Carefully assess whether your organisation falls under the Dutch Cybersecurity Act and which steps you need to take next.
Start with the service and sector
Look beyond the trading name or Dutch industry classification (SBI) code. Determine which services the organisation actually provides and whether they fall within a designated sector or type of entity.
The Dutch Government lists sectors including energy, drinking water, digital infrastructure, healthcare, government and transport. The full statutory scope and any sector-specific guidance remain decisive.
- which services are actually provided
- in which sector and geographical area
- size of the organisation, including relevant partner and linked enterprises
- any specific designation or exception
- its role as a supplier to an organisation covered by the Act
Direct or indirect impact
Even if the Act does not apply to you directly, customers may impose security requirements. Organisations covered by the Act must manage risks in their supply chains.
Distinguish between statutory applicability and contractual or commercial impact. Both may lead to controls, but the legal basis and accountability differ.
What should you record in your assessment?
Record the facts, sources used, conclusion, uncertainties and responsible decision-maker. A short memo reviewed periodically is often more useful than an opaque yes/no outcome.
If the Act applies
Identify which registration, risk-management, reporting and governance duties apply to you and meet the applicable statutory deadlines. The Act has applied since 15 August 2026; a preparation plan does not provide additional time. Check specific rules and deadlines, including those for board members’ knowledge and skills. Existing ISO 27001 or NEN 7510 processes can provide building blocks, provided you assess the additional statutory requirements separately.
Frequently asked questions
Is company size the only deciding factor?+
No. Sector, service, size, designations and exceptions must be assessed together.
What if we are only a supplier?+
First check whether your own services fall directly within the Act’s scope. If they do not, customers may still set security requirements to manage their supply chain risks.
When did the Act enter into force?+
The Dutch Cybersecurity Act entered into force on 15 August 2026. When applying it, check the latest official information from the Dutch Government and the NCSC.
Sources and further reading
We prioritise primary sources for factual and time-sensitive information. Always check the current official publication when making important decisions.
- Dutch Government: official informationAccessed on 20 September 2026
- EUR-Lex: official informationAccessed on 20 September 2026
- National Cyber Security Centre: official informationAccessed on 20 September 2026
- NCSC: scope and size criteriaAccessed on 20 September 2026
- Dutch Cybersecurity Act: enacted legislation (Staatsblad 2026, 187)Accessed on 20 September 2026
- Dutch Cybersecurity Decree: detailed rules and commencement (Staatsblad 2026, 189)Accessed on 20 September 2026
Related articles
This is general guidance and does not replace a legal assessment or the official standard.
