NIS2 in the Netherlands

Last updated: 21 July 2026

NIS2 in the Netherlands is settled law. The Dutch Senate, the Eerste Kamer, adopted the Cyberbeveiligingswet on 7 July 2026, and the act enters into force on 15 August 2026 with no transition period. For the roughly 8,000 organisations the Dutch government expects to fall in scope, the duty of care, the reporting clock and the registration requirement all begin on that same date.

What follows is where the NIS2 transposition in the Netherlands actually stands, who is caught, what the Cyberbeveiligingswet requires, and what the Dutch fines are, with the article and legal references you can check yourself.

The Netherlands Transposed NIS2 Nearly Two Years Late, in Force 15 August 2026

The Netherlands transposed the NIS2 Directive through the Cyberbeveiligingswet, adopted by the Eerste Kamer on 7 July 2026, signed on 8 July, published as Staatsblad 2026, 187, and in force from 15 August 2026 without a transition period.

The Union set the transposition deadline at 17 October 2024. The Netherlands crossed it by more than 20 months. The European Commission referred the country to the Court of Justice on 8 July 2026, the day after the Senate had already passed the law, asking the Court to impose a lump sum and daily penalty payments until transposition was complete. The referral will almost certainly be withdrawn once the Netherlands formally notifies its transposition, but it is an honest marker of how late this ran. Earlier drafts pointed to 1 July 2026, and before that to the start of the year. Both dates slipped. The operative date is 15 August 2026, and any guide still treating Dutch NIS2 as an open question, rather than a dated law awaiting only formal notification, is out of date. On the same day the Senate also passed the Wet weerbaarheid kritieke entiteiten, which transposes the companion CER Directive on physical resilience and reaches around 500 designated critical entities, a smaller and separate net from the one described here.

Supervision Splits Across the RDI, the NCSC and the Sector Regulators

Central supervision sits with the Rijksinspectie Digitale Infrastructuur (RDI), incident handling runs through the NCSC, and several sector regulators police their own domains.

Above the sector detail sit two fixed points. The NCSC runs incident handling as the national and sectoral CSIRT, and a single filing is forwarded to both the CSIRT and the relevant supervisor. The RDI is the horizontal default supervisor, including for most of central government. Everything else is a sector regulator keeping the patch it already had. Healthcare answers to the Inspectie Gezondheidszorg en Jeugd, transport and the water authorities to the Inspectie Leefomgeving en Transport, municipalities to their own CSIRT in the IBD, and finance to De Nederlandsche Bank and the AFM. For banks, insurers and investment firms, DORA is lex specialis under Article 4 of the Directive, so on ICT risk management and incident reporting those entities follow DORA, not the equivalent NIS2 duties. The practical read is that your supervisor depends on your sector, and the body you report an incident to is not always the one that can fine you.

Who Does NIS2 Apply To in the Netherlands

NIS2 in the Netherlands applies to essential and important entities across 18 sectors, generally organisations with at least 50 staff or more than €10 million in annual turnover or balance sheet total that operate in a listed sector.

The label you land on decides how closely you are watched, not what you have to do. Essential entities face proactive supervision, both before and after an incident. Important entities face reactive supervision, triggered by a signal or an incident. Both carry the same core obligations. The sectors split into a high-criticality group that includes energy, transport, banking, health, drinking water, digital infrastructure, public administration and space, and a second group covering postal services, waste, chemicals, food, several manufacturing lines, digital providers and research. Some entities are in scope regardless of size, including central and decentralised government, top-level domain registries, DNS providers and qualified trust service providers. Publicly funded higher education institutions were also opted in, though their obligations phase in on a later timetable than the 15 August start, one of the few genuine soft edges in the Dutch text.

The exemptions are where a lot of readers wrongly count themselves out, or in. Bodies whose main activity is national security, public security, defence or law enforcement are carved out under Article 5 of the Cyberbeveiligingswet. That covers the Ministry of Defence, the AIVD and MIVD intelligence services, the Openbaar Ministerie, the police and the veiligheidsregio’s. The judiciary, both chambers of parliament, and De Nederlandsche Bank as an institution are also outside the law, even though DNB supervises the financial sector under it. And the reach runs further than the direct list, because in-scope entities have to secure their supply chains, which pulls tens of thousands of Dutch suppliers into the requirements indirectly through their customers’ contracts. If you want to work out whether you are essential, important or out of scope before you read another word, does NIS2 apply to your company is the faster route, and our NIS2 Applicability Checker walks the sector and size tests in order.

