The Cyberbeveiligingswet Just Changed Who Is In Scope

Roughly 8,000 Dutch organizations are directly in scope. An estimated 133,000 more are about to find out they are not exempt.

Imagen decorativa

Puntos clave

The Cyberbeveiligingswet, the Dutch implementation of the EU’s NIS2 Directive, takes effect on August 15, 2026, with no general transition period.

  • Roughly 8,000 organizations across 18 sectors take on new registration, risk management, and incident reporting duties from day one.
  • NIS2 writes supply chain security into the law. Dutch cybersecurity firms estimate the number of Dutch small and midsize businesses pulled in indirectly, through supplier questionnaires and contract clauses, at 133,000.
  • Essential entities face fines up to 10 million euros or 2 percent of global turnover; important entities face up to 7 million euros or 1.4 percent.
  • Directors can now be held personally liable for failing the duty of care.

What follows sets out who carries this obligation, what a defensible program looks like, and the four steps compliance and risk teams should take before the first questionnaire lands.

In This Article
  1. What Does the Cyberbeveiligingswet Require Starting August 15?
  2. Why Does the Cyberbeveiligingswet Reach Suppliers It Never Names?
  3. What Does Board-Level Duty of Care Require Now?
  4. What Should Compliance and Risk Teams Do Now?
  5. The Choice in Front of Compliance Teams Now
  6. Ask Jan: Questions I Get About the Cyberbeveiligingswet

It reads like a domestic Dutch cybersecurity law, the Cyberbeveiligingswet. Beginning August 15, it becomes a question your procurement team cannot dodge, whether your business has ever set foot in the Netherlands or not.

Roughly 8,000 organizations are named in the Cyberbeveiligingswet. The obligation behind it reaches an estimated 133,000 more, and most of them will never see their name anywhere in the text. That gap, between who the law names and who it actually touches, is where this gets interesting, and it is where most risk leaders are still looking in the wrong place.

Most compliance teams have not worked out yet where this lands. This law does not stop at the edge of a Dutch entity register. It moves through contracts, and it moves fast. If your business sells into the Netherlands, or runs through a Dutch supplier, the obligation may already be sitting in a security questionnaire you have not opened yet.

What Does the Cyberbeveiligingswet Require Starting August 15?

On August 15, 2026, the Cyberbeveiligingswet enters into force with no general transition period, so its three legal duties apply immediately rather than phasing in.

The Cyberbeveiligingswet is the Dutch implementation of the EU’s NIS2 Directive, and those duties require roughly 8,000 organizations across 18 sectors to register with the national cyber authority, put risk management measures in place, and report significant incidents within 24 hours. Only higher education institutions get a three-year phase-in. Everyone else starts on day one.

The law applies to two categories of organization. Essential entities sit in the most critical sectors, including energy, transport, banking, health care, drinking water, and digital infrastructure, and face proactive supervision, meaning regulators can check compliance without waiting for an incident.

Important entities cover other critical sectors, including food production, manufacturing, and postal services, and face reactive supervision instead, meaning oversight typically follows an incident or a complaint. Essential entities face fines up to 10 million euros or 2 percent of global turnover, whichever is higher. Important entities face fines up to 7 million euros or 1.4 percent.

The reporting duty is phased, not a single deadline. Companies have 24 hours to send an early warning, 72 hours for an initial report, and one month for a full account of what happened, why, and what they did about it.

The duty of care belongs to the board as a governance responsibility, and the obligations attached to it extend well beyond the register.

Essential Entities Important Entities
Example Sectors Energy, transport, banking, health care, drinking water, digital infrastructure Food production, manufacturing, postal services
Supervision Type Proactive, regulators can check compliance without an incident Reactive, oversight typically follows an incident or complaint
Maximum Fine 10 million euros or 2 percent of global turnover, whichever is higher 7 million euros or 1.4 percent of global turnover, whichever is higher
Registration Duty Yes, effective August 15, 2026, no transition period (education only) Yes, effective August 15, 2026, no transition period (education only)
Notificación de incidentes 24-hour early warning, 72-hour initial report, one-month full report Same phased timeline
Board Duty of Care Personal liability for directors on gross negligence Same standard applies

Why Does the Cyberbeveiligingswet Reach Suppliers It Never Names?

The part most people read past is Article 21 of the NIS2 Directive, which requires every essential and important entity to manage the security of its supply chain, and the Cyberbeveiligingswet writes that requirement directly into Dutch law.

In practice, that means the roughly 8,000 organizations directly in scope are already pushing the same security standard onto their suppliers, whether or not those suppliers are Dutch, and whether or not they meet the size thresholds themselves.

Dutch cybersecurity firms estimate the number of Dutch small and midsize businesses pulled in indirectly at 133,000, nearly sixteen times the number of organizations the law actually names. That figure defines the real shape of the compliance perimeter, and it is easy to miss if your risk register only tracks who is formally in scope.

Once a Dutch customer takes this seriously, a supplier can expect security questionnaires before a contract renews, audit rights written into the agreement, and a requirement to notify the customer fast enough that they can still meet their own 24-hour reporting window.

A supplier feels this the moment it matters to a customer who is named in the Act.

For a global enterprise, that reach does not stop at the Dutch border either. If any part of your business supplies goods or services to a Dutch essential or important entity, from anywhere in the world, that relationship now carries the same expectations. Compliance teams who assumed this was a domestic Dutch problem are the ones who will be caught explaining themselves in a contract review they did not see coming.

