NIS2 and the Dutch Cybersecurity Act

Does the Dutch Cybersecurity Act apply to my organisation?

Sector, size, service and exceptions determine whether the Act applies directly.

Carefully assess whether your organisation falls under the Dutch Cybersecurity Act and which steps you need to take next.

Start with the service and sector

Look beyond the trading name or Dutch industry classification (SBI) code. Determine which services the organisation actually provides and whether they fall within a designated sector or type of entity.

The Dutch Government lists sectors including energy, drinking water, digital infrastructure, healthcare, government and transport. The full statutory scope and any sector-specific guidance remain decisive.

  • which services are actually provided
  • in which sector and geographical area
  • size of the organisation, including relevant partner and linked enterprises
  • any specific designation or exception
  • its role as a supplier to an organisation covered by the Act

Direct or indirect impact

Even if the Act does not apply to you directly, customers may impose security requirements. Organisations covered by the Act must manage risks in their supply chains.

Distinguish between statutory applicability and contractual or commercial impact. Both may lead to controls, but the legal basis and accountability differ.

What should you record in your assessment?

Record the facts, sources used, conclusion, uncertainties and responsible decision-maker. A short memo reviewed periodically is often more useful than an opaque yes/no outcome.

If the Act applies

Identify which registration, risk-management, reporting and governance duties apply to you and meet the applicable statutory deadlines. The Act has applied since 15 August 2026; a preparation plan does not provide additional time. Check specific rules and deadlines, including those for board members’ knowledge and skills. Existing ISO 27001 or NEN 7510 processes can provide building blocks, provided you assess the additional statutory requirements separately.

Frequently asked questions

Is company size the only deciding factor?+

No. Sector, service, size, designations and exceptions must be assessed together.

What if we are only a supplier?+

First check whether your own services fall directly within the Act’s scope. If they do not, customers may still set security requirements to manage their supply chain risks.

When did the Act enter into force?+

The Dutch Cybersecurity Act entered into force on 15 August 2026. When applying it, check the latest official information from the Dutch Government and the NCSC.

Sources and further reading

We prioritise primary sources for factual and time-sensitive information. Always check the current official publication when making important decisions.

Related articles

NIS2 and the Dutch Cybersecurity ActNIS2 controls: what do you need to put in place?Read article →Suppliers and supply chain securityWhat does NIS2 mean for suppliers and the supply chain?Read article →ISO 27001What is ISO 27001 and what does it mean for your organisation?Read article →

This is general guidance and does not replace a legal assessment or the official standard.