What changed in the Netherlands?
The Dutch Cyberbeveiligingswet implements the European NIS2 Directive nationally. NCSC and RDI materials now present the law as in force from 15 August 2026. That means Dutch organizations should use current Dutch guidance rather than older NIS2 preparation pages that described the law as future-only.
The Dutch model includes registration, a duty of care for cybersecurity measures, and a reporting duty for significant incidents. Which authority or supervisor is relevant depends on sector.
How to check whether your organization is in scope
Dutch NCSC guidance explains that scope depends mainly on the sector and the size of the organization, with specific criteria and exceptions for certain services. The guidance points organizations to the RDI self-evaluation and official sector information.
For SMBs, the important point is to check formally rather than rely on a quick label. Group structure, supplier role, sector, service type, and customer relationships can all affect the analysis.
Check the sector
Compare your activities with the Dutch sector lists and sector-specific guidance.
Check size and exceptions
Review employee count, turnover, balance sheet, connected companies, and services where no normal size threshold may apply.
Use official tools
Use the RDI self-evaluation and NCSC/RDI guidance for the latest route.
Assign an owner
Someone should own the scope check, registration status, evidence, and updates.
What Dutch organizations should prepare
If the Cyberbeveiligingswet applies, preparation should be operational as well as legal.
- Registration details and access to the relevant portal.
- Risk analysis and information-system security policy.
- Incident response process and reporting escalation path.
- Backup, recovery, continuity, and crisis-management arrangements.
- Supplier inventory and supplier security review process.
- Vulnerability handling and secure acquisition, development, and maintenance practices.
- Cyber hygiene, training, access control, asset management, and authentication measures.
- Evidence that controls are implemented and periodically reviewed.
Incident reporting in the Dutch process
Dutch NCSC guidance describes a staged reporting process for significant incidents. The early warning is due as soon as possible and no later than 24 hours after the organization becomes aware of the incident. A 72-hour notification and final report then follow, with progress updates when needed.
That makes incident records important. A Dutch SMB or supplier responding under customer pressure needs a timeline, owner decisions, evidence links, suspected cause, impact view, and updates that management can understand quickly.
Where aneo helps Dutch teams
Framework-Pro can help Dutch teams structure NIS2 readiness around framework choice, control mapping, policies, owners, and evidence placeholders. IncidentAI can help with the incident side: intake, triage, ownership, timelines, summaries, and RCA drafts.
Neither product replaces legal interpretation, regulator guidance, or accountable management decisions. They help the team create cleaner security work products that can be reviewed, approved, implemented, and explained.
Quick FAQ
What is the Cyberbeveiligingswet?
The Cyberbeveiligingswet is the Dutch implementation of the European NIS2 Directive. It sets Dutch requirements for covered organizations, including registration, cybersecurity measures, and significant incident reporting.
When did the Cyberbeveiligingswet come into force?
Dutch NCSC and RDI guidance present the Cyberbeveiligingswet as in force from 15 August 2026.
Where should Dutch organizations check NIS2 scope?
Use official Dutch sources such as NCSC and RDI guidance, including the RDI self-evaluation and sector-specific materials.
Do Dutch suppliers need to care about NIS2?
Yes, even when not directly covered, suppliers can be affected when customers under the Cyberbeveiligingswet ask for security evidence or incident notification commitments.
Official sources used
These pages were used for factual grounding. aneo summarizes them in original wording and does not provide legal advice.
