Control over AI
Blog
Compliance and AI 9 min read

The Netherlands has its NIS2 law: what applies from 15 August

Almost two years late, NIS2 is now Dutch law. From 15 August 2026, the duty of care, the reporting duty, and the registration duty apply to more than 8,000 organisations. The timeline, the duties, and what to arrange now.

NIS2 at a glance: the key milestones from directive to the Dutch Cyberbeveiligingswet
Quick answer

The Cyberbeveiligingswet is the Dutch transposition of the European NIS2 directive and applies from 15 August 2026. More than 8,000 organisations across eighteen sectors get three duties: a duty of care (demonstrably manage cyber risks with appropriate measures), a reporting duty (an early warning within 24 hours and a full report within 72 hours of a significant incident), and a registration duty (register through mijn.ncsc.nl). The board must approve the measures itself and oversee them, and can be held liable for serious negligence. Maximum fines reach 10 million euros or 2 percent of global annual turnover.

01

The Cyberbeveiligingswet applies from 15 August 2026 and replaces the Wbni

02

More than 8,000 organisations across eighteen sectors fall under the law

03

Three duties: duty of care, reporting duty (24 and 72 hours), registration duty

04

The board approves the measures, oversees them, and is accountable

05

AI tools are part of your attack surface and supply chain, so part of your duty of care

Almost two years later than intended, but it is here: on 7 July 2026 the Dutch Senate adopted the Cyberbeveiligingswet, and on 15 August 2026 it takes effect. That turns NIS2 in the Netherlands from a directive you prepare for into a law you comply with. For more than 8,000 organisations, something fundamental changes: cybersecurity becomes a legal duty with a supervisor, reporting deadlines, and fines.

From European