Back to blogNIS2

Dutch Cybersecurity Act: demonstrable control becomes the new norm

uComply

Team uComply

Author

July 23, 2026

Published

On 15 August 2026, the Dutch Cybersecurity Act (Cyberbeveiligingswet) enters into force. With it, the Netherlands transposes the European NIS2 directive into national law. For thousands of organizations, this brings new obligations in the areas of cybersecurity, risk management, incident reporting and board-level accountability.

Many organizations find themselves asking the same question: do we have to be fully compliant on 15 August?

That may not even be the right question.

The more important question is: *can you demonstrate that you manage your cyber risks, carry out improvement actions and actively work on digital resilience as an organization?*

It is precisely this demonstrable control that becomes the new norm under the Cybersecurity Act.

No more time to wait

The Cybersecurity Act takes effect on 15 August 2026. From that moment, organizations covered by the act must meet new obligations such as a duty of care, a reporting obligation and a registration obligation. In addition, the board is explicitly made responsible for managing cyber risks.

In practice, we see that many organizations are still grappling with questions such as:

  • Do we actually fall under the act?
  • Which risks do we need to record?
  • Do we have sufficient policy?
  • How do we maintain evidence?
  • Which suppliers introduce risks?
  • These are valid questions. But those who only start once the act is in force are, in effect, already behind.

    The biggest challenge is not security

    Technical measures are of course important. Think of multi-factor authentication, backups, monitoring and vulnerability management.

    But during audits, something else often turns out to be the biggest challenge: organizations cannot sufficiently demonstrate what they are doing.

  • Policy has been drawn up, but it is not maintained.
  • Risks have been identified, but improvement actions are not followed up.
  • Measures have been taken, but the substantiation is missing.
  • And this is exactly where the focus of regulators is shifting. Not only to the question of whether measures exist, but above all to whether organizations can demonstrate that they structurally manage cyber risks. After all, the act requires organizations to take appropriate measures to manage risks to network and information systems and to prevent or limit incidents.

    Demonstrability requires structure

    Many organizations manage compliance information scattered across SharePoint, Teams, Excel files and email. This leads to fragmentation:

  • risk analyses are stored in different locations;
  • policy is not centrally managed;
  • action points fall out of sight;
  • evidence is hard to retrieve.
  • When an auditor or regulator asks for substantiation, gathering the information often takes more time than carrying out the measures themselves.

    That is precisely why a structured approach is becoming increasingly important.

    How uComply helps

    uComply supports organizations in centrally managing compliance processes, risks, measures and evidence. With uComply, organizations can:

    Make risks transparent

    Identify risks, determine impact and likelihood, record control measures and monitor the progress of improvement actions from one central environment.

    Centralize policy and control management

    Policies, procedures, work instructions and controls are linked to the relevant standards, risks and measures.

    Collect evidence easily

    Audit evidence, documents and records are stored centrally and are immediately available when needed.

    Follow up improvement actions

    Open actions are assigned to owners, monitored and demonstrably followed up.

    Provide management insight

    Dashboards and reports — such as the Flightdeck dashboard — help executives gain insight into risks, progress and compliance status.

    This creates not only an overview of what needs to be done, but above all of what has actually been done.

    The board takes on a bigger role

    An important difference from earlier legislation is the explicit involvement of the board. The Cybersecurity Act places responsibility for cyber risk management with the organization's leadership. Board members must have sufficient knowledge to assess risks and security measures and will need to follow appropriate training for this.

    This means that cybersecurity is no longer solely an IT matter. Board members must be able to demonstrate that they:

  • have insight into risks;
  • track improvement measures;
  • make decisions based on up-to-date information;
  • actively steer on digital resilience.
  • Central information provision is essential for this as well.

    Start with demonstrable control today

    The organizations that will stand strongest are not necessarily those with the most documents or the largest security budgets. They are the organizations that can demonstrate:

  • which risks are known;
  • which measures have been taken;
  • which improvements are still in progress;
  • who is responsible;
  • how progress is monitored.
  • Ultimately, the Cybersecurity Act is not only about complying with rules. It is about demonstrably managing risks and structurally improving digital resilience. And that is exactly where sustainable compliance begins.

    Would you like to know how uComply can help you demonstrably manage cyber risks and prepare for the Cybersecurity Act? Schedule a no-obligation demonstration and discover what demonstrable control means for your organization.

    Frequently Asked Questions

    Does my organization have to be fully compliant on 15 August 2026?

    More important than a snapshot of full compliance is that you can demonstrate you structurally manage cyber risks and actively work on improvement. Regulators focus above all on demonstrable, ongoing control.

    What does "demonstrable control" mean in practice?

    That at any moment you can show which risks are known, which measures have been taken, which improvements are in progress, who is responsible and how progress is monitored — with the underlying evidence centrally available.

    Is the Cybersecurity Act the same as NIS2?

    The Cyberbeveiligingswet is the Dutch transposition of the European NIS2 directive. The core is the same, but the national law specifically elaborates on supervision, reporting procedures and board accountability.

    We currently use SharePoint and Excel. Is that a problem?

    Not necessarily, but fragmented information makes demonstrability difficult. During an audit, gathering evidence then often takes more time than carrying out the measures themselves. A central, structured approach makes control demonstrable and repeatable.