NIS2 is the European cybersecurity directive for entities within defined sectors. The Netherlands implements it through the Cyberbeveiligingswet (Cbw). The NCSC identifies 15 August 2026 as the entry-into-force date. Use this overview to distinguish scope assessment, operational measures and legal reporting.
Establish scope before selecting controls
Assess the actual sector, service and organisation size. The NCSC’s general size test is at least 50 full-time equivalents, or fewer employees with both turnover and balance-sheet total above EUR 10 million. Specific categories and designations can create exceptions. Contractual security requirements from a regulated customer are a separate question from the supplier’s own registration duty.
Three operational workstreams
| Workstream | Practical output |
|---|---|
| Registration | A recorded scope decision and current registration where required. |
| Risk management | Appropriate controls, assigned responsibilities and evidence of review. |
| Incident reporting | An executable reporting route, timeline and authorised contacts. |
Put reporting times into the response procedure
The standard sequence for a significant incident is an early warning within 24 hours of awareness, a notification within 72 hours and a final report within a month of the notification. Trust services have a specific 24-hour notification exception, and significance criteria vary by sector. The registration and reporting guide explains those distinctions and links to official sources.
Connect duties to existing management processes
Use existing risk, supplier and incident procedures as a starting point. Map each applicable duty to available evidence and additional work. ISO 27001 certification does not replace that assessment. Define who makes decisions, who submits notifications and who takes over when the main contact is absent.
A practical starting record
- Record the scope decision, date and official source.
- Assign registration and maintenance responsibilities.
- Document the reporting route and relevant exceptions.
- List gaps between current practices and applicable duties.
Checked on 8 September 2026. Duties follow from applicable law, not from the moment the registration form is submitted.