Directive NIS2 European Union
NL · Member state

NIS2 in Netherlands


What binds you in Netherlands is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.

Transposition
Transposed
Competent authority
RDI
National CSIRT
VAT on your purchase
21%

Reviewed . Verify against the national official journal before relying on this for a filing.

The text that actually binds you

National transposition


Referred to the Court of Justice

The European Commission referred this member state to the Court of Justice of the European Union in its July 2026 infringement package for failing to fully transpose NIS2, asking the Court to impose a lump sum and daily penalty payments. The referral predates the Senate vote of 7 July 2026 by one day, and the act has been in force since 15 August 2026 — but a referral is withdrawn on NOTIFICATION of complete transposition, not on entry into force, and the outstanding ministerial regulations are part of what has to be notified. Treat the case as live until the Commission says otherwise.

This does not suspend your obligations. The directive still binds the member state, and entities are expected to be working to article 21(2) regardless of how late the national text is.

Status of the national text · In force since 15 August 2026 (Staatsblad 2026, 189)

National law

Cyberbeveiligingswet (Cbw)

In force

Approved by the Tweede Kamer on 15 April 2026 and by the Senate on 7 July 2026, in force since 15 August 2026. The Cyberbeveiligingsbesluit (Cbb), the implementing decree, carries the detail on duty of care, registration and management training — read it alongside the act, not after it. One layer is still outstanding: ministerial regulations per ministry or sector further specify parts of the Cbb, and not all are published — entry into force is expected across the second half of 2026. That is why the Commission procedure is not moot even though the act itself is now applicable: what remains is sectoral detail, not the duty.

Registration

Entity register (entiteitenregister) at NCSC-NL

Registration became compulsory on 15 August 2026, the enforcement date. Supervision sits with the RDI, registration with NCSC-NL — two different bodies, a distinction that catches people out.

National assessment framework · Public sector only — private entities have none

Baseline Informatiebeveiliging Overheid 2 — BIO2 v1.3, published in the Staatscourant

v1.3, 5 March 2026 (BIO2 first published 24 September 2025), published by Interbestuurlijke werkgroep-BIO, chaired by the Ministry of the Interior (BZK). Built on NEN-EN-ISO/IEC 27001:2023 (nl) and NEN-EN-ISO/IEC 27002:2022 (nl).

For the PUBLIC SECTOR there is one, and the note we published here before was wrong to imply otherwise: BIO2, the Baseline Informatiebeveiliging Overheid, built on NEN-EN-ISO/IEC 27001:2023 and 27002:2022. It binds the Rijk, provinces, water boards and municipalities, and the ministerial regulation for the government sector under the Cbb makes applying its overheidsmaatregelen a legal obligation rather than self-regulation. Public administration is an Annex I sector, so this is squarely a NIS2 matter. For PRIVATE entities there is no national framework: the duty of care is specified in the Cbw and the Cbb, ISO/IEC 27001 and 27002 serve as guidance rather than as a route to compliance, and the RDI is unusually explicit that meeting your own normenkader does not mean you meet the duty of care. Registration with NCSC-NL was voluntary until 15 August 2026 and is compulsory since.

A label is not compliance

BIO2 binds the PUBLIC SECTOR, not private entities. It applies to the Rijk, provinces, water boards and municipalities, and once the Cbw takes effect also to the Hoge Colleges van Staat, the Ministry of Defence, the AIVD and the police by ministerial decision. A private entity in NIS2 scope in the Netherlands has no national framework: it works to the duty of care in the Cbw and the Cbb directly. And which version binds you depends on your government layer — municipalities remain on BIO1 v1.04zv as binding self-regulation and use BIO2 as guidance.

BIO2 in full — levels, controls and what it does not cover →

Who supervises you

RDI is the competent authority designated by Netherlands. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.

Incident notifications under article 23 normally go to NCSC-NL, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.

What differs from the directive

Because NIS2 is a directive, Netherlands legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:

  • Registration. The portal, the information required and the deadline are national.
  • Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
  • Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
  • Reporting format. Deadlines are fixed by the directive; the form and the language are national.

If you operate in several member states

You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.

Cart 0