< Back to all clusters
[TECHNOLOGY] · Netherlands · 2 sources

Netherlands to enforce EU NIS2 cyber‑security law on 8,000 organisations from 2026

The European Union’s NIS2 directive, published in December 2022, sets stricter cyber‑security requirements for a broader range of entities than its 2016 predecessor. The Netherlands will translate the directive into national law through the Cyberbeveiligingswet, which takes effect on 15 August 2026.

The new law will apply to roughly 8,000 Dutch organisations that provide essential or important services, including energy, transport, health care, water supply, postal and waste management, food production and digital service providers. Obligations include a registration duty with the National Cyber Security Centre, a risk‑management and incident‑reporting regime (24‑hour initial notice, full report within 72 hours), and personal liability for directors who fail to ensure compliance. Cyber‑security responsibility shifts from purely IT departments to the board level, and organisations must assess the resilience of their entire supply chain, affecting suppliers, MSPs, cloud providers and other partners.

A recent Cegeka survey of 245 manufacturing firms found that almost one‑third are insufficiently prepared for the tightened standards, raising concerns about a widening gap between early adopters and laggards. The government’s first‑chamber approval on 7 July and the forthcoming implementation give organisations limited time to conduct audits, strengthen governance and train board members.