NIS2 compliance & the Dutch cybersecurity act
From checkbox compliance to practical cyber resilience.
The Dutch Cybersecurity Act takes effect on 15 August 2026. Is your organisation in scope? Then you need to show that risks, incidents and accountability are managed in practice, not just on paper.

At a glance
- One plan for the law, your biggest cyber risks and the measures already in place.
- From 15 August 2026, your organisation must register, manage cyber risks and report serious incidents.
- Address the risks with real impact first, then the rest.
- Board members know what is expected of them and which decisions they own.
From legal duty to better security
The law requires risk management that demonstrably works. That starts with knowing where your organisation is vulnerable and who will act, not with a folder full of policies.
We use what is already in place, test whether it works and fix the most important gaps. The evidence for the regulator then matches the security work your people actually do.
You will know which risks you face, which measures actually work and what evidence you can show the regulator.
> We are subject to the Act ourselves
As a managed security provider, Neo Security falls under the Dutch Cybersecurity Act itself. The same registration duty, the same duty of care, the same reporting obligation.
Everything we advise you to do, we apply to ourselves. No textbook theory, but the approach we use every day.
What is NIS2 / the Cybersecurity Act?
NIS2 is the European cybersecurity directive. The Netherlands implements it through the Cybersecurity Act. The Act takes effect on 15 August 2026 for essential and important organisations in sectors including energy, transport, healthcare, government and digital infrastructure.
The requirements are substantial:
- Risk analyses
- Timely reporting of significant incidents
- Supply chain security
- Board responsibility and training
A regulator can intervene when an organisation fails to meet these obligations.
What needs to be in place now?
Determine whether the Act applies
Check sector, size and exceptions for each part of the organisation. This determines whether registration, duty of care and reporting obligations apply.
Register the organisation
Registration becomes mandatory on 15 August 2026. Prepare MijnNCSC, eHerkenning and the required organisation details now.
Make measures demonstrable
Record which risks you face, who owns them and how you check whether measures work. A policy document alone is not enough.
Practise reporting and governance
Set up the process for an initial report within 24 hours, train board members and rehearse who makes which decision during a significant incident.
From baseline to working measures
Step 1: scope and registration
ImmediatelyWe determine which parts of the organisation are in scope, who supervises them and what data is needed for registration through MijnNCSC.
Step 2: risk analysis and governance
First 30 daysWe link the biggest risks and supply chain dependencies to the people who must decide and act.
Step 3: measures and incident process
30 to 90 daysWe implement the most important measures, agree responsibilities with suppliers and set up the incident reporting process.
Step 4: test and improve
ContinuousWe test technology and crisis scenarios, retain the evidence and improve anything that does not work well enough.
Why does your organisation probably fall under NIS2?
Essential sectors:
Important sectors:
The fine print:
If your organisation operates in a designated sector and has 50 or more employees, or more than 10 million euros in annual turnover or balance sheet total, it is likely in scope. Some organisations are covered regardless of size. Assess each entity separately.
NIS2 as a business case: return on security investment
Direct benefits:
Lower insurance premiums
From the first year of implementation
Competitive advantage
In tenders (already now!)
Fewer incidents
Through better prevention
Faster recovery
When things go wrong
Indirect value:
- IT modernisation under the flag of compliance
- Improved processes that go beyond security
- Culture change towards risk awareness
- Innovation through safer digitalisation
The four pillars of working NIS2 compliance
1. Risk management that lives
Not an annual Excel exercise but continuous risk assessment. We implement practical tools and processes that your people actually use.
2. Incident response that works
A 24-hour reporting obligation demands well-oiled processes. We don't just build procedures but train your team with realistic exercises. When things go wrong, everyone knows what to do.
3. Supply chain security with teeth
From vendor assessment to contractual agreements – we make your chain resilient. Including practical monitoring so you can see what's happening.
4. Governance without bureaucracy
Clear responsibilities, workable reporting, directors who understand what they sign. Security governance that fits your organisation.
Frequently asked questions about NIS2
Does my organisation need to register?
If your organisation is in scope, it must register through MijnNCSC from 15 August 2026. Check each part of the organisation based on sector, size and exceptions.
When does the Cybersecurity Act take effect?
The Dutch Senate adopted the Act on 7 July 2026. The Cybersecurity Act takes effect on 15 August 2026. There is no general grace period.
What must happen immediately after an incident?
A significant incident must be reported as soon as possible and initially within 24 hours. The competent regulator depends on your sector. Board members must be trained and remain responsible for the approach.
Start today with your NIS2 advantage
Getting the law onto paper is not difficult. Making sure the measures actually work is where the effort lies.
We first establish whether the Act applies. You then get a concrete plan for registration, risks, incident reporting and technical improvements.