Almost two years later than intended, but it is here: on 7 July 2026 the Dutch Senate adopted the Cyberbeveiligingswet, and on 15 August 2026 it takes effect. That turns NIS2 in the Netherlands from a directive you prepare for into a law you comply with. For more than 8,000 organisations, something fundamental changes: cybersecurity becomes a legal duty with a supervisor, reporting deadlines, and fines.
#From European directive to Dutch law
NIS2 is the European directive that raises the bar on cybersecurity well beyond its predecessor. A directive only works through national legislation, so the Netherlands had to transpose it. That should have happened by 17 October 2024; it became August 2026. The Cyberbeveiligingswet replaces the old Wbni and passed parliament together with the law on the resilience of critical entities.
#Who is covered
The law reaches organisations in eighteen sectors, from energy, drinking water, and transport to healthcare, digital infrastructure, and government. Within those sectors a size test applies: mid-sized and large organisations are covered, as a rule of thumb from roughly fifty employees or ten million euros in annual turnover. Some organisations, such as providers of essential digital services, are covered regardless of size.
The law distinguishes essential and important entities. The duties are largely the same; the difference sits mainly in supervision (proactive for essential entities, after the fact for important ones) and in the fine ceilings. In doubt about your status? The supervisor RDI's FAQ is the place to check.
#The three duties
1. The duty of care. You demonstrably manage cyber risks with appropriate measures: a current risk analysis, security of your network and information systems, a working incident procedure, business continuity, and supply chain security. Demonstrably is the key word. Policy that sits in a binder but is not followed does not count as control.
2. The reporting duty. A significant incident triggers a tight schedule: an early warning within 24 hours, a full report with a first assessment of severity and impact within 72 hours, and a final report within a month. Meeting those deadlines only works if you spot incidents quickly and set up the reporting route in advance.
3. The registration duty. Organisations covered by the law register through mijn.ncsc.nl. Voluntary registration has been possible since October 2024; from 15 August it is mandatory.
#The board is on the hook
The Cyberbeveiligingswet places responsibility squarely with the board. Directors must approve the security measures themselves, oversee their implementation, and follow training to be able to assess the risks. For serious negligence, board members can be held personally accountable. Delegating cybersecurity to IT and looking away is formally over.
The fines underline it: up to 10 million euros or 2 percent of global annual turnover for essential entities, up to 7 million euros or 1.4 percent for important entities.
#Where AI use meets the law
NIS2 never mentions AI, and yet AI sits right in the middle of it. AI tools are part of your attack surface and your data processing, and every AI vendor is part of the supply chain your duty of care must cover. An employee pasting customer data into a public chatbot creates exactly the kind of risk this law expects you to see, weigh, and manage. And when it goes wrong, a data leak through an AI tool can be a reportable incident, with the 24-hour clock starting immediately.
The hard part: most organisations do not know which AI tools are in use. You cannot manage what you cannot see. How NIS2 and AI use come together is covered in NIS2 and AI.
#What to arrange now
- Establish whether you are covered, and whether you count as essential or important.
- Register through mijn.ncsc.nl. The first formal step, and the easiest one.
- Update your risk analysis, including the supply chain and the AI use on the work floor.
- Set up the reporting route. Who assesses an incident, who reports, and can you make 24 hours?
- Bring the board along. Approving the measures and following training is not a formality but a legal requirement.
Getting sight of AI use does not have to be manual work. The AI Tools module shows which AI tools are in use, how often, and at what risk, checked against a catalog of more than 700 assessed tools.
#Demonstrable without the busywork
The common thread in the Cyberbeveiligingswet is demonstrability: not just taking measures, but being able to show they work. That is exactly where most organisations get stuck, because collecting evidence is manual work that has to happen on top of the day job.
BeeSensible turns that around. What happens on the work floor becomes the substantiation: which AI tools are in use, which sensitive data got a highlight before it left the building, and how it was handled. Always as counts, never the text, never one person.