Current position in the Netherlands
The Act translates the European NIS2 framework into Dutch law and defines the sectors, entity types, competent authorities and enforcement structure. The Cybersecurity Decree and sector-specific rules provide further detail.
Organisations should use the final Dutch framework for their scope and implementation decisions. The directive remains the European basis, while the national Act determines the practical legal obligations in the Netherlands.
Entry into force on 15 August 2026
The statutory date creates a clear planning point for registration, risk management, incident reporting, governance and evidence. Boards can use the period before entry into force to confirm scope, assign ownership and close the most material gaps.
A focused roadmap is more useful than treating every control as equally urgent. Priorities follow from critical services, risk, legal deadlines and current maturity.
What the Act requires in practice
Entities within scope must register, manage risks through appropriate and proportionate measures, report significant incidents within the required timeline and cooperate with the competent authorities. Executive directors approve measures, oversee implementation and complete appropriate training.
- documented scope and registration;
- an all-hazards risk analysis connected to critical services;
- proportionate duty-of-care measures and evidence of effectiveness;
- a workable process for early warning, notification and final reporting;
- board decisions, ownership, reporting and periodic review.
Suppliers and chain partners
A supplier does not become a NIS2 entity simply because its customer is in scope. Essential and important entities must nevertheless manage supply-chain risk and may require stronger security, incident, continuity, assurance and audit arrangements from relevant suppliers.
Boards should therefore track both direct statutory obligations and contractual requirements received through customers or sector chains.
What executive and supervisory boards should organise
Confirm scope, assign an accountable executive sponsor, approve a risk-based roadmap, schedule training and define management reporting. Supervisory boards should agree which information supports oversight and how overdue actions, material exceptions and incidents are escalated.
Frequently asked questions
When does the Dutch Cybersecurity Act enter into force?
The Act enters into force on 15 August 2026.
Does every Dutch organisation fall within the Act?
No. Scope depends on the statutory sector, entity type, size rules, exceptions and possible designation.
What should the board do first?
Confirm and document scope, ownership, the current risk picture, the implementation roadmap, training and reporting.
Prepare the board for 15 August 2026
Use a briefing or masterclass to align scope, responsibilities, priorities and reporting before the Dutch Cybersecurity Act takes effect.
Discuss the appropriate training route