One deadline already passed this year while many business owners still don't know whether it applies to them: 15 August 2026. Since then, the Dutch Cybersecurity Act (Cyberbeveiligingswet) has been in force — the Netherlands' national implementation of the EU's NIS2 directive. Unlike most regulation, there's no transition period: the obligations apply from day one.
An estimated 8,000 Dutch organisations fall directly in scope, plus tens of thousands of suppliers indirectly through the supply chain. Yet a large share of SMEs still don't know whether they're among them. This explainer helps you find out — and shows what you can do right now.
What is the Cybersecurity Act (NIS2), exactly?
NIS2 is an EU directive requiring organisations in vital and important sectors to get their digital resilience in order. The Netherlands transposes this into the Cybersecurity Act (Cbw). Its core: a duty of care (appropriate technical and organisational measures), a duty to report significant incidents, mandatory registration with the supervisor/the NCSC, and — critical for SMEs — supply-chain accountability.
Important: the board is liable. NIS2 explicitly places responsibility with company leadership, and non-compliance carries substantial fines. This is no longer an IT-department matter — it's a boardroom topic.
Does NIS2 apply to my company? The two routes
There are two ways you can fall in scope:
Route 1 — direct, by sector and size. The law designates sectors as "essential" or "important": energy, transport, healthcare, drinking water, digital infrastructure, ICT management (managed service providers), government, banking, postal services, waste management, chemicals, food, and digital providers. If you sit in one of these sectors and are mid-sized or larger (roughly 50+ employees or €10M+ revenue), you likely fall directly in scope.
Route 2 — indirect, through the supply chain. This is the route that catches SMEs off guard. If you supply services or software to an organisation that IS in scope for NIS2 — a hospital, an energy company, a government body — that customer will require demonstrable cyber measures from YOU, via its own supply-chain accountability. Being small doesn't protect you if your biggest customer is in scope.
What concretely changed on 15 August 2026?
- Duty of care: you must take appropriate measures against cyber risks — risk assessment, access management, backups, incident handling, supply-chain security.
- Duty to report: significant incidents must be reported quickly (an initial report is typically due within 24 hours).
- Registration: in-scope entities must register with the supervisor/the NCSC — from the effective date, with no grace period.
- Board liability: leadership is accountable and must demonstrably steer cyber resilience.
At the same time, the Critical Entities Resilience Act (Wwke) also took effect, covering the physical resilience of critical suppliers. For most SMEs, the Cybersecurity Act is the relevant one.
NIS2 and the EU AI Act: two deadlines, the same year
2026 is a busy compliance year. Alongside NIS2, the first EU AI Act obligations are now live too: AI literacy (mandatory since February 2025) and, since 2 August 2026, the transparency obligation (Article 50 — you must disclose when a customer is interacting with AI) and the requirements for high-risk AI systems. Both are active now, not future plans — alongside the NIS2 deadline, August 2026 is a busy month for compliance.
Practical checklist for SMEs
- Determine your position: route 1 (sector + size) or route 2 (supply chain)?
- Map your AI and data flows, and your suppliers — who processes your critical data?
- Run a risk assessment and close the biggest gaps (access management, backups, patching, MFA).
- Set up incident detection and a reporting process (who reports what, within what deadline?).
- Register with the NCSC if you're in scope.
- Assign responsibility at board level and document the policy.
Where to start
The trap is paralysis: the law looks big, so nothing happens. The way out is starting small with an overview. First know where you stand — which obligations affect you and how big your exposure is — then tackle the biggest risks in a targeted way.
That's what our free AI Compliance & Risk Scan is for: in three minutes you'll see your exposure on NIS2, AI literacy, transparency and the GDPR, with an honest report and a concrete first move. Want us to carry it out? Take a look at our Responsible AI service — we don't just advise, we implement.
Get started
The 15 August 2026 deadline has already passed. Start with knowing where you stand.