Suggested region and language based on your location

    Your current region and language

    Project manager discusses and presents a database prototype and design review process to the project owner for approval.
    • Blog
      Digital Trust

    NIS2 in the Netherlands: What Changes and How BSI can Help

    Dutch Cybersecurity Act enters into force 15 August 2026. Learn what organisations need to do now to comply.

    On 15 August 2026, the Dutch Cyberbeveiligingswet will enter into force as the national implementation of NIS2. For organisations in essential and important sectors, this means new legal obligations around cybersecurity risk management, incident reporting, registration, governance, and supply-chain security. The Dutch authorities estimate that more than 8,000 organisations will be affected. 

    For many organisations, the first question is no longer “what is NIS2?” but “are we ready for it?” ISO/IEC 27001 is an excellent foundation for an information security management system, but it does not automatically cover every NIS2 requirement. Organisations still need to check their scope, close any gaps, and make sure governance, reporting, and supplier controls are all in place. BSI can support that journey with gap assessments, NIS2 assessments, ISO/IEC 27001 and ISO 22301 services, training, and supply-chain reviews. 

    What changes under the Dutch Cyberbeveiligingswet? 

    The Dutch law implements the EU NIS2 Directive and replaces the current cybersecurity framework. Under the new regime, organisations are expected to take a structured approach to cyber resilience rather than treating cybersecurity as a purely technical issue. The main obligations are clear: determine whether the law applies to you, register where required, prepare to report incidents, manage cyber risks proportionately, and ensure senior management is engaged and informed. 

    That makes governance just as important as technology. Organisations need policies, responsibilities, escalation paths, supplier oversight, and evidence that cybersecurity risks are being managed in a systematic way. In practice, this often means aligning existing ISO/IEC 27001 controls with the additional NIS2 expectations and then closing the remaining gaps. 

    How to become NIS2 compliant in the Netherlands 

    A practical compliance journey usually starts with scoping. Organisations should first confirm whether they fall within the sectors and size criteria covered by the Dutch law. The Dutch authorities advise organisations not to wait for the law to take effect before preparing. 

    Next comes registration. The NCTV states that organisations already have the option to register voluntarily, and that registration becomes mandatory for essential entities, important entities, and domain name registration service providers when the law enters into force on 15 August 2026. 

    From there, organisations should review the core NIS2 areas: incident response and reporting, risk management, management accountability, and supplier risk. This is where a formal gap assessment is valuable, because it shows where existing controls already meet the requirement and where extra measures are still needed. BSI’s NIS2 offering includes precisely that kind of assessment, together with ISO/IEC 27001 certification, ISO 22301 business continuity support, and supply-chain auditing. 

    How BSI can support your NIS2 journey 

    BSI can help organisations prepare in a structured way. Typical support includes: 

    • a NIS2 gap assessment to compare your current ISO/IEC 27001-based controls with the additional NIS2 requirements;
    • an NIS2 audit/assessment to evaluate implementation of the extra controls needed for conformity;
    • ISO/IEC 27001 certification support as the information security management backbone;
    • ISO 22301 certification support to strengthen business continuity and resilience; training for leadership, management, and operational teams.

    After performing the NIS2 audit/assessment to evaluate implementation of the extra controls needed for conformity, BSI is able to issue the Letter of Conformity.That is especially useful for organisations that need clear evidence for customers, partners, or internal stakeholders that they have had their NIS2 implementation independently assessed. 

    Why act now? 

    The deadline is close, and the work is broader than a simple checklist exercise. NIS2 is about building demonstrable resilience: knowing your scope, managing your risks, training your people, securing your suppliers, and being ready to respond when something goes wrong. The organisations that move early will be better placed to avoid disruption and show clear governance when the law takes effect. 

    Belgium note:

    Belgium uses a slightly different approach. Presumption of conformity with NIS2 can be obtained through a CyberFundamentals verification (assurance levels BASIC and IMPORTANT), a CyberFundamentals certification (assurance level ESSENTIAL), or an ISO/IEC 27001 certification, provided that the scope and Statement of Applicability (SoA) are deemed acceptable by the CCB. BSI is recognised by the CCB as a Conformity Assessment Body (CAB). This means that BSI can verify whether an organisation’s SoA demonstrates that it has implemented cybersecurity measures that are demonstrably equivalent to the CyFun® requirements for the applicable assurance level.