Registration at mijn.ncsc.nl Becomes Mandatory on 15 August 2026

Entities in scope must register in the national entity register through the NCSC portal at mijn.ncsc.nl, and registration is mandatory from 15 August 2026.

Registration is a standalone duty, not a by-product of compliance. The Cyberbeveiligingswet scrapped the old designation procedure. No authority writes to tell you that you are covered. You self-assess, and if you are in, you register yourself. Access is via eHerkenning, the register pulls your organisation data from the KVK trade register, and you have two weeks to notify material changes. Miss the registration and the RDI can impose a fine or a last onder dwangsom for that alone, separate from any security failing. Voluntary registration has been open since October 2024, so the mechanism is not new, only the obligation is. Running the scope test in our NIS2 Applicability Checker before 15 August is the cheapest way to find out whether the clock applies to you.

The Zorgplicht Runs on Article 21 Measures and a 24-Hour Reporting Clock

The duty of care requires the risk-management measures listed in Article 21 of Directive (EU) 2022/2555, and a significant incident triggers an early warning within 24 hours, a full notification within 72 hours, and a final report within one month under Article 23.

Strip the article numbers away and the measures collapse into a few jobs. Prove you manage the risk, through a risk-analysis and information-security policy, incident handling, business continuity and backups. Prove you have looked past your own walls, through supply-chain security and secure acquisition and development. Prove the basics are in place, through cryptography, access control, multi-factor authentication and staff training. The Article 21 measures are the same ten categories the Directive sets for every member state, so a Dutch programme built against them travels rather than locking you into one jurisdiction. The reporting duty does not end at the 72-hour mark either, since the supervisor can require an interim report while the incident is still live. Sitting on top of all of it is board accountability under Article 24 of the Cyberbeveiligingswet, which puts approval and oversight of those measures on the management body itself, with training it must be able to evidence.

Dutch NIS2 Fines Reach €10 Million for Essential Entities and €25,000 for Directors

Under the Cyberbeveiligingswet, essential entities face fines up to €10 million or 2% of worldwide annual turnover, whichever is higher, important entities up to €7 million or 1.4%, and individual board members up to €25,000.

These are Dutch amounts, set in Dutch statute, and they are not a single EU-wide figure. The Directive fixes only minimum ceilings that member states may exceed, and the Netherlands took the floor for the turnover-linked tiers while adding its own flat caps. Essential-entity fines sit in Article 80 of the Cyberbeveiligingswet, important-entity fines in Article 87, a €1 million cap for domain-name registration providers in Article 91, and the €25,000 personal fine for board members in Article 93. A director who cannot show they were trained on the risks they are meant to oversee can be fined €25,000 in a personal capacity. A Cbw fine cannot stack on a GDPR fine for the same conduct, the no-double-penalty rule that Article 35 of the Directive carries, and for essential entities the RDI can go further and suspend a director from management functions.

No fine has been imposed under the Cyberbeveiligingswet. It cannot be, because the law only takes effect on 15 August 2026. Any tracker citing an early Dutch NIS2 penalty is either describing another member state or inventing one.

Scope and Registration Are the Work You Can Finish Before 15 August

The two steps that do not depend on any further Dutch guidance are working out your status and registering. Both can be done before the law takes effect, and both are cheap.

Determine whether you are an essential entity, an important entity or out of scope, using the 50-staff and €10 million thresholds against the 18 listed sectors, and remember the always-in-scope carve-ins for government and digital infrastructure. Register at mijn.ncsc.nl from 15 August 2026 through eHerkenning, and keep the entry current within the two-week window. Map your controls against the Article 21 measures and stand up the reporting workflow so a significant incident produces a 24-hour early warning without a scramble. Get the board its Article 24 training and document it, because the €25,000 exposure under Article 93 is personal, not corporate. If you need external help for the Dutch market, NIS2 providers in the Netherlands lists vetted options.

RegDossier

Making EU compliance almost enjoyable. Almost.

EU regulatory updates in your inbox every two weeks. Free.

Get the next briefing

Similar Posts