secure acquisition and development Security in acquiring, developing and maintaining network and information systems, including vulnerability handling and disclosure.
  • f. Effectiveness assessment Policies and procedures to assess whether the measures actually work.
  • g. Cyber hygiene and training Basic cyber hygiene practices and cybersecurity training.
  • h. Cryptography Policies and procedures on the use of cryptography and, where appropriate, encryption.
  • i. Personnel, access and assets Human resources security, access control policies and asset management.
  • j. Authentication and communication Where appropriate: multi-factor or continuous authentication, secured voice, video and text communication and secured emergency communication systems.

Reporting: 24 hours, 72 hours, one month

For a significant incident, reporting to the CSIRT or the competent authority runs in three steps (Art. 23(4)).

  • Within 24 hours, early warning Indicating whether the incident is suspected of being caused by unlawful or malicious acts, or could have cross-border impact.
  • Within 72 hours, incident notification An updated notification with an initial assessment of severity and impact and, where available, indicators of compromise.
  • Within one month, final report A detailed description of the incident, the type of threat or likely root cause, the mitigation measures applied and ongoing, and any cross-border impact.
  • If the incident is still ongoing A progress report is submitted at that point, and a final report within one month of handling the incident. The authority may also request an interim report.

The board is accountable

NIS2 places responsibility explicitly with the management body, not with the IT department.

  • Approve and oversee The management body approves the cybersecurity risk management measures, oversees their implementation and can be held liable for infringements of Article 21 (Art. 20(1)).
  • Training obligation Board members must follow training to identify and assess cyber risks; organisations are encouraged to offer the same to their staff (Art. 20(2)).
  • Registration An in-scope organisation registers itself with the supervisory authority; the law does not wait for you to come forward.

Enforcement and fines

The maximum fines are set out in Article 34 and apply to infringements of the duty of care (Art. 21) or the reporting obligation (Art. 23).

  • Essential entities Up to at least ten million euro or two per cent of total worldwide annual turnover for the preceding financial year, whichever is higher (Art. 34(4)).
  • Important entities Up to at least seven million euro or 1.4 per cent of total worldwide annual turnover, whichever is higher (Art. 34(5)).
  • Beyond money A fine comes on top of other enforcement measures. If those remain ineffective, for an essential entity the authority can have a certification or authorisation temporarily suspended, or request a temporary ban on a person exercising managerial functions (Art. 32(5)).

Verified counts

Legislation

46 articles

Richtlijn (EU) 2022/2555 - Network and Information Security Directive.

Links

84 legislation-to-control links

Direct references from statutory articles to concrete controls in the library.

Library

52 frameworks

This standard does not stand alone: the library counts 3,738 controls and 4,291 cross-references.

Get started with NIS2 and the Dutch Cybersecurity Act

Request a demo or see how NIS2 Scanner supports this standard.

Frequently asked questions

Who does NIS2 apply to?

NIS2 applies to essential and important entities in sectors such as energy, transport, healthcare, digital infrastructure, government and food, and to many of their suppliers. Medium-sized organisations (from 50 employees or 10 million euro turnover) in those sectors are also in scope.

What do I need to arrange for NIS2?

The core: a duty of care with appropriate risk management measures (from policy and incident handling to supply chain security and encryption), an obligation to report significant incidents, and demonstrable board involvement. The Dutch Cyberbeveiligingswet implements this for the Netherlands.

How do I know where my organisation stands?

With Audirium's free NIS2 Scanner you complete a self-assessment on the NIS2 themes and immediately see the biggest gaps. The underlying library links every NIS2 article to concrete controls, so the next step is clear straight away.

When does the Dutch Cybersecurity Act apply?

Since 15 August 2026, without a transition period. The Dutch Senate passed the Cyberbeveiligingswet on 7 July 2026; the duty of care, the reporting obligation and the registration obligation apply from day one, for an estimated eight thousand Dutch organisations. The Wwke, the Dutch implementation of the CER Directive, entered into force at the same time.

How quickly must I report an incident?

In three steps to the CSIRT or the competent authority: an early warning within 24 hours, the incident notification within 72 hours with an initial assessment of severity and impact, and a final report within one month of that notification covering the root cause and the measures taken. If the incident is still ongoing, a progress report comes first and the final report follows within a month of handling it (Art. 23(4)).

What are the ten measures of the duty of care?

Article 21(2) lists: risk analysis and security policy, incident handling, business continuity and crisis management, supply chain security, secure acquisition and development including vulnerability handling, assessment of the effectiveness of the measures, cyber hygiene and training, cryptography and encryption, security around personnel, access and assets, and where appropriate multi-factor authentication and secured communication. It is a floor, not a menu.

What is the difference between an essential and an important entity?

The duty of care is identical; supervision and the maximum fine differ. Essential entities are the larger Annex I organisations, plus a few providers regardless of size, and are supervised proactively. Important entities are the remaining in-scope Annex I or II entities and are checked reactively, after an incident or a signal (Art. 3, 32 and 33).

How high can the fine be?

For essential entities up to at least ten million euro or two per cent of total worldwide annual turnover, whichever is higher. For important entities up to at least seven million euro or 1.4 per cent (Art. 34). A fine comes on top of other measures: if remediation fails, an essential entity can face temporary suspension of a certification, or a temporary ban on a person exercising managerial functions (Art. 32(5)).

Is the board personally accountable?

Yes. The management body approves the measures, oversees their implementation and can be held liable for infringements of Article 21. Board members must also follow training themselves to be able to assess cyber risks (Art. 20).