AI Trust Insights 2025 | Latest News & Expert Analysis

Dutch Cybersecurity Act: 15 Days to Compliance Deadline

Written by Nemko Digital | Jul 31, 2026, 8:30:02 AM

Organizations falling within the scope of the Dutch Cybersecurity Act face immediate compliance requirements without a general transition or grace period. The legislation, which implements the broader European NIS2 Directive, also referred to as the European NIS2 Directive or NIS 2 Directive, replaces the current Security of Network and Information Systems Act and enters into force on 15th of August 2026. This development represents a significant shift in regulatory expectations and a new norm for information security, requiring organizations to proactively establish robust AI regulatory compliance frameworks to manage systemic risks and demonstrate control over global data effectively.

 

Core Obligations Under the Dutch Cybersecurity Act

The Act implements the European NIS2 Directive and was adopted by the Dutch Senate on 7 July 2026. It will replace the current Security of Network and Information Systems Act (Wet beveiliging netwerk- en informatiesystemen).

 

The legislation introduces four primary obligations for in-scope entities. First, organizations must complete mandatory registration through the Dutch National Cyber Security Centre (NCSC) web portal using appropriate electronic identification tools. Failure to register correctly by the implementation date exposes organizations to potential enforcement actions under the new regulations.

Second, the Dutch Cybersecurity Act establishes a comprehensive duty of care. Entities must implement appropriate and proportionate technical, operational, and organizational measures to manage cyber risk management responsibilities, protect information systems, and prevent incidents. These measures must be grounded in a thorough risk assessment, aligning with established methodologies such as the NIST Cybersecurity Framework and, where appropriate, ISO 27001.

Third, the legislation introduces a stringent, phased incident reporting regime. Organizations must provide an early warning to the relevant Computer Security Incident Response Team (CSIRT) without undue delay, followed by a formal incident reporting notification within 72 hours of becoming aware of a significant incident. A final comprehensive report is required within one month, including detailed information about the incident and any improvement actions.

 

Board-Level Governance and Accountability

A defining feature of the Dutch Cybersecurity Act is the elevation of digital security to a board-level responsibility. The management body must actively approve and supervise the implementation of cybersecurity risk-management measures. Furthermore, board members are legally required to possess sufficient knowledge and skills to identify risks and assess appropriate mitigation strategies.

This requirement underscores the necessity for comprehensive AI governance structures that ensure leadership is adequately prepared to oversee complex digital ecosystems. Organizations must demonstrate that their board members have completed necessary cybersecurity training, with a two-year period provided to meet these specific knowledge requirements and establish demonstrable control.

 

Scope and Enforcement Mechanisms

The legislation applies to organizations active in designated essential and important sectors, including energy, transport, banking, healthcare, digital infrastructure, and manufacturing. However, applicability is not determined by sector alone; size thresholds and the potential impact of service disruption on public safety also play crucial roles. International groups must assess compliance based on the specific activities of their Dutch legal entities rather than their global operations, including how they process global data and non-personal data.

Supervisory authorities possess significant enforcement capabilities under the new regime. Essential entities face potential administrative fines of up to €10 million or 2% of their total worldwide annual turnover, whichever is higher. Important entities may be subject to fines of up to €7 million or 1.4% of turnover. Additionally, board members can face personal fines for failing to maintain adequate knowledge and skills.

As the implementation date approaches, organizations must urgently evaluate their current AI management systems and cybersecurity postures. This preparation should include mapping existing incident response procedures against the new requirements, reviewing the Dutch Telecommunications Act (Telecommunicatiewet) where relevant, and ensuring clear documentation of board-level ownership. Organizations should also assess their alignment with the Critical Entities Resilience Act and broader European digital regulations. This proactive approach is essential for organizations aiming to achieve compliance while mastering the cyber resilience act and meeting the evolving requirements of the European NIS2 Directive.