How the Directive relates to Dutch legislation
The NIS2 Directive sets common European objectives for cybersecurity risk management, incident reporting, governance and supervision. Each Member State implements the directive through national legislation.
For organisations operating in the Netherlands, the Dutch Act is the primary legal reference for entity scope and practical obligations, interpreted within the European framework.
The components of the Dutch framework
The Cybersecurity Act defines essential and important entities, registration, duty of care, incident reporting, governance, supervision and enforcement. The Cybersecurity Decree and sector-specific provisions add detailed rules and thresholds.
Organisations should maintain a source register for the provisions relevant to their entity type and sector rather than relying on an old summary of the directive.
What the Dutch framework asks organisations to do
- assess and document whether the entity is in scope;
- register through the designated route where required;
- manage cyber risk through appropriate and proportionate measures;
- report significant incidents within the statutory timeline;
- organise executive training, approval and oversight;
- maintain evidence and cooperate with the competent authority.
Entry into force on 15 August 2026
The Cybersecurity Act enters into force on 15 August 2026. Boards can use this date to confirm scope, complete the executive mandate, prioritise material gaps and ensure registration and incident processes are ready.
Implementation continues after entry into force through testing, evidence, review and improvement.
Translate legal requirements into board preparation
Create a legal and governance overview, assign accountable ownership, connect each obligation to an existing or planned process and define which evidence supports completion. Training helps the board assess the roadmap and management information with a shared understanding.
Frequently asked questions
Is the NIS2 Directive directly the same as Dutch law?
The Directive is the European basis. The Dutch Cybersecurity Act and Decree implement it for the Netherlands.
When does the Dutch Act enter into force?
The Cybersecurity Act enters into force on 15 August 2026.
Which source should a Dutch organisation use?
Use the final Dutch Act, Decree and applicable sector rules, informed by the European NIS2 framework.
Translate the legal framework into a board agenda
The Boardroom Briefing and Masterclass explain how the Directive, Dutch Act and Decree affect governance, decisions and oversight.
Discuss the appropriate training route