EuroComply
Sign up
๐Ÿ‡ณ๐Ÿ‡ฑNederland

NIS2 Directive Compliance in Netherlands

NIS2 expands cybersecurity obligations to essential and important entities across critical sectors. It mandates risk management, incident reporting, and supply chain security.

How does NIS2 apply in Netherlands?

NIS2 applies in Netherlands under EU law with the same obligations as across the bloc โ€” maximum fine โ‚ฌ10M or 2% / โ‚ฌ7M or 1.4% (essential / important entities). The national supervisory authority is the Autoriteit Persoonsgegevens (AP), which handles enforcement, complaints, and notifications. Deadline: October 17, 2024 (transposition deadline).

  • Supervisory authority: Autoriteit Persoonsgegevens (AP)
  • Maximum fine: โ‚ฌ10M or 2% / โ‚ฌ7M or 1.4% (essential / important entities)
  • Key deadline: October 17, 2024 (transposition deadline)
Supervisory authorityAutoriteit Persoonsgegevens (AP)
Maximum fineโ‚ฌ10M or 2% / โ‚ฌ7M or 1.4% (essential / important entities)
Key deadlineOctober 17, 2024 (transposition deadline)
Sectors affectedEnergy, Transport
Source: Autoriteit Persoonsgegevens (AP)Reviewed:
Deadline

October 17, 2024 (transposition deadline)

Max Fine

โ‚ฌ10M or 2% / โ‚ฌ7M or 1.4% (essential / important entities)

Sectors Affected

Energy, Transport, Healthcare

What are my NIS2 obligations in Netherlands?

  • Implement cybersecurity risk management measures
  • Report significant incidents within 24-72 hours
  • Assess supply chain security
  • Ensure management body oversight
  • Conduct regular security audits

Who enforces NIS2 in Netherlands?

Nationaal Cyber Security Centrum (NCSC)

Official authority website

National implementing law

Cyberbeveiligingswet (Cbw)

Cybersecurity Act

Rijksoverheid โ€” Cyberbeveiligingswet (NIS2)

NIS2 in Netherlands: what is different here?

The Netherlands transposes NIS2 through the Cyberbeveiligingswet (Cybersecurity Act), with the Nationaal Cyber Security Centrum (NCSC) acting as the national CSIRT.

Source: Rijksoverheid โ€” Cyberbeveiligingswet (NIS2)

Dutch organisations can use the government's 'NIS2-zelfevaluatie' self-assessment to check whether they are an essential or important entity under the directive.

Source: Rijksoverheid / RDI โ€” NIS2 zelfevaluatie

Supervision in the Netherlands is divided by sector: the Rijksinspectie Digitale Infrastructuur (RDI) supervises several sectors while other competent authorities cover their own domains.

Source: Rijksinspectie Digitale Infrastructuur โ€” NIS2

What are the NIS2 penalties for Netherlands organisations?

NIS2 Directive (Article 34) distinguishes between essential entities and important entities. Essential entities face a higher fine ceiling โ€” up to โ‚ฌ10M or 2% of global annual turnover โ€” while important entities face a lower ceiling of โ‚ฌ7M or 1.4%. Member States have discretion to set actual fine amounts within these ceilings through national transposition legislation.

Essential entities โ€” cybersecurity risk management and incident reporting violations

โ‚ฌ10,000,000 or 2% of global annual turnover
Art. 34(4) โ€” EUR-Lex

Important entities โ€” cybersecurity risk management and reporting violations

โ‚ฌ7,000,000 or 1.4% of global annual turnover
Art. 34(3) โ€” EUR-Lex
What is the maximum NIS2 fine?โ–ผ

Essential entities under NIS2 face a maximum fine of โ‚ฌ10,000,000 or 2% of global annual turnover, whichever is higher. Important entities face a lower ceiling of โ‚ฌ7,000,000 or 1.4% of global turnover. Exact amounts depend on national transposition legislation in each Member State.

Who is an essential entity under NIS2?โ–ผ

Essential entities include large organisations (250+ employees or โ‚ฌ50M+ turnover) in sectors such as energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure (DNS, IXPs, cloud providers, data centres), ICT service management, public administration, and space.

When did NIS2 penalties start applying?โ–ผ

NIS2 penalties apply from each Member State's national transposition date. The EU-wide transposition deadline was 17 October 2024, but several Member States have delayed full transposition. Entities should check their national authority's published guidance.

Full NIS2 penalty breakdown

NIS2 transposition and deadlines

NIS2 national transposition deadline

Member States were required to adopt and publish national transposition measures by 17 October 2024. As of May 2026, several Member States have not yet fully transposed NIS2: Belgium, Bulgaria, Czech Republic, Greece, Hungary, Luxembourg, Portugal, Romania, Slovakia, Slovenia, and Spain have either delayed or produced incomplete transposition laws.

Member States must designate NIS2 competent authorities and single points of contact

Six months after the transposition deadline: Member States must designate national competent authorities, single points of contact (SPOC), and ensure operational CSIRT capacity as required by NIS2.

