Go to content
We are the #1 Microsoft partner
#1 Microsoft partner of NL
Console Courses Working at (NL)

Cybersecurity Act

Cybersecurity Act (NIS2)

From legislation to demonstrable digital resilience

The Dutch Cybersecurity Act will come into force on 15 August 2026. As the Dutch implementation of the European NIS2 Directive, it introduces stricter requirements for cybersecurity and resilience, board-level accountability, incident reporting and supply chain risks.

For organisations, this means that security measures must not only be properly implemented, but must also be demonstrably effective. This includes maintaining an up-to-date risk assessment, assigning clear responsibilities, testing crisis response procedures and understanding the risks associated with partners and suppliers.

Even if your organisation does not fall directly within the scope of the Act, you may still be affected. Organisations that are subject to the Cybersecurity Act must be able to demonstrate that their supply chains are adequately secured.

On this page, you will find practical guidance and insights on:

  • The requirements of the Cybersecurity Act;
  • The steps you can take to prepare your organisation;
  • The responsibilities of boards and senior management;
  • Incident response and business continuity;
  • Managing risks associated with partners and suppliers.
Cybersecurity legislation requires demonstrable preparedness

Cybersecurity Tabletop

A Cybersecurity Tabletop exercise allows your crisis team to experience what happens when the pressure mounts. Who makes the decisions, who communicates, and what steps do you take when every minute counts?

Knowledge

Blogpost / 15-7-2026

Can you demonstrate that your partners have their security in order?

Read how Wortell demonstrably manages information security, business continuity and supplier risks and what this means for your supply chain responsib...
Go to Can you demonstrate that your partners have their security in order?
Blogpost / 9-7-2026

The Cybersecurity Act: Step-by-step plan for what you want to have in place before 15 August

On 7 July 2026, the Senate approved the Cybersecurity Act (Cbw) and the Resilience of Critical Entities Act (Wwke). This means that the Dutch implemen...
Go to The Cybersecurity Act: Step-by-step plan for what you want to have in place before 15 August
Blogpost / 7-5-2026

Security in 2026: control is no longer an IT issue

In 2026, cyber resilience will no longer be a purely IT issue, but an administrative responsibility. With NIS2 and the Cybersecurity Act, organization...
Go to Security in 2026: control is no longer an IT issue

What we do

Proposition Wortell Secure logo

Managed eXtended Detection and Response.

Managed eXtended Detection and Response (MxDR): Protects at every stage of the MITRE ATT&CK framework.
Go to Managed eXtended Detection and Response.