On 15 August 2026 the Cyberbeveiligingswet entered into force, the law by which the Netherlands implements the NIS2 Directive. It was adopted by the Senate on 7 July and replaces the earlier Wbni, which is repealed.
Around eight thousand organisations fall directly within scope: those operating in a sector listed in Annex I or II of the Directive, qualifying as medium or large enterprises and providing services in the Union. Certain high-risk entities are in scope regardless of size.
The number that matters is a different one
Through supply-chain responsibility, the law reaches an estimated one hundred and thirty-three thousand Dutch small and medium enterprises. Not because they are subject to it, but because they supply someone who is — and that someone will have to demand assurances they do not currently hold.
It is the same mechanism the GDPR triggered through Article 28: the formal obligation rests on a few, but contractual demands propagate downstream. Anyone advising SMEs will notice it first in the questionnaires their clients start receiving from their own customers.
What applies immediately
- obligation to register with the competent authority
- duty of care over technical and organisational measures
- incident reporting obligation
- governance obligations resting on the management body, which answers for them directly
That last point deserves attention: NIS2 places responsibility on the board, which must approve the measures and oversee their implementation. It is not an obligation that can be delegated to the IT function.
No grace period
The law firms commenting on the Act agree on one point: no transitional period is provided. From 15 August the obligations are enforceable, and anyone who has not acted before is already late.
Why it matters outside the Netherlands
NIS2 must be implemented by every Member State, and transposition dates are staggered. The Dutch Act is a preview of what will arrive elsewhere: the same structure of obligations, the same propagation along the chain, the same accountability for directors.
For a data protection officer the point of attention is the overlap with Article 33 GDPR. A single incident may trigger two notifications, to two different authorities, with different deadlines and recipients: the security notification under NIS2 and the personal data breach notification under the Regulation. They are distinct obligations, and one does not absorb the other.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free