NIS2 checkContact

Directive and national law

What NIS2 asks of your organisation

The Dutch Cyberbeveiligingswet came into force on 15 August 2026. It applies to roughly 8,000 Dutch organisations across eighteen sectors. There is no general transition period. This page sets out who the law applies to, which measures are required, which reporting deadlines apply and what the board is responsible for.

8,000Dutch organisations estimated to be in scope
24 / 72 / 30the three reporting moments, in hours and days
€10M / 2%maximum fine, essential entities
Article 20your board approves and supervises

Scope first

Three ways your organisation can be affected by NIS2

The directive distinguishes essential and important entities. Alongside them there is a large group of suppliers that does not fall under the law directly, but does receive security requirements from customers who have to comply with NIS2.

ESSENTIAL

Essential entities

Organisations in Annex I sectors from 250 staff upwards can be classified as essential entities. These include energy, drinking and waste water, transport, banking, financial market infrastructure, health, digital infrastructure, ICT service management, public administration and space. The regulator may investigate without an incident having occurred first.

The national law draws the exact lines. A classification scan settles them per legal entity.
IMPORTANT

Important entities

Organisations in Annex I sectors with 50 to 249 staff, and organisations from 50 staff upwards in Annex II sectors, can be classified as important entities. Annex II covers postal and courier services, waste management, chemicals, food, research, digital providers and parts of manufacturing. The same ten security areas and the same reporting deadlines apply to them. Supervision usually starts after an incident, a signal or a concrete indication.

The national law draws the exact lines. A classification scan settles them per legal entity.
SUPPLY CHAIN

Suppliers in the chain

Article 21(2)(d) obliges organisations in scope to manage the security risks at their direct suppliers as well. MKB-Nederland estimates that this brings 50,000 to 70,000 Dutch SMEs questions about their security without the law naming them. Those requirements usually arrive through contracts, tenders, audits and supplier questionnaires.

There is no direct statutory duty in that case, but it can be a condition for staying a customer.

One directive, twenty-seven national laws

NIS2 across several countries

Every member state has written NIS2 into national law. As a result the name of the law, the competent regulator, the registration system and the date of entry into force all differ. Where your organisation operates in several countries, we assess each legal entity separately. Per country you receive an overview of the applicable law, the classification, the registration and the reporting route.

NIS2 transposition in the countries Think Smart Europe covers today
CountryNational lawCompetent authorityIn forceRegistration route
NetherlandsCyberbeveiligingswet (Cbw)NCSC, RDI and sector supervisors15 August 2026Entity register via mijn.ncsc.nl. No general transition period.
GermanyNIS2UmsuCG, replacing the BSIGBSI6 December 2025BSI portal, after a Mein Unternehmenskonto account. Deadline passed.
BelgiumLaw of 26 April 2024 and Royal DecreeCentre for Cyber security Belgium18 October 2024Safeonweb@Work. CyberFundamentals or ISO 27001 as the framework.
FranceLoi résilience, awaiting promulgationANSSIExpected 2026MesServicesCyber pre-registration. ReCyF is the reference framework.
DenmarkNIS2-loven, plus sector actsSAMSIK with sector supervisors1 July 2025Sector regulator. Deadline passed.
SwedenCybersäkerhetslagen SFS 2025:1506MSB and PTS with sector authorities15 January 2026Report to the sector supervisor. Duties applied immediately.
FinlandKyberturvallisuuslaki 124/2025Traficom NCSC-FI plus seven supervisors8 April 2025Sector supervisor. Deadline passed.
NorwayDigitalsikkerhetsloven. NIS2 not yet incorporated.NSM1 October 2025 (NIS1)EEA state. Expansion to NIS2 expected during 2026.

Status 19 August 2026. Think Smart Europe maintains a transposition tracker for all 27 member states and reviews it monthly. On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for late transposition, the Dutch referral arriving one day after the Eerste Kamer adopted the Cyberbeveiligingswet.

