For a long time it was a moving target: NIS2 was coming, but exactly when kept shifting. That uncertainty is now gone. On 7 July 2026 the Senate approved the Cybersecurity Act, the Dutch translation of the European NIS2 directive, and the law takes effect on 15 August 2026. No more “expected”. Below, in plain language, what that means, for whom, and what you can do now, without the scaremongering.
What exactly was decided
The legislative process is complete. The House of Representatives already approved it on 15 April 2026, and with the Senate on 7 July the law is now final. The start date is 15 August 2026, and there is no transition period: from that day the duty of care applies.
At the same time, the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten) also cleared the Senate. That one focuses on the physical resilience of a smaller group of vital organisations. For most SMEs, the Cybersecurity Act is the piece to know.
Who does something change for?
The law distinguishes two groups, and there is a third group that is easily forgotten:
- Essential entities (over 8,000 organisations): think energy, drinking water, hospitals, banks, digital infrastructure and central government. Here the regulator also keeps an eye on things in advance.
- Important entities (around 500 organisations): including food production, chemicals, waste management, postal and courier services and medium-sized IT service providers. Roughly from 50 employees or more than 10 million euros in revenue in a designated sector.
- The supply chain (tens of thousands of suppliers): businesses that don’t fall under the law themselves, but do supply an organisation that does. That customer has to get its entire supply chain in order and passes the requirements down.
That last group is exactly where many SMEs sit. Even if the law doesn’t apply to you directly, from this summer your biggest customer may ask you for provable security.
What the law asks in practice
Without lapsing into legal language, it comes down to four things:
- Duty of care. Appropriate technical and organisational measures against cyber risks, including the risks in your chain. In practice it’s about a healthy basis: knowing the risks you run, keeping access and systems in order, multi-factor authentication, tested backups, aware people and a plan for when something goes wrong.
- Reporting obligation. You report a significant incident to the NCSC in phases: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within a month.
- Registration obligation. If you fall under the law, you register your organisation with the regulator.
- Responsibility at board level. Management has to know and approve the measures, and is personally accountable for them too. Cybersecurity is no longer a small IT topic you pass on, but a board responsibility.
Fines come with it too, up to 10 million euros or 2 percent of worldwide annual revenue for the heaviest category. More important than the worst-case image: the measures themselves simply protect your business, and are increasingly asked for by customers and insurers as well.
What you can do this summer
The date is fixed, but that’s no reason to panic. Don’t start with a thick policy document, but with clarity: knowing where you stand now immediately shows what still needs doing. Often you’ve already arranged part of it and it’s about the finishing touches.
Our free security scan touches exactly the themes that NIS2 covers too, so within a few minutes you know where you stand. Want to record it in a measurable, provable way, precisely what a customer or regulator wants to see? Then we do that with MIRA.
If you work in a sector where a standstill or outage immediately ripples through, such as manufacturing or transport and logistics, this is a good moment to hold your chain and your continuity up to the light.
A few questions we often get
Is 15 August 2026 really fixed now?
Yes. The law has been passed by both chambers, the Senate last on 7 July 2026, and the start date is 15 August 2026. Unlike previous years, this is no longer a target date but a fixed one, with no transition period.
I’m a smaller business. Do I need to do anything now?
Maybe not directly, but don’t count yourself out too quickly. If you don’t fall under the law yourself, you can still be affected through a customer who passes the requirements down. Not sure whether it applies to you? Then we’ll take a look with you in an intro call.
What if I only start now?
You still have time to get it in order calmly rather than under pressure. Precisely because it’s about healthy basic measures, a clear picture lets you work in a targeted way on what’s still missing, without overhauling everything at once.
Curious how you stand now the law is here? Take the free security scan for a first picture, or book an intro call, and we’ll look together whether and how NIS2 affects you.