All news
Regulation August 15, 2026 5 min

NIS2 is law in the Netherlands, with no grace period

From 15 August: registration, duty of care, incident reporting and board-level accountability. Eight thousand organisations directly, one hundred and thirty-three thousand through contractual contagion

On 15 August 2026 the Cyberbeveiligingswet entered into force, the law by which the Netherlands implements the NIS2 Directive. It was adopted by the Senate on 7 July and replaces the earlier Wbni, which is repealed.

Around eight thousand organisations fall directly within scope: those operating in a sector listed in Annex I or II of the Directive, qualifying as medium or large enterprises and providing services in the Union. Certain high-risk entities are in scope regardless of size.

The number that matters is a different one

Through supply-chain responsibility, the law reaches an estimated one hundred and thirty-three thousand Dutch small and medium enterprises. Not because they are subject to it, but because they supply someone who is — and that someone will have to demand assurances they do not currently hold.

It is the same mechanism the GDPR triggered through Article 28: the formal obligation rests on a few, but contractual demands propagate downstream. Anyone advising SMEs will notice it first in the questionnaires their clients start receiving from their own customers.

What applies immediately

  • obligation to register with the competent authority
  • duty of care over technical and organisational measures
  • incident reporting obligation
  • governance obligations resting on the management body, which answers for them directly

That last point deserves attention: NIS2 places responsibility on the board, which must approve the measures and oversee their implementation. It is not an obligation that can be delegated to the IT function.

No grace period

The law firms commenting on the Act agree on one point: no transitional period is provided. From 15 August the obligations are enforceable, and anyone who has not acted before is already late.

Why it matters outside the Netherlands

NIS2 must be implemented by every Member State, and transposition dates are staggered. The Dutch Act is a preview of what will arrive elsewhere: the same structure of obligations, the same propagation along the chain, the same accountability for directors.

For a data protection officer the point of attention is the overlap with Article 33 GDPR. A single incident may trigger two notifications, to two different authorities, with different deadlines and recipients: the security notification under NIS2 and the personal data breach notification under the Regulation. They are distinct obligations, and one does not absorb the other.

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Regulation
26the article nobody signs before broadcasting

Who answers for the live stream of the under-14 match? Sweden answers the question nobody asks

On 25 August the Swedish authority published guidance on streaming youth sport. Many clubs stream children's matches online, and the guidance sets out the factors that decide what is allowed. But the part worth reading is the other one: responsibility when the municipality owns the venue and the club wants to install cameras.

Aug 25, 2026New 5 min
Regulation
24months after which a past incident should not be used

The score they refuse your credit with can be requested, and it has to be explained

On 19 August the CNIL translated for the public its May 2026 recommendation on assessing creditworthiness. Inside are three numbers and one principle that concern anyone doing scoring: twenty-four months for past incidents, six months for the data of a refused application, and a right of access to the score that cannot be dismissed by invoking trade secrecy.

Aug 19, 2026New 6 min
Regulation
2EDPB criteria and the DPIA becomes mandatory

In schools, advertising trackers are prohibited — and consent has nothing to do with it

On 24 August the CNIL published its rules for the digital workspaces used in schools. The decisive point is not the protection of minors but a principle of administrative law: the neutrality of the public education service includes commercial neutrality, so trackers used for advertising or profiling are prohibited in principle. If the tool has them, the controller must switch them off.

Aug 24, 2026New 6 min