Article 21(2)

The ten security measures

Article 21 describes ten areas in which organisations have to take appropriate measures. For each area it has to be clear what is in place, who is responsible and what evidence is available. The letters in the overview follow the structure of the directive.

1

Risk and security policies

A current risk assessment covering the main systems, data, threats and dependencies, with an owner, a priority and a planned measure per risk. An asset register, an overview of what you have under management, that is kept current, and security policies that match how the organisation is actually set up and actually works, aligned with ISO 27001.

Shared responsibility We draw up the assessment and the policies together with you. Your board decides which risks are acceptable and approves the policies.

Protect
2

Incident handling

Recognising, assessing, containing and reporting security incidents. Detection and response from our SOC, day and night, with SIEM and XDR underneath, rehearsed playbooks, and a response time on priority alerts set out in the SLA. For each type of incident it is recorded which actions the SOC may carry out immediately.

Think Smart Europe carries this out Our SOC handles detection, triage and the agreed response. Your organisation approves formal notifications and external communication.

Essential
3

Business continuity

Backups that cannot be altered or deleted, restore tests fixed in the calendar, and recovery objectives that were on paper before anyone needed them. For important processes we record in advance the recovery time required and the maximum data loss allowed.

Think Smart Europe carries this out We manage the agreed backups, restore tests and technical run books. The RTO and RPO, how long recovery may take and how much data you may lose in the process, are set together with you.

Essential
4

Supply chain security

Knowing which suppliers have access to systems, data or critical processes and what risks come with that: a maintained supplier register, security requirements in the contracts, and assessments with evidence behind them.

Shared responsibility We run the supplier register and the security assessments. Your organisation remains responsible for the commercial and legal arrangements with suppliers.

Advanced
5

System lifecycle

Acquiring, developing, configuring, updating and changing systems securely. Patching on an agreed rhythm, vulnerability scanning, hardened configurations and security testing that follows every system through its life. For software development we look at matters such as access rights, code management, testing and the handling of vulnerabilities found.

Think Smart Europe carries this out We run the agreed scans, updates and technical checks within the recorded remediation windows.

Protect
6

Effectiveness assessment

Assessing periodically whether the measures are carried out and have the intended effect: patch coverage, restore tests, follow-up on alerts, account management and vulnerabilities, reported on a fixed rhythm instead of one assessment gathering dust.

Think Smart Europe carries this out We collect and report the agreed data. The internal audit can be run by your organisation or by a separately appointed party.

Advanced
7

Cyber hygiene and training

Teaching staff how to recognise and report suspicious email, unusual requests and possible incidents. A structured awareness programme, phishing simulation with per-person completion records, and the training Article 20 obliges the management body itself to follow.

Think Smart Europe carries this out We run the agreed training programme and record attendance and results.

Essential
8

Cryptographic controls

Data encrypted where it sits and where it travels, certificates and keys managed across their full lifecycle, and a record of who has access, how keys are replaced and what happens when a key or a certificate expires.

We set it up; your organisation keeps ownership We set up the technical provisions for encryption and key management. Ownership and final control over the keys stay with your organisation.

Protect
9

HR security and access control

Access rights that match the role and are adjusted in time when someone changes role or leaves, with joiner, mover and leaver wired to HR, privileges reviewed against least privilege, meaning no more rights than someone needs, and administrator accounts managed separately and checked periodically.

Shared responsibility We run the technical measures and the access reviews. HR and line managers remain responsible for passing on and approving changes in time.

Advanced
10

Authentication and communications

Multi-factor authentication reduces the chance that a stolen password gives direct access. Strong sign-in wherever it matters, with conditional access on top, secured collaboration tools, and a separate communication channel for situations in which the normal email or collaboration environment cannot be relied on.

Think Smart Europe carries this out We set up and manage the agreed technical measures: strong sign-in, conditional access and the channel outside your own network (out-of-band).