Map the Exposure Before a Contract Review Finds It

Mitratech Prevalent maps third-party risk before it shows up in a contract renewal, not after

Discover More Now

What Does Board-Level Duty of Care Require Now?

Meeting this requirement takes more than a signed policy statement. Directors of essential and important entities are personally responsible for the Cyberbeveiligingswet’s duty of care, and they can be held personally liable if gross negligence contributes to a failure. They are also required to complete cybersecurity training and hold a certificate showing they did.

This is a different kind of exposure than a fine attached to the company. A fine is a cost the business absorbs. Personal liability is a question a named director has to answer about what they knew and when they knew it.

Regulators want specific proof that a named individual was trained on the risks relevant to their organization, on a specific date, with content that reflects the systems the organization actually runs.

A completion certificate from a broad awareness course, filed away and never revisited, is the kind of evidence that looks fine right up until someone asks a harder question.

The pattern is familiar to anyone who has watched similar duty-of-care standards emerge elsewhere. Article 4 of the EU AI Act asks something nearly identical of companies training staff to work with AI systems. The wording changes from one regime to the next, but the expectation holds: a dated record, not a general assurance.

What Should Compliance and Risk Teams Do Now?

Four steps close the gap between assembled and defensible. They separate risk leaders who can already answer a regulator’s question from the ones who will be assembling an answer after the fact.

  • Map every supplier relationship that touches a Dutch essential or important entity, directly or a few steps removed, and note which security measures each relationship actually depends on.
  • Audit existing board training against the standard regulators will apply. A single onboarding session is not evidence of ongoing competence.
  • Dated, role-specific training records are what a supervisor asks to see first.
  • Put the duty of care in writing, tied to specific systems and specific dates, rather than a policy statement general enough to describe any company in any sector.
  • Start before the questionnaires arrive, not after, and keep the evidence current on an ongoing basis rather than reviewed once at onboarding and forgotten.

These four steps produce a record a regulator can use.

The Choice in Front of You Now

A regulator, or a customer’s procurement team, can now ask a very specific question: what did you do, and can you prove it.

Evidence will become the standard the moment enforcement begins. A risk register that only tracks direct scope will miss the exposure sitting in a supplier contract. Training filed away at onboarding will not satisfy someone asking for a dated record two years later.

Only 8,000 organizations are named in the Cyberbeveiligingswet. The other 133,000 just found out by reading this. Mapping this dependency now is far more straightforward than reconstructing it for a regulator later.

Build a Duty-of-Care Record That Holds Up Under Scrutiny

See how the Mitratech Global GRC Platform connects vendor risk, policy evidence, and board reporting in one place

See the Platform

Cómo puede ayudar Mitratech

Most of the exposure created by the Cyberbeveiligingswet runs through vendor relationships, not through systems Mitratech customers built themselves. Mitratech Prevalent extends third-party risk management to cover that exposure across the supply chain. Mitratech Alyne connects that vendor risk to the enterprise risk register the board actually reviews. Mitratech PolicyHub gives compliance teams an auditable record of who attested to what and when. And Mitratech Syntrio delivers the director cybersecurity training this law now requires, tracked and certified by name rather than issued as a single generic session. Learn more now.

Ask Jan: Questions I Get About the Cyberbeveiligingswet

GRC Answers from Jan Stappers, Executive Vice President, GRC Solutions Strategy at Mitratech

What is the Cyberbeveiligingswet?
“It is the Dutch implementation of the EU’s NIS2 Directive, and it is the reason roughly 8,000 organizations in the Netherlands now have a registration duty, a risk management duty, and a phased incident reporting duty, all starting on the same day. I would stop calling August 15 a deadline. A deadline is something you can still be early for. This is the date the obligation simply exists.”
Is there really no transition period?
“For almost everyone, no. The one exception is higher education, which gets three years. Every other organization in scope starts under full enforcement the moment the law takes effect. I have reviewed transposition laws with phased rollouts before. This one was written deliberately without one, and that choice tells you something about how seriously the Dutch government is treating this.”
Does this affect my organization if we are not based in the Netherlands?
“This reaches you even if you are not based in the Netherlands, and it is the part I would check first. If any part of your business supplies goods or services to a Dutch essential or important entity, their obligations flow down to you through contracts, questionnaires, and audit rights, regardless of where you are headquartered. I have seen companies outside the Netherlands assume a Dutch law was someone else’s problem, and that assumption tends to become expensive the moment a contract comes up for renewal.”
Does this reach my suppliers even if they are not directly in scope?
“It reaches further than most people expect. Article 21 requires in-scope organizations to manage the security of their own suppliers, and market analysis puts the number of Dutch small and midsize businesses pulled in this way at over 130,000, next to roughly 8,000 organizations actually named in the law. I would start by mapping which of your vendor relationships touch a Dutch entity, directly or a few steps removed, before a customer asks you to prove it.”
What does a defensible duty-of-care record actually need to contain?
“Three things, and I have yet to see a program pass review without all three. A dated record of board training, specific to the systems the organization actually runs rather than a general course. Documented risk management measures tied to the specific requirements of Article 21. And evidence that supplier relationships are being monitored on an ongoing basis, not checked once at onboarding and forgotten. I have sat across from boards that had all the right policies and none of the evidence. Evidence is what a regulator actually wants, and policies alone rarely qualify.”