On 15 August 2026, the Dutch Cybersecurity Act (Cyberbeveiligingswet) enters into force. With it, the Netherlands transposes the European NIS2 directive into national law. For thousands of organizations, this brings new obligations in the areas of cybersecurity, risk management, incident reporting and board-level accountability.
Many organizations find themselves asking the same question: do we have to be fully compliant on 15 August?
That may not even be the right question.
The more important question is: *can you demonstrate that you manage your cyber risks, carry out improvement actions and actively work on digital resilience as an organization?*
It is precisely this demonstrable control that becomes the new norm under the Cybersecurity Act.
No more time to wait
The Cybersecurity Act takes effect on 15 August 2026. From that moment, organizations covered by the act must meet new obligations such as a duty of care, a reporting obligation and a registration obligation. In addition, the board is explicitly made responsible for managing cyber risks.
In practice, we see that many organizations are still grappling with questions such as:
These are valid questions. But those who only start once the act is in force are, in effect, already behind.
The biggest challenge is not security
Technical measures are of course important. Think of multi-factor authentication, backups, monitoring and vulnerability management.
But during audits, something else often turns out to be the biggest challenge: organizations cannot sufficiently demonstrate what they are doing.
And this is exactly where the focus of regulators is shifting. Not only to the question of whether measures exist, but above all to whether organizations can demonstrate that they structurally manage cyber risks. After all, the act requires organizations to take appropriate measures to manage risks to network and information systems and to prevent or limit incidents.
Demonstrability requires structure
Many organizations manage compliance information scattered across SharePoint, Teams, Excel files and email. This leads to fragmentation:
When an auditor or regulator asks for substantiation, gathering the information often takes more time than carrying out the measures themselves.
That is precisely why a structured approach is becoming increasingly important.
How uComply helps
uComply supports organizations in centrally managing compliance processes, risks, measures and evidence. With uComply, organizations can:
Make risks transparent
Identify risks, determine impact and likelihood, record control measures and monitor the progress of improvement actions from one central environment.
Centralize policy and control management
Policies, procedures, work instructions and controls are linked to the relevant standards, risks and measures.
Collect evidence easily
Audit evidence, documents and records are stored centrally and are immediately available when needed.
Follow up improvement actions
Open actions are assigned to owners, monitored and demonstrably followed up.
Provide management insight
Dashboards and reports — such as the Flightdeck dashboard — help executives gain insight into risks, progress and compliance status.
This creates not only an overview of what needs to be done, but above all of what has actually been done.
The board takes on a bigger role
An important difference from earlier legislation is the explicit involvement of the board. The Cybersecurity Act places responsibility for cyber risk management with the organization's leadership. Board members must have sufficient knowledge to assess risks and security measures and will need to follow appropriate training for this.
This means that cybersecurity is no longer solely an IT matter. Board members must be able to demonstrate that they:
Central information provision is essential for this as well.
Start with demonstrable control today
The organizations that will stand strongest are not necessarily those with the most documents or the largest security budgets. They are the organizations that can demonstrate:
Ultimately, the Cybersecurity Act is not only about complying with rules. It is about demonstrably managing risks and structurally improving digital resilience. And that is exactly where sustainable compliance begins.
Would you like to know how uComply can help you demonstrably manage cyber risks and prepare for the Cybersecurity Act? Schedule a no-obligation demonstration and discover what demonstrable control means for your organization.
Frequently Asked Questions
Does my organization have to be fully compliant on 15 August 2026?
More important than a snapshot of full compliance is that you can demonstrate you structurally manage cyber risks and actively work on improvement. Regulators focus above all on demonstrable, ongoing control.
What does "demonstrable control" mean in practice?
That at any moment you can show which risks are known, which measures have been taken, which improvements are in progress, who is responsible and how progress is monitored — with the underlying evidence centrally available.
Is the Cybersecurity Act the same as NIS2?
The Cyberbeveiligingswet is the Dutch transposition of the European NIS2 directive. The core is the same, but the national law specifically elaborates on supervision, reporting procedures and board accountability.
We currently use SharePoint and Excel. Is that a problem?
Not necessarily, but fragmented information makes demonstrability difficult. During an audit, gathering evidence then often takes more time than carrying out the measures themselves. A central, structured approach makes control demonstrable and repeatable.




