Qteco
Services01 Sovereign Cloud02 NIS203 Security Check04 Investment05 References06 News07 Contact08
Client Portal Book a call
NIS2 · Dutch Cybersecurity Act

NIS2 and the Dutch Cybersecurity Act: what your organisation must arrange.

The European NIS2 directive has become law in the Netherlands: the Cyberbeveiligingswet has applied since 15 August 2026 to more than 8,000 organisations. Those in scope must demonstrably manage risks, report incidents within 24 hours and register with the supervisory authority. Directors are personally responsible.

This page explains who the law applies to, what exactly it requires, how it differs from ISO 27001 and how to become demonstrably compliant in ten steps. Want to know first whether you are in scope? The free NIS2 scan walks you through the official decision tree in two minutes.

Since 15 August 2026 — Cybersecurity Act in force Over 8,000 organisations — directly designated Report within 24 hours — early warning Up to € 10 million — or 2 percent of turnover
Who is in scope

Does your organisation fall under NIS2?

Three questions determine the answer, in this order. Merely operating in a broad sector is not enough: the precise activity must be listed in annex 1 or 2 of the law, and the organisation must be medium-sized or large. An industry code alone is not decisive. The official self-assessment of the Dutch government remains leading.

01

Special digital provider or government?

Telecom, trust services, DNS and domain registration and central and local government are often in scope regardless of size.

02

Is your activity listed in annex 1 or 2?

Annex 1 (highly critical): energy, transport, banking, healthcare, drinking water, digital infrastructure, ICT service management such as MSPs, government, space. Annex 2: postal services, waste, chemicals, food, certain manufacturing, digital providers, research.

03

Medium-sized or large by the EU definition?

From 50 employees or more than 10 million euros in turnover or balance sheet total. Small organisations are usually out of scope, unless designated or covered by step 1.

What the law requires

Four duties, one accountable board.

The Cybersecurity Act does not prescribe products but outcomes you must be able to demonstrate. These four obligations form the core.

Duty of care

Appropriate and proportionate measures to manage risks to network and information systems: from risk analysis and access management to backup, supply-chain security and training. The ten measures are listed below as a checklist.

Article 21 of the directiveProvable, not just present

Duty to notify

A significant incident is reported in three steps: an early warning within 24 hours, an incident notification within 72 hours and a final report within a month. That requires an incident plan that is ready before the incident.

24 hours · 72 hours · 1 monthNotification to the NCSC

Registration duty

Designated organisations register with the supervisory authority for their sector and keep that information current. The authority can request documents and carry out audits; for essential entities also without cause.

Supervisor per sectorProactive or reactive supervision

Board accountability

The board approves the measures, supervises their implementation and follows training itself. In case of negligence the authority can hold directors personally accountable and, at essential entities, temporarily remove them from office.

Training for the boardPersonal liability
NIS2 checklist for SMEs

The ten measures of the duty of care, as a checklist.

Article 21 of the directive names ten topics every designated organisation must cover. This is how Qteco translates them to the practice of an organisation with 20 to 250 employees.

01

Risk analysis and security policy

An up-to-date overview of systems, data, accounts and suppliers, with the risks and who is responsible for them.

02

Incident handling

An incident and data-breach plan with roles, contact details and the 24- and 72-hour reporting deadlines, rehearsed at least annually.

03

Continuity and backup

Independent, immutable backups of servers, cloud and e-mail, with a restore test in the past twelve months.

04

Supply-chain security

Security agreements in processing and supplier contracts and insight into how your MSP, software vendors and cloud services demonstrate their security.

05

Secure procurement, development and maintenance

Central patch and update control and a process for reporting and fixing vulnerabilities.

06

Measuring effectiveness

Logging that is actually reviewed, periodic access reviews and an annual management review of the measures.

07

Cyber hygiene and training

Annual training for employees and the board, with phishing simulations and clear basic rules.

08

Cryptography

Encryption of devices, connections and backups, and a policy for managing keys and certificates.

09

Personnel, access and assets

Access revoked immediately on departure, admin accounts separated from daily accounts, and a complete inventory of devices.

