← Back to overview

NIS2 & the Cybersecurity Act: What Dutch SMBs Must Do Now

The Dutch Cybersecurity Act took effect on 15 August 2026 — no transition period. Does it apply to your business, what do you need to arrange, and where do you start? A practical explainer for SMBs.

NIS2 and the Cybersecurity Act for Dutch SMBs

One deadline has already passed this year while many business owners still don't know if it applies to them: 15 August 2026. Since then, the Dutch Cybersecurity Act (Cyberbeveiligingswet) has been in force — the national implementation of the European NIS2 directive. Unlike most new regulation, there's no transition period: the obligations apply from day one.

An estimated 8,000 Dutch organisations fall directly under it, plus tens of thousands of suppliers indirectly through the chain. Yet a large share of SMBs still don't know whether they're covered. This explainer helps you find out — and shows what to do now.

Short answer in 3 minutes: not sure whether NIS2, the AI Act or GDPR applies to you? Take the free AI Compliance & Risk Scan — see your exposure per obligation instantly, with an honest report. No sales pitch.

What is the Cybersecurity Act (NIS2), exactly?

NIS2 is a European directive requiring organisations in vital and important sectors to get their digital resilience in order. The Netherlands implements this through the Cybersecurity Act (Cbw). The core of the law: a duty of care (appropriate technical and organisational measures), a duty to report significant incidents, mandatory registration with the supervisor/NCSC, and — critical for SMBs — supply-chain responsibility.

Importantly: the board is liable. NIS2 explicitly places responsibility with company leadership, and non-compliance carries substantial fines. This is no longer just an IT matter — it's a board-level topic.

Does my business fall under NIS2? Two routes

There are two ways you can be covered:

Route 1 — direct, based on sector + size. The law designates sectors as "essential" or "important": energy, transport, healthcare, drinking water, digital infrastructure, IT management (managed service providers), government, banking, postal services, waste management, chemicals, food, and digital providers. If you're in one of these sectors and medium-sized or larger (roughly 50+ employees or €10m+ revenue), you likely fall directly under the law.

Route 2 — indirect, through the supply chain. This is the route that catches SMBs off guard. Do you supply services or software to an organisation that does fall under NIS2 — a hospital, an energy company, a government body? Then that customer will soon require demonstrable cybersecurity measures from you, via its own supply-chain responsibility. Being small doesn't protect you if your large customer is covered.

Common misconception: "we're too small for NIS2." Maybe for route 1. But via route 2 (the supply chain), the law reaches far more SMBs than the ~8,000 directly covered.

What changed on 15 August 2026?

At the same time, the Critical Entities Resilience Act (Wwke) took effect, covering the physical resilience of critical providers. For most SMBs, the Cybersecurity Act is the relevant one.

NIS2 and the AI Act: two deadlines, the same year

2026 is a busy compliance year. Alongside NIS2, the first EU AI Act obligations are now live: AI literacy (mandatory since February 2025) and, since 2 August 2026, the transparency obligation (Article 50 — you must disclose when a customer is interacting with AI) and the requirements for high-risk AI systems. Both are active now, not future plans — alongside the NIS2 deadline, August 2026 was a packed month for compliance.

A practical checklist for SMBs

  1. Determine your position: route 1 (sector + size) or route 2 (supply chain)?
  2. Map your AI and data flows, and your suppliers — who processes your critical data?
  3. Run a risk assessment and close the biggest gaps (access management, backups, patching, MFA).
  4. Set up incident detection and a reporting process (who reports what, within what timeframe?).
  5. Register with the NCSC if you fall under the law.
  6. Assign responsibility at board level and document the policy.

Where to start

The trap is paralysis: the law looks big, so nothing happens. The way out is to start small with an overview. First know where you stand — which obligations affect you and how big your exposure is — then tackle the biggest risks. Want to understand the law itself first? Read what the Cybersecurity Act (NIS2) actually requires.

That's what our free AI Compliance & Risk Scan is for: in three minutes, see your exposure on NIS2, AI literacy, transparency and GDPR, with an honest report and a concrete first plan. Want us to implement it for you? Look at our Responsible AI service — we don't just advise, we implement.

Get started

The Cybersecurity Act has been in force since 15 August 2026 — with no transition period. Don't wait until a customer or regulator asks. Start by knowing where you stand.

Take the free AI Compliance & Risk Scan

Frequently asked questions

When did the Dutch Cybersecurity Act (NIS2) take effect?

On 15 August 2026, with no transition period. The obligations apply from day one.

Does NIS2 apply to my SMB?

Possibly directly, if you're in a designated sector and large enough, or indirectly through supply-chain responsibility if you supply an organisation that falls under the law.

What do I need to do for NIS2?

Determine whether you're in scope, register with the NCSC if required, put duty-of-care measures and incident reporting in place, and map your supplier chain.