uComply

Home/Standards/Cybersecurity Act

In force since 15 August 2026

Dutch Cybersecurity Act (NIS2)

The Dutch transposition of the NIS2 directive has been in force since 15 August 2026. Discover the obligations — and how uComply has the entire act fully integrated, ready to use.

What is the Dutch Cybersecurity Act?

The Cybersecurity Act (Cyberbeveiligingswet) is the Dutch transposition of the European NIS2 directive. It replaces the old Network and Information Systems Security Act (Wbni) and requires essential and important entities to demonstrably manage their cyber risks, report incidents and make the board actively accountable.

The act entered into force on 15 August 2026. From that moment, the duty of care (Art. 21), the governance obligation for directors (Art. 24), the reporting obligation (Art. 25–30) and supervision apply. Non-compliance can lead to fines of up to €10 million or 2% of global annual turnover.

NIS2 across Europe — this page covers the Dutch law

NIS2 is a European directive; each member state transposes it into its own national law. This page describes the Dutch implementation — the Cyberbeveiligingswet. In other EU countries the same core obligations apply through a national law and timeline of their own — in force in Belgium since October 2024, and in Germany through its own NIS2-Umsetzungsgesetz.

Timeline of the act

2022

NIS2 adopted

The EU adopts the NIS2 directive as the successor to NIS (2016).

2026

Act published

The Cybersecurity Act is published in the Dutch Bulletin of Acts (2026, 187).

15 aug

In force

Duty of care, reporting obligation, governance and enforcement take effect.

Which organizations must comply with NIS2?

NIS2 applies to essential and important entities in the following sectors

Energy

🚆

Transport

🏦

Banking

🏥

Healthcare

💧

Drinking Water

💻

Digital Infrastructure

🏛️

Public Administration

🛰️

Space

Criteria: >50 employees OR >€10M revenue. Some organizations fall under NIS2 regardless of size.

Essential or important entity?

The act distinguishes two categories. Your category determines the supervisory regime and the maximum fine.

Essential entities

Large organizations in the most critical sectors (including energy, transport, drinking water, healthcare, digital infrastructure and government) and certain providers regardless of size, such as DNS service providers and top-level domain registries. They are subject to proactive supervision.

Fine up to €10 million or 2% of global annual turnover

Important entities

Medium and large organizations in the other designated sectors (including postal, waste, chemicals, food, manufacturing and digital providers). They are subject to reactive supervision — after an incident or signal.

Fine up to €7 million or 1.4% of global annual turnover

In doubt whether you fall under the act? That in itself is a reason to take scoping seriously now. In uComply you determine scope in a structured, demonstrable way.

The obligations: duty of care (Art. 21) and governance (Art. 24)

The act requires appropriate and proportionate measures based on an all-hazards approach — and a demonstrably involved board.

1

Risk management

Carry out systematic risk analysis and establish information security policy (Art. 21(3)(a)).

2

Incident handling & reporting

Handle incidents in a structured way and report significant incidents within 24 hours, 72 hours and one month (Art. 25–30).

3

Supply chain security

Manage the risks of your supply chain and direct suppliers (Art. 21(3)(d)).

4

Cryptography & encryption

Maintain policy on cryptography and, where appropriate, encryption (Art. 21(3)(h)).

5

Access & assets

Arrange personnel security, access control and asset management; apply MFA where appropriate (Art. 21(3)(i–j)).

6

Business continuity

Ensure backup management, recovery plans and crisis management (Art. 21(3)(c)).

7

Cyber hygiene & training

Secure basic cyber hygiene and cybersecurity training (Art. 21(3)(g)).

8

Assessing effectiveness

Periodically assess the effectiveness of your control measures (Art. 21(3)(f)).

9

Governance & board

The board approves the measures, holds demonstrable knowledge and follows appropriate training (Art. 24).

Reporting obligation: strict deadlines

For a significant incident you report without delay to your CSIRT and the competent authority.

24 hours

Early warning

First signal of the significant incident to the CSIRT and competent authority.

72 hours

Full notification

Notification with an initial assessment of severity, impact and indicators.

1 month

Final report

Detailed report with root cause and the measures taken.

Fines and sanctions for non-compliance

The Cybersecurity Act (NIS2) introduces significant fines for organizations that fail to comply.

Essential Entities

€10M / 2%

Up to €10 million or 2% of global annual revenue

Important Entities

€7M / 1.4%

Up to €7 million or 1.4% of global annual revenue

Additionally, directors can be held personally liable for non-compliance with the directive.

Ready to use

The entire act — integrated in uComply

Since 15 August 2026 the complete Dutch Cybersecurity Act sits in uComply as a working framework — ready to use and linked to your existing standards.

CBW/NIS2 control framework

The NCSC framework ready to use in the platform — not a blank page, but concrete controls.

Linked to your standards

One control counts toward ISO 27001, NEN 7510 and the Cybersecurity Act — the required evidence instantly in order.

Reporting as a workflow

Record incidents and monitor the 24-hour, 72-hour and one-month deadlines.

Board dashboard

With Flightdeck you demonstrably show what Article 24 asks of your board.

How uComply Helps with NIS2 Compliance

From gap analysis to certification: we guide you through the entire NIS2 compliance journey

NIS2 Gap Analysis

Identify where your organization stands against NIS2 requirements with our comprehensive gap analysis tool

AI Compliance Consultant

Our AI Consultant answers all your NIS2 questions and guides you step by step through implementation

Certification Guidance

Achieve the NIS2 Quality Mark with guidance from our certified auditors and consultants

NIS2 Quality Mark

The NIS2 Quality Mark

uComply is affiliated with the official NIS2 Quality Mark program. This quality mark demonstrates that your organization complies with the NIS2 directive and takes cybersecurity seriously.

  • Official recognition of NIS2 compliance
  • Increased trust from customers and partners
  • Demonstrable compliance for regulators

Frequently asked questions about the Cybersecurity Act

What is the Dutch Cybersecurity Act?

The Cybersecurity Act (Cyberbeveiligingswet) is the Dutch transposition of the European NIS2 directive. It replaces the old Network and Information Systems Security Act (Wbni) and requires essential and important entities to observe a duty of care (risk management), a reporting obligation for incidents and active board accountability.

When does the Dutch Cybersecurity Act take effect?

The Cybersecurity Act entered into force on 15 August 2026. From that moment, the duty of care (Art. 21), the governance obligation for directors (Art. 24), the reporting obligation (Art. 25–30) and supervision with enforcement apply.

Which organizations does the act apply to?

The act applies to essential and important entities in sectors such as energy, transport, drinking water, healthcare, digital infrastructure, government, space, postal, waste, chemicals, food and manufacturing. Medium and large organizations are usually in scope; some types of providers regardless of size.

What are the reporting deadlines for a significant incident?

For a significant incident: an early warning within 24 hours, a full notification with initial assessment within 72 hours and a final report within one month — to your CSIRT and the competent authority.

What are the fines for non-compliance?

For essential entities, up to 10 million euros or 2% of global annual turnover; for important entities, up to 7 million euros or 1.4%. In addition, directors are explicitly responsible for managing cyber risks.

How does uComply help with the Cybersecurity Act?

uComply has the entire Dutch Cybersecurity Act integrated as a working CBW/NIS2 control framework. The platform links the act to existing standards such as ISO 27001 and NEN 7510, supports the reporting-obligation workflow and, with the Flightdeck dashboard, demonstrably shows what Article 24 asks of directors.

Start with the Cybersecurity Act today

Discover how uComply helps you demonstrably comply with the Dutch Cybersecurity Act — from scope and duty of care to reporting and the board.