Back to blogNIS2

The Dutch Cybersecurity Act goes live tomorrow — and uComply fully integrates it

uComply

Team uComply

Author

August 14, 2026

Published

Tomorrow, 15 August 2026, the Dutch Cybersecurity Act (Cyberbeveiligingswet) enters into force — the Dutch transposition of the European NIS2 directive. For thousands of organizations in the Netherlands, cybersecurity, risk management and incident reporting thereby become legal obligations rather than good intentions.

Ahead of that, we are announcing today that uComply has integrated the entire Dutch Cybersecurity Act — as a working framework, ready to use. In this article we briefly outline the main lines of the act. But above all we address the question that really matters: why does it pay off to treat the act not as a separate file, but to place it directly in your compliance tool — and how does uComply give shape to that?

A note on scope: this article is about the *Dutch* implementation of NIS2. NIS2 is an EU directive, and every member state transposes it into its own national law with its own timeline — it has been in force in Belgium since October 2024, and Germany implements it through its own NIS2 Implementation Act (NIS2-Umsetzungsgesetz). The dates below are specific to the Netherlands, but the underlying obligations are largely the same across the EU — and so is the way uComply helps you demonstrably meet them.

The act in brief

The Cybersecurity Act replaces the old Network and Information Systems Security Act (Wbni) and is much broader. It distinguishes two categories — essential and important entities — and translates into a number of concrete duties:

  • Duty of care (Art. 21): appropriate and proportionate measures to manage cyber risks — from risk policy and incident handling to business continuity, supply chain, encryption and access control.
  • Governance (Art. 24): the board approves the measures, is responsible and must have demonstrable knowledge.
  • Reporting obligation (Art. 25–30): report significant incidents within 24 hours, 72 hours and one month to your CSIRT and the competent authority.
  • Registration and supervision: entities are registered and supervised with enforcement.
  • Fines: up to €10 million or 2% of global annual turnover (essential entities) and €7 million or 1.4% (important entities).
  • The full elaboration — all measures, the articles and exactly who falls under the act — is on our in-depth Cybersecurity Act page.

    Why bringing a law into your compliance tool pays off so much

    Complying with the act is one thing. Being able to demonstrate that you comply is an entirely different story — and that is where the heart of the matter lies.

    The biggest challenge is not the technology, but demonstrability. In audits the same thing turns out time and again: organizations do take measures, but cannot sufficiently show what they do. Policy is drawn up but not maintained, risks are identified but improvement actions are left undone, measures are taken but the substantiation is missing. And that is exactly what the Cybersecurity Act asks for: demonstrable, structural control of your risks.

    A law kept as a separate file works against demonstrability. Keeping compliance information scattered across Excel, SharePoint, Teams and email leads to fragmentation. When an auditor or regulator asks for substantiation, gathering the evidence often takes more time than carrying out the measure itself.

    In your compliance tool, compliance becomes a living, repeatable process instead of a snapshot just before an audit. Risks, measures, policy and evidence are in one place and continuously up to date.

    Linking to your existing standards is the real accelerator. Already working with ISO 27001 or NEN 7510? Then you link the measures you have already implemented directly to the Cybersecurity Act. One control counts toward multiple frameworks at the same time — and the required evidence is instantly in order, without double work.

    The board becomes demonstrably in control. Article 24 explicitly requires this: directors must be able to show that they have insight into the risks and steer on them. That only works with central, up-to-date information.

    And because the act touches the entire digital backbone of the Netherlands — from hospitals and municipalities to energy, transport, data centers and manufacturing — an approach that makes the act manageable for everyone is valuable not just for one organization, but an accelerator for the whole chain.

    How uComply gives shape to this

    We have set up uComply so that you benefit from the above advantages immediately. The complete Dutch Cybersecurity Act sits in the platform as a working framework.

    The CBW/NIS2 control framework, ready to use

    The CBW/NIS2 framework developed by the NCSC is fully integrated into uComply. You don't start from a blank page, but with a complete, structured control framework that translates the duty of care and the legal obligations into concrete controls.

    Your existing measures count immediately

    This is the heart of the integration. Measures you have already implemented for ISO 27001, NEN 7510 or another standard link directly to the requirements of the Cybersecurity Act. One control, set up and maintained once, counts toward multiple frameworks at the same time — and the evidence the act requires is immediately in order. Not a separate file, but a single integrated management system.

    Reporting obligation as a workflow

    The 24-hour, 72-hour and one-month deadlines are no longer a loose note. You record incidents, monitor the reporting deadlines and keep the evidence around a notification complete and traceable.

    Evidence and board insight

    With the Flightdeck dashboard, leadership sees at a glance where the organization stands on risks, progress and compliance status — exactly the demonstrability that Article 24 asks of directors.

    Start today

    The act is coming. The obligations are clear. And the way to demonstrably meet them — without reconstructing a framework in Excel for months — is here too.

    Would you like to see how the Cybersecurity Act works in uComply and what demonstrable control means for your organization? Schedule a no-obligation demo or view our pricing. The full content of the act is on our Cybersecurity Act page.

    Frequently Asked Questions

    When does the Dutch Cybersecurity Act take effect?

    The Cybersecurity Act enters into force on 15 August 2026. From that moment, the duty of care, the reporting obligation, the registration and governance obligations and supervision apply.

    Is the Cybersecurity Act the same as NIS2?

    The Cyberbeveiligingswet is the Dutch transposition of the European NIS2 directive. The core is the same, but the national law specifically elaborates on supervision, reporting procedures and board accountability.

    What does "the act integrated in uComply" mean?

    The CBW/NIS2 control framework sits fully as a working control framework in uComply, linked to your existing standards, with a reporting-obligation workflow, evidence management and a board dashboard. Organizations can get started immediately from the moment the act takes effect, without building a framework themselves.