The Dutch Cybersecurity Act is in force: is your organisation ready?
Since 15 August 2026 the Netherlands has its Cybersecurity Act (Cyberbeveiligingswet), the national implementation of the European NIS2 directive. Replacing the earlier Wbni act, it puts more than 8,000 organisations under a registration duty, a duty of care, a 24-hour reporting duty and board-level accountability. Here is what that means in practice – even if your organisation does not formally fall under it.
On 15 August 2026 the Dutch Cybersecurity Act (Cyberbeveiligingswet) entered into force: the national implementation of the European NIS2 directive. It replaces the earlier Wbni act and is estimated to affect more than 8,000 Dutch organisations – considerably more than its predecessor, which targeted a small group of critical providers. Sectors in scope include energy, drinking water, transport, healthcare, digital infrastructure, managed IT services, waste management, food production, parts of manufacturing, and public bodies.
This is not a paper exercise: supervision comes with it, and ultimately enforcement. At the same time the core of the law is refreshingly down to earth. It is not about a heavy certification programme, but about whether you know what you run, whether you keep it in order, and whether you know what to do when something goes wrong.
Four obligations in outline
- Registration duty – organisations in scope must enter themselves in the entity register through the Dutch NCSC portal. The first step is therefore establishing whether you are in scope; that is not always obvious, certainly not for suppliers.
- Duty of care – you must take appropriate technical and organisational measures based on a risk assessment. Appropriate means: proportionate to your size, your risks and the state of the art.
- Reporting duty – significant cyber incidents must be reported to the sectoral CSIRT and the supervisory authority: an early warning within 24 hours, a follow-up report within 72 hours and a final report no later than one month after the first notification. Those deadlines are only achievable if it is decided in advance who reports, on what basis and with which details.
- Board-level accountability – management must approve the measures, oversee them and receive training; the accompanying decree (Cyberbeveiligingsbesluit) sets out that training obligation in more detail. Cybersecurity is explicitly no longer something that can be delegated entirely to "IT".
The supply chain counts
New and important is the emphasis on supply chain security. Organisations must look beyond their own environment to the suppliers and service providers that have access to their systems. A well-protected organisation with a poorly protected managed service provider is still vulnerable.
That produces an effect reaching well beyond the law itself: even if your organisation is not directly in scope, clients or supply chain partners may start imposing higher security requirements. Questionnaires in tenders, contractual demands about patching policy and recovery times, evidence that backups are actually tested – that is the direction of travel. Digital resilience is becoming steadily less optional.
Cybersecurity is more than a firewall
In practice, things rarely go wrong because a firewall or virus scanner is missing. They go wrong on the less visible parts:
- Patch management – are servers, workstations and network devices updated structurally, or only when there is time left over?
- Backups and recovery procedures – a backup that has never been restored is an assumption. Tested recovery is a measure.
- Access management – who holds administrator rights, who should no longer have them, and is multi-factor authentication (2FA/MFA) in place on the important entry points?
- Monitoring and logging – would you notice if something happened, and could you reconstruct it afterwards?
- Documentation – an up-to-date overview of systems, integrations and suppliers underpins every risk assessment and every fast incident report.
- Servers and workstations – outdated operating systems without security updates are a risk that is harder to ignore with this law in hand.
Start small, but start
The government itself stresses that organisations must first determine whether they fall under the law and, if so, take measures and register. For many, the first step is simpler than expected: map what you have, who can access it, what happens if it fails and how long recovery takes. That inventory produces a list of measures that can be tackled in order of risk.
How digitally resilient is your organisation?
Apptimate helps organisations assess and improve their IT environment in practical terms – server and workstation management, Linux and Windows administration, backup & recovery, access security and continuity. Not a thick report, but a concrete picture of where you stand and which steps deliver the most.
Would you like to know how your environment is doing? Get in touch for a no-obligation conversation.
More about the act itself at Digitale Overheid and the NCSC (Dutch).