10

MFA and secured communication

Multi-factor authentication for all users, protected e-mail domains and secured channels for emergency communication.

Law or standard

NIS2 and ISO 27001: what is the difference?

They are often mentioned in one breath, but they are different things. NIS2 is a law you must comply with; ISO 27001 is a standard you can choose. Those who have implemented ISO 27001 well cover most of the duty of care, but not the notification and registration duties.

ISO 27001 NIS2 / Cybersecurity Act
Nature Voluntary international standard for a management system Law, mandatory for designated organisations
Evidence Certificate after an audit by a certification body Government supervision, documents on request, audits
Notification No statutory reporting deadline 24 hours, 72 hours and one month, to the NCSC
Board Management involvement as a standard requirement Personal liability and mandatory training
Overlap Covers most of the duty of care; a certificate is strong evidence Additionally requires registration, a notification process and supply-chain agreements
For SMEs Worthwhile when customers require it; a 6- to 12-month project Mandatory if designated; the ten measures are achievable without a certificate
How Qteco helps

From scan to demonstrably compliant, without thick reports.

As an MSP, Qteco itself runs an environment that falls under annex 1 and applies the measures daily. We bring that practice to your organisation: pragmatic, in proportion to your size and with evidence a supervisor, insurer or customer can read.

01

NIS2 readiness scan

The free scan determines your legal status (A to D), tests sixteen basic measures and delivers a report with an action plan for two weeks, thirty and ninety days.

02

Risk analysis and improvement plan

We translate the ten measures into concrete steps in your environment, prioritising what removes the most risk: MFA, backup, patching, incident plan.

03

Demonstrably compliant

Managed IT and managed cybersecurity deliver the measures and the evidence: reports, logging, tested recovery and an evidence file of nine documents any supervisor may request.

FAQ

Frequently asked questions about NIS2.

What is the Cyberbeveiligingswet and when did it come into force?

The Cyberbeveiligingswet is the Dutch implementation of the European NIS2 directive and replaces the Wet beveiliging netwerk- en informatiesystemen. The Senate approved it on 7 July 2026; the law entered into force on 15 August 2026. From that moment the duty of care, the duty to notify and the registration duty apply to more than 8,000 organisations.

Does my company fall under NIS2?

That depends on three things: whether your precise activity is listed in annex 1 or 2 of the law, whether your organisation is medium-sized or large (from 50 employees or 10 million euros in turnover) and whether you have been designated as a special provider or critical entity. Qteco’s free NIS2 scan walks through that decision tree for you; the official self-assessment of the Dutch government remains leading.

Within how many hours must I report an incident?

A significant incident is reported to the NCSC within 24 hours as an early warning, followed by an incident notification with initial assessment within 72 hours and a final report within a month. If personal data is involved, the GDPR notification to the Dutch Data Protection Authority within 72 hours applies as well.

Does NIS2 also apply to suppliers of companies that are in scope?

Not directly, but in practice yes. Designated organisations must manage the risks in their supply chain and may therefore impose security requirements on suppliers: MFA, backups, an incident process and evidence of them. Those who supply healthcare, energy, government, banks or large industry get those questions in tenders and contracts.

What are the fines and the liability of directors?

For essential entities up to 10 million euros or 2 percent of worldwide annual turnover, for important entities up to 7 million euros or 1.4 percent, whichever is higher. Directors must approve the measures and supervise them; in case of negligence they can be held personally accountable and, at essential entities, be temporarily removed from office.

Is ISO 27001 the same as NIS2 compliance?

No. ISO 27001 is a voluntary standard with a certificate; NIS2 is a law with supervision. A well-implemented ISO 27001 management system covers most of the duty of care and is strong evidence, but registration, the notification process with the 24- and 72-hour deadlines and supply-chain agreements must be arranged separately. Conversely, a certificate is not required to comply with NIS2.

See also

The measures behind the law.

NIS2 asks for working security, not paper. These services deliver the measures from the checklist, managed by one team.

Background in the news: NIS2 is coming: what does it mean for your SME?

Start today

Know where you stand within two minutes.

Take the free NIS2 scan and receive a personal report with your legal status, the legislation matrix and an action plan. Or book a call with an engineer right away.