One deadline has already passed this year while many business owners still don't know if it applies to them: 15 August 2026. Since then, the Dutch Cybersecurity Act (Cyberbeveiligingswet) has been in force — the national implementation of the European NIS2 directive. Unlike most new regulation, there's no transition period: the obligations apply from day one.
An estimated 8,000 Dutch organisations fall directly under it, plus tens of thousands of suppliers indirectly through the chain. Yet a large share of SMBs still don't know whether they're covered. This explainer helps you find out — and shows what to do now.
What is the Cybersecurity Act (NIS2), exactly?
NIS2 is a European directive requiring organisations in vital and important sectors to get their digital resilience in order. The Netherlands implements this through the Cybersecurity Act (Cbw). The core of the law: a duty of care (appropriate technical and organisational measures), a duty to report significant incidents, mandatory registration with the supervisor/NCSC, and — critical for SMBs — supply-chain responsibility.
Importantly: the board is liable. NIS2 explicitly places responsibility with company leadership, and non-compliance carries substantial fines. This is no longer just an IT matter — it's a board-level topic.
Does my business fall under NIS2? Two routes
There are two ways you can be covered:
Route 1 — direct, based on sector + size. The law designates sectors as "essential" or "important": energy, transport, healthcare, drinking water, digital infrastructure, IT management (managed service providers), government, banking, postal services, waste management, chemicals, food, and digital providers. If you're in one of these sectors and medium-sized or larger (roughly 50+ employees or €10m+ revenue), you likely fall directly under the law.
Route 2 — indirect, through the supply chain. This is the route that catches SMBs off guard. Do you supply services or software to an organisation that does fall under NIS2 — a hospital, an energy company, a government body? Then that customer will soon require demonstrable cybersecurity measures from you, via its own supply-chain responsibility. Being small doesn't protect you if your large customer is covered.
What changed on 15 August 2026?
- Duty of care: you must take appropriate measures against cyber risks — risk assessment, access management, backups, incident handling, supply-chain security.
- Duty to report: significant incidents must be reported quickly (an initial report is typically due within 24 hours).
- Registration: entities covered by the law must register with the supervisor/NCSC, from the effective date, with no grace period.
- Board liability: leadership is responsible and must demonstrably steer cyber resilience.
At the same time, the Critical Entities Resilience Act (Wwke) took effect, covering the physical resilience of critical providers. For most SMBs, the Cybersecurity Act is the relevant one.
NIS2 and the AI Act: two deadlines, the same year
2026 is a busy compliance year. Alongside NIS2, the first EU AI Act obligations are now live: AI literacy (mandatory since February 2025) and, since 2 August 2026, the transparency obligation (Article 50 — you must disclose when a customer is interacting with AI) and the requirements for high-risk AI systems. Both are active now, not future plans — alongside the NIS2 deadline, August 2026 was a packed month for compliance.
A practical checklist for SMBs
- Determine your position: route 1 (sector + size) or route 2 (supply chain)?
- Map your AI and data flows, and your suppliers — who processes your critical data?
- Run a risk assessment and close the biggest gaps (access management, backups, patching, MFA).
- Set up incident detection and a reporting process (who reports what, within what timeframe?).
- Register with the NCSC if you fall under the law.
- Assign responsibility at board level and document the policy.
Where to start
The trap is paralysis: the law looks big, so nothing happens. The way out is to start small with an overview. First know where you stand — which obligations affect you and how big your exposure is — then tackle the biggest risks. Want to understand the law itself first? Read what the Cybersecurity Act (NIS2) actually requires.
That's what our free AI Compliance & Risk Scan is for: in three minutes, see your exposure on NIS2, AI literacy, transparency and GDPR, with an honest report and a concrete first plan. Want us to implement it for you? Look at our Responsible AI service — we don't just advise, we implement.
Get started
The Cybersecurity Act has been in force since 15 August 2026 — with no transition period. Don't wait until a customer or regulator asks. Start by knowing where you stand.
Take the free AI Compliance & Risk Scan
Frequently asked questions
When did the Dutch Cybersecurity Act (NIS2) take effect?
On 15 August 2026, with no transition period. The obligations apply from day one.
Does NIS2 apply to my SMB?
Possibly directly, if you're in a designated sector and large enough, or indirectly through supply-chain responsibility if you supply an organisation that falls under the law.
What do I need to do for NIS2?
Determine whether you're in scope, register with the NCSC if required, put duty-of-care measures and incident reporting in place, and map your supplier chain.