The Dutch law that transposes the EU NIS2 directive into national obligations for digital resilience — with no transition period.
NIS2 is the 2022 EU directive; the Cyberbeveiligingswet is the Dutch law that transposes it into national law. Both names refer to the same obligations — the law significantly widens the group of organisations that must meet cybersecurity requirements compared with the old Wbni, and places accountability explicitly with management.
Four core obligations, regardless of sector — the details differ per organisation, the principle doesn't.
Enforcement. Non-compliance can lead to directives and fines from the supervisor; repeated or severe breaches can bring management liability into play. Don't wait for an inspection to find out where you stand.
Two separate laws that are often both relevant to the same SME.
| Law | Covers | In force since |
|---|---|---|
| Cyberbeveiligingswet (NIS2) | Digital resilience and incident reporting | 15 August 2026 |
| EU AI Act | Responsible use of AI systems | Phased since 2025 |
Both often affect the same organisation. Our free AI-Compliance & Risk Scan weighs both in a single 3-minute report.
The free AI-Compliance & Risk Scan shows your exposure on the Cyberbeveiligingswet, AI literacy and transparency — with an honest report, no sales pitch.
Take the free risk scan