what happens if I do not comply with NIS2 obligations
Supervision, remediation and ultimately a sanction
Where NIS2 obligations are not met, practice shows that supervision and an opportunity to remedy come first, and only then — if that does not happen — a sanction from the supervisor. The Cybersecurity Act, the Dutch transposition of NIS2, gives the supervisor tools to check whether an organization meets the risk management obligation and the incident notification obligation. Which supervisor that is exactly varies by sector; that is detailed on the page about which supervisory authority oversees my sector under NIS2. Where there are shortcomings, the supervisor can issue directions, impose binding instructions or, at a later stage, proceed to enforcement.
What that means in practice depends on what goes wrong: the absence of the ten mandatory measures from the risk management obligation, a notification that is late or does not arrive, or a supply chain that has not been assessed. For the incident notification obligation, there are specific triggers that require notification; that is detailed on the page about when must I report a cyber incident to the supervisory authority. For the risk management obligation, it is a series of measures that must be in order as a whole, described on the page about which ten measures must I take according to NIS2. There is also a separate question of whether the board can be personally held accountable for a breach, which is addressed separately on the page about Director liability in case of NIS2 breach.
Legal basis in the Directive and national law
The obligations subject to supervision derive from Article 21 of the NIS2 Directive, which establishes the duty of care together with ten measures, and from the reporting obligation that stands separately; the Dutch Cybersecurity Act transposes these obligations into Dutch law and also governs the supervisory authority's powers. The precise implementation of supervision and sanctions follows from that national law and from publications by the supervisory authorities themselves, including the NCSC.
What this is based on
- Directive (EU) 2022/2555 (NIS2), Article 21(2) — the ten measures
- Cybersecurity Act — the Dutch transposition of NIS2
- ISO/IEC 27001 — Annex A, the control measures
- NCSC — guidance on the security obligation and the reporting obligation
The Regulation itself is available on EUR-Lex. We provide references for each statement; you need not take our word for it.
What you concretely need to do
The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.
View the subscription First the free NIS2 checkThis is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.
Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.