Full NIS2 compliance timeline

Common NIS2 compliance questions

What does the NIS2 Directive require for EU organisations?โ–ผ

The NIS2 Directive (Directive 2022/2555) requires essential and important entities to implement risk management measures (Article 21) including incident handling, supply chain security, access control, and cryptography; and incident reporting within 24 hours (early warning) and 72 hours (initial notification) to the national CSIRT. Management bodies are personally liable for NIS2 compliance (Article 20). Medium and large companies in energy, transport, banking, health, digital infrastructure, ICT services, water, and space are in scope.

What is the NIS2 compliance tool for a 40-person SaaS company?โ–ผ

A 40-person SaaS company likely qualifies as an important entity under NIS2 if it operates in digital infrastructure or ICT service management sectors. Required actions: (1) Register with the national authority โ€” BSI in Germany, ANSSI in France, NCSC in the Netherlands; (2) Implement Article 21 risk management measures; (3) Establish incident response and 24-hour reporting capability; (4) Assess supply chain security. EuroComply's NIS2 module covers scope assessment, risk register, incident response templates, and regulatory monitoring from โ‚ฌ49/month, without requiring dedicated security staff.

What was the NIS2 transposition deadline for EU member states?โ–ผ

EU member states were required to transpose the NIS2 Directive into national law by 17 October 2024. Germany's NIS2UmsuCG (NIS2 Implementation Act) entered into force in November 2024, with BSI as the primary enforcement authority. France, the Netherlands, Belgium, Austria, and Ireland met or were close to the October 2024 deadline. Companies in Germany should register with BSI and implement Article 21 risk measures. Failure to register or implement required measures exposes management boards to personal liability.

What is the NIS2 Directive explained in plain language?โ–ผ

NIS2 is an EU law requiring medium and large companies in critical sectors to strengthen their cybersecurity. Adopted in January 2023 and replacing the original NIS Directive, it covers 18 sectors including energy, transport, banking, health, digital infrastructure, cloud, ICT services, and public administration. Key obligations: appoint a responsible manager with personal liability; implement security measures; report incidents within 24 hours; assess supply chain risk. Fines reach โ‚ฌ10M or 2% of global turnover for essential entities (Article 34(4)), and โ‚ฌ7M or 1.4% for important entities (Article 34(5)).

Does NIS2 apply to your Netherlands business?

Find out in 2 minutes with our free regulation checker.

Check now โ€” free

NIS2 in Netherlands by Industry

View full NIS2 compliance guide

Check Your Compliance Obligations

Find out which NIS2 obligations apply to your Netherlands organisation in under 2 minutes.

Run NIS2 Scope Checker

Key NIS2 Compliance Questions

What is the NIS2 Directive?โ–ผ

The NIS2 Directive is the European Union's updated cybersecurity framework enacted to strengthen the security of network and information systems across critical sectors. It expands on the original NIS Directive (2016/1148) with broader scope, stricter requirements, and significantly higher penalties. NIS2 applies to: (1) Essential entities in 11 sectors (energy, transport, water, health, banking, financial markets, DNS/TLD, public administration, space, chemicals, food); (2) Important operators in 7 sectors (digital services, cloud, CDN, managed security providers, social media, online marketplaces, search engines); (3) DNS service providers and critical infrastructure providers regardless of sector. The directive is applicable across all 27 EU member states.

Who must comply with NIS2?โ–ผ

NIS2 applies to two primary categories: (1) Essential entities are large organizations in critical sectors whose failure would significantly impact essential services. Article 2 defines essential entities by sector (Annex I) and size (โ‰ฅ250 employees or โ‚ฌ50M annual turnover). Examples: energy utilities, hospitals, banks, airports, national defense networks. (2) Important entities are medium and large organizations (โ‰ฅ50 employees or โ‚ฌ10M annual turnover) in sectors listed in Annex II, including digital service providers offering cloud computing, DNS, CDN, managed security, social media, or online marketplaces. Your organization must comply if it fits either category. Most commercial organizations in covered sectors do not qualify for exemptions. If you operate in critical infrastructure or provide digital services at scale, you almost certainly must comply.

What are the key NIS2 compliance obligations?โ–ผ

NIS2 requires four main compliance areas: (1) ICT Risk Management: Implement policies, procedures, and technical measures to manage cybersecurity risks. This includes asset inventories, vulnerability management, access controls, encryption, incident response plans, and business continuity measures per Article 21 and Annex I. (2) Incident Reporting: Notify your national competent authority within 24 hours of discovering a significant incident; notify affected customers within 72 hours per Article 23. (3) Supply Chain Security: Assess third-party risks, include security clauses in vendor contracts, monitor supplier performance per Article 21. (4) Board Accountability: Senior management (board/executive level) is personally liable for approving cybersecurity measures and ensuring implementation per Article 20. Failure to meet these obligations triggers penalties up to โ‚ฌ10M or 2% global revenue.

Explore NIS2 Compliance

For informational purposes only. This is not legal advice โ€” consult qualified legal counsel.