Essential

The services named show how we can support the measure in practice. How it is finally set up depends on the risks, the size and the technical environment of your organisation.

Where we differ

From assessment to operation

An assessment makes clear what is missing. After that the measures have to be implemented, managed and demonstrably carried out. Think Smart Europe B.V. can cover these steps within a single engagement. Our CISO assesses the situation and draws up the plan. Our engineers carry out the technical measures. The SOC handles the monitoring and incident response. The reporting and the evidence are kept current for as long as the service runs. Your existing IT team or supplier can stay involved for the parts that are already well set up.

The report route
  • A scoping study and a classification opinion
  • A gap review against the ten areas
  • Policies, a findings sheet and a roadmap
  • A handshake, and the building is yours to arrange

The work that actually reduces the risk starts after that invoice, with a partner you still have to find.

The Think Smart route
  • The same assessment, led by a Think Smart CISO
  • Implementation by our own engineers, from endpoint protection and SIEM to identity, backup and encryption
  • Operation from our European SOC, day and night
  • Evidence ready for regulator, insurer and customer alike

One accountable partner, from classification to day-to-day operation.

Frequently asked

Questions and answers

Does NIS2 apply to our organisation?

That depends on your sector, your size, your activities, your legal structure and the countries you operate in.

In the sectors concerned, organisations from 250 staff upwards often fall into the essential category. Organisations with 50 to 249 staff can be classified as important. National exemptions and designations can depart from this.

A classification scan settles it per legal entity and per country.

What does it mean if we are not directly in scope?

Customers who are in scope can put security requirements into contracts, tenders and supplier assessments. Article 21(2)(d) makes them responsible for the security of their direct suppliers. MKB-Nederland estimates that this brings 50,000 to 70,000 Dutch SMEs questions without the law naming them.

You may then need the same measures and the same evidence, but on the basis of a commercial arrangement rather than a direct statutory duty.

What are the consequences if we do nothing?

Essential entities can be investigated without a prior incident: the regulator can inspect, request evidence and intervene. Fines run to €10 million or 2 percent of worldwide annual turnover, whichever is higher.

For important entities supervision usually starts after an incident or a signal.

Personally, the exposure sits with the board. Article 20 makes approving and supervising the measures a board duty that cannot be delegated, member states make senior management liable for shortcomings, and for an essential entity an authority can ask a court to temporarily bar the director or legal representative from exercising managerial functions.

Is an ISO 27001 certificate enough?

ISO 27001 covers many subjects that also appear in NIS2. In Belgium the CyberFundamentals framework treats ISO 27001 as a route to compliance.

The certificate does not, however, automatically settle the statutory classification, the registration, the reporting deadlines and the responsibility of the board. It also has to be checked whether the scope of the certificate covers all the relevant entities, locations and systems.

In our assessments an ISO 27001-certified organisation typically meets seven or eight of the ten measures.

How long do the assessment and the implementation take?

A classification and a first assessment usually take two to three weeks per country.

The implementation can amount to a few administrative adjustments, but it can also take several months where important technical measures are missing, such as a SIEM, privileged access management or tested disaster recovery.

A reliable plan is only possible once the existing environment has been assessed.

Can our current IT supplier stay involved?

Yes. We record which measures are already well set up, which parts are missing and who is responsible for implementation, monitoring and reporting.

Work your current supplier does well does not have to be replaced.

Where to begin

Start with a classification scan

With the classification scan we establish, per country and per legal entity, which legislation applies, how your organisation is classified and which measures or evidence are missing.

The opening move

The classification scan, one member state at a time

You receive a written assessment stating whether your organisation falls under the law, how it is classified, and which of the ten areas are already covered. Missing evidence is listed separately from missing measures.

The scan has a fixed price per country. Price, lead time and any offset against follow-up work are agreed in the intake call.
Plan an intake callA call with our CISO, free of charge.
Cyber Incident