Cybersecurity Act
From legislation to demonstrable digital resilience
The Dutch Cybersecurity Act will come into force on 15 August 2026. As the Dutch implementation of the European NIS2 Directive, it introduces stricter requirements for cybersecurity and resilience, board-level accountability, incident reporting and supply chain risks.
For organisations, this means that security measures must not only be properly implemented, but must also be demonstrably effective. This includes maintaining an up-to-date risk assessment, assigning clear responsibilities, testing crisis response procedures and understanding the risks associated with partners and suppliers.
Even if your organisation does not fall directly within the scope of the Act, you may still be affected. Organisations that are subject to the Cybersecurity Act must be able to demonstrate that their supply chains are adequately secured.
On this page, you will find practical guidance and insights on:
- The requirements of the Cybersecurity Act;
- The steps you can take to prepare your organisation;
- The responsibilities of boards and senior management;
- Incident response and business continuity;
- Managing risks associated with partners and suppliers.