Cybersecurity has long stopped being a luxury; it is a precondition for doing business safely. With NIS2 the European rules have been tightened considerably, and in the Netherlands they are now law: the Cyberbeveiligingswet came into force on 15 August 2026 and applies to more than 8,000 organisations. Not only large companies, but more and more SMEs are affected. The big questions: do you need to act, and are you ready?
NIS2 — the European directive (2022/2555) on network and information security, implemented in the Netherlands through the Cyberbeveiligingswet. It obliges designated organisations to manage risk (duty of care), report incidents within 24 hours (duty to notify), register with the supervisory authority and demonstrate board-level accountability.
When does NIS2 apply to you?
Many SMEs assume NIS2 only applies to large companies. In reality, medium-sized organisations are in scope too, for example if you operate in IT services, transport, healthcare, energy, manufacturing or waste management, or if you supply digital services or software. And even those not designated themselves get the requirements passed on: NIS2 obliges organisations to manage their supply chain, so your larger customers will ask for evidence. The free NIS2 scan gives a first answer in two minutes.
What NIS2 asks of your company
- Risk analysis and appropriate measures: MFA, encryption, backups, secure access.
- Endpoint security: computers, servers and mobile devices, with monitoring.
- Supply-chain management: knowing and recording how your suppliers handle your data and systems.
- Awareness and training across the organisation, including the board.
- An incident response plan, with an early warning to the NCSC within 24 hours.
In short: you must be able to demonstrate that you take cybersecurity seriously. The maximum fine runs up to 10 million euros or 2 percent of worldwide annual turnover, and directors are personally accountable for negligence.
Without stress and sky-high costs
Qteco helps SMEs towards NIS2 compliance step by step. Not with thick reports and endless consultancy, but pragmatically and in proportion to your company size and budget: a NIS2 readiness scan, a clear risk analysis with improvement plan, security of devices and systems, active monitoring, training for employees and accessible support from Eindhoven. Those who start now are ready before the first question from a customer or insurer.
Frequently asked questions
How do I know whether my company falls under NIS2?
That depends on your sector and size: the law targets medium-sized and large organisations in designated sectors, with exceptions for small providers in a key role. Qteco's NIS2 scan walks the decision tree for you; in doubt, a call with an engineer is the fastest answer.
What is the difference between the duty of care and the duty to notify?
The duty of care is about measures in advance: knowing and managing risks. The duty to notify is about what you do when things go wrong: an early warning of a significant incident within 24 hours, with a fuller notification within 72 hours.
I am not designated. Can I ignore NIS2?
Better not. Your customers that are designated must manage their supply chain and will ask you for evidence: MFA, backups, incident process. Those who can show it win tenders; those who cannot drop out.
Want to know where you stand? Take the free NIS2 scan and receive a personal report, or read how managed cybersecurity bundles the measures into one service.
Sources
- Richtlijn (EU) 2022/2555 (NIS2) — EUR-Lex (2022-12-27)
- Cyberbeveiligingswet (NIS2) — NCSC
- Cyberbeveiligingswet vanaf 15 augustus 2026 van kracht — Rijksoverheid (2026-07-07)
Ready to run worry-free?
Book a no-obligation introduction. We map your IT and security and show where the difference lies.
Book a call →
