← Back to overview

NIS2 & the Dutch Cybersecurity Act: what SMEs must arrange now

Since 15 August 2026 the Dutch Cybersecurity Act has been in force — with no transition period. Does it apply to your company, what do you need to arrange, and where do you start? A practical explainer for SMEs.

NIS2 and the Cybersecurity Act for SMEs

One deadline already passed this year while many business owners still don't know whether it applies to them: 15 August 2026. Since then, the Dutch Cybersecurity Act (Cyberbeveiligingswet) has been in force — the Netherlands' national implementation of the EU's NIS2 directive. Unlike most regulation, there's no transition period: the obligations apply from day one.

An estimated 8,000 Dutch organisations fall directly in scope, plus tens of thousands of suppliers indirectly through the supply chain. Yet a large share of SMEs still don't know whether they're among them. This explainer helps you find out — and shows what you can do right now.

Short answer in 3 minutes: not sure whether NIS2, the EU AI Act or the GDPR applies to you? Take the free AI Compliance & Risk Scan — you'll see your exposure per obligation immediately, with an honest report. No sales pitch.

What is the Cybersecurity Act (NIS2), exactly?

NIS2 is an EU directive requiring organisations in vital and important sectors to get their digital resilience in order. The Netherlands transposes this into the Cybersecurity Act (Cbw). Its core: a duty of care (appropriate technical and organisational measures), a duty to report significant incidents, mandatory registration with the supervisor/the NCSC, and — critical for SMEs — supply-chain accountability.

Important: the board is liable. NIS2 explicitly places responsibility with company leadership, and non-compliance carries substantial fines. This is no longer an IT-department matter — it's a boardroom topic.

Does NIS2 apply to my company? The two routes

There are two ways you can fall in scope:

Route 1 — direct, by sector and size. The law designates sectors as "essential" or "important": energy, transport, healthcare, drinking water, digital infrastructure, ICT management (managed service providers), government, banking, postal services, waste management, chemicals, food, and digital providers. If you sit in one of these sectors and are mid-sized or larger (roughly 50+ employees or €10M+ revenue), you likely fall directly in scope.

Route 2 — indirect, through the supply chain. This is the route that catches SMEs off guard. If you supply services or software to an organisation that IS in scope for NIS2 — a hospital, an energy company, a government body — that customer will require demonstrable cyber measures from YOU, via its own supply-chain accountability. Being small doesn't protect you if your biggest customer is in scope.

Common mistake: "we're too small for NIS2." Maybe for route 1. But through route 2 (the supply chain), the law reaches far more SMEs than just the ~8,000 directly in scope.

What concretely changed on 15 August 2026?

At the same time, the Critical Entities Resilience Act (Wwke) also took effect, covering the physical resilience of critical suppliers. For most SMEs, the Cybersecurity Act is the relevant one.

NIS2 and the EU AI Act: two deadlines, the same year

2026 is a busy compliance year. Alongside NIS2, the first EU AI Act obligations are now live too: AI literacy (mandatory since February 2025) and, since 2 August 2026, the transparency obligation (Article 50 — you must disclose when a customer is interacting with AI) and the requirements for high-risk AI systems. Both are active now, not future plans — alongside the NIS2 deadline, August 2026 is a busy month for compliance.

Practical checklist for SMEs

  1. Determine your position: route 1 (sector + size) or route 2 (supply chain)?
  2. Map your AI and data flows, and your suppliers — who processes your critical data?
  3. Run a risk assessment and close the biggest gaps (access management, backups, patching, MFA).
  4. Set up incident detection and a reporting process (who reports what, within what deadline?).
  5. Register with the NCSC if you're in scope.
  6. Assign responsibility at board level and document the policy.

Where to start

The trap is paralysis: the law looks big, so nothing happens. The way out is starting small with an overview. First know where you stand — which obligations affect you and how big your exposure is — then tackle the biggest risks in a targeted way.

That's what our free AI Compliance & Risk Scan is for: in three minutes you'll see your exposure on NIS2, AI literacy, transparency and the GDPR, with an honest report and a concrete first move. Want us to carry it out? Take a look at our Responsible AI service — we don't just advise, we implement.

Get started

The 15 August 2026 deadline has already passed. Start with knowing where you stand.

Take the free AI Compliance & Risk Scan