NIS2 guideNIS2 Netherlands

NIS2 in the Netherlands now means the Cyberbeveiligingswet.

For Dutch organizations, NIS2 is implemented through the Cyberbeveiligingswet. The practical questions are whether the law applies, who owns registration and security measures, how significant incidents are reported, and how supplier pressure moves through the chain.

Framework-Pro + IncidentAIUpdated August 2026
Key points

What to remember before you act.

  • Use Dutch NCSC and RDI sources for current local guidance.
  • Scope depends on sector, size, service type, and specific criteria.
  • Covered entities have registration, duty-of-care, and incident reporting obligations.
  • The incident reporting process includes 24-hour early warning, 72-hour notification, and final reporting.
  • Suppliers can feel indirect impact when covered customers request stronger security evidence.

What changed in the Netherlands?

The Dutch Cyberbeveiligingswet implements the European NIS2 Directive nationally. NCSC and RDI materials now present the law as in force from 15 August 2026. That means Dutch organizations should use current Dutch guidance rather than older NIS2 preparation pages that described the law as future-only.

The Dutch model includes registration, a duty of care for cybersecurity measures, and a reporting duty for significant incidents. Which authority or supervisor is relevant depends on sector.

How to check whether your organization is in scope

Dutch NCSC guidance explains that scope depends mainly on the sector and the size of the organization, with specific criteria and exceptions for certain services. The guidance points organizations to the RDI self-evaluation and official sector information.

For SMBs, the important point is to check formally rather than rely on a quick label. Group structure, supplier role, sector, service type, and customer relationships can all affect the analysis.

01

Check the sector

Compare your activities with the Dutch sector lists and sector-specific guidance.

02

Check size and exceptions

Review employee count, turnover, balance sheet, connected companies, and services where no normal size threshold may apply.

03

Use official tools

Use the RDI self-evaluation and NCSC/RDI guidance for the latest route.

04

Assign an owner

Someone should own the scope check, registration status, evidence, and updates.

What Dutch organizations should prepare

If the Cyberbeveiligingswet applies, preparation should be operational as well as legal.

  • Registration details and access to the relevant portal.
  • Risk analysis and information-system security policy.
  • Incident response process and reporting escalation path.
  • Backup, recovery, continuity, and crisis-management arrangements.
  • Supplier inventory and supplier security review process.
  • Vulnerability handling and secure acquisition, development, and maintenance practices.
  • Cyber hygiene, training, access control, asset management, and authentication measures.
  • Evidence that controls are implemented and periodically reviewed.

Incident reporting in the Dutch process

Dutch NCSC guidance describes a staged reporting process for significant incidents. The early warning is due as soon as possible and no later than 24 hours after the organization becomes aware of the incident. A 72-hour notification and final report then follow, with progress updates when needed.

That makes incident records important. A Dutch SMB or supplier responding under customer pressure needs a timeline, owner decisions, evidence links, suspected cause, impact view, and updates that management can understand quickly.

Where aneo helps Dutch teams

Framework-Pro can help Dutch teams structure NIS2 readiness around framework choice, control mapping, policies, owners, and evidence placeholders. IncidentAI can help with the incident side: intake, triage, ownership, timelines, summaries, and RCA drafts.

Neither product replaces legal interpretation, regulator guidance, or accountable management decisions. They help the team create cleaner security work products that can be reviewed, approved, implemented, and explained.

Quick FAQ

What is the Cyberbeveiligingswet?

The Cyberbeveiligingswet is the Dutch implementation of the European NIS2 Directive. It sets Dutch requirements for covered organizations, including registration, cybersecurity measures, and significant incident reporting.

When did the Cyberbeveiligingswet come into force?

Dutch NCSC and RDI guidance present the Cyberbeveiligingswet as in force from 15 August 2026.

Where should Dutch organizations check NIS2 scope?

Use official Dutch sources such as NCSC and RDI guidance, including the RDI self-evaluation and sector-specific materials.

Do Dutch suppliers need to care about NIS2?

Yes, even when not directly covered, suppliers can be affected when customers under the Cyberbeveiligingswet ask for security evidence or incident notification commitments.

Official sources used

These pages were used for factual grounding. aneo summarizes them in original wording and does not provide legal advice.

Dutch NIS2 readiness

Prepare policies, controls, evidence, and incident records before pressure starts.

Use Framework-Pro for readiness documents and IncidentAI for incident workflow structure. Both keep human review and accountable decisions at the center.