The Cybersecurity Act: what applies in the Netherlands
The Dutch implementation of NIS2, and why there is no transition period.
No transition period
The Netherlands has implemented NIS2 in the Cybersecurity Act. Unlike much legislation, there is no transition period: the obligations apply from the moment of entry into force. Organizations that fall under it must register and comply with the duty of care.
That is why there is so much fuss about it now. Thousands of organizations are only discovering this year that they fall under it, and their suppliers are noticing it through the questionnaires that follow.
Who does what
There is a supervisory authority that enforces and a CSIRT where incident reports go and where threat information comes from. For some sectors, a separate supervisory authority has been designated; which one depends on your sector.
The government itself offers self-assessments and guidance. These are good and free, and we refer to them. Where we go further is with the question that comes next: how do you document it, how do you keep it up to date, and how do you answer your customer's questionnaire with it.
The duty of the board
A point that is defined more sharply in the Netherlands than in the directive itself: the board must approve the measures, oversee their implementation, and must receive training for this. That liability lies with the board member personally and cannot be contracted away.
For employees it is different. Training follows from the duty of care, but there is no separate obligation in the law. We mention that difference, because it matters for what you need to arrange and what it costs.
Frequently asked questions
Where do I register?
With the supervisory authority, via the portal designated for that purpose. You need a login credential there that is registered to your organization. We prepare the requested information; you submit it yourself.
What happens if I do not register?
Not registering is a violation in itself, regardless of whether your security is in order. It is also the first thing a supervisory authority sees.
Are there lower requirements for small organizations?
The measures must be appropriate and proportionate, so yes: an organization of sixty people is expected to do less than one of six thousand. But the subjects are the same, and the registration and reporting obligations offer no discount.
This is explanation, not advice about your own situation. secria.eu does not assess your organization and does not provide assurance.