what is the Cybersecurity Act and what is changing
The Dutch Cybersecurity Act transposes NIS2 into Dutch law
The Dutch Cybersecurity Act is the Dutch law that transposes the European NIS2 Directive into national rules. NIS2 is a European Directive, and a Directive does not automatically apply in each country — national legislation is required for that. In the Netherlands, that is the Cybersecurity Act, available on the statutory law website. In broad terms, the Act follows the Directive: the same sectors, the same classification into essential and important entities, and the same core obligations. Whoever wants to know whether their sector falls under the annexeswill find there the overview that forms the basis of this Act.
What changes for organisations that fall under the Act is primarily the scope of obligations. There is a duty of care: taking appropriate measures to secure your own digital systems. There is a registration obligation to the competent authority. And there is an incident notification obligation, with the question of when and to whom notification must be made. For organisations that do not themselves fall under the Act, there is also an indirect change: regulated entities must assess their suppliers, and that means that non-regulated companies can also receive questionnaires and contractual requirements. Whoever wonders why those questions come in anywayreads there how that effect works through the supply chain.
Where this follows from: the transposition of Articles 21 and 23
The obligations in the Dutch Cybersecurity Act follow directly from the NIS2 Directive: Article 21(2) of Directive (EU) 2022/2555 lists the ten measures that form the basis of the duty of care, and the notification obligation is also laid down in the Directive. The Dutch Act elaborates these requirements in national provisions, available on the statutory law website. The NCSC provides guidance on how the duty of care and the notification obligation are implemented in practice.
What this is based on
- Directive (EU) 2022/2555 (NIS2), Article 21(2) — the ten measures
- Cybersecurity Act — the Dutch transposition of NIS2
- ISO/IEC 27001 — Annex A, the control measures
- NCSC — guidance on the security obligation and the reporting obligation
The Regulation itself is available on EUR-Lex. We provide references for each statement; you need not take our word for it.
What you concretely need to do
The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.
View the subscription First the free NIS2 checkThis is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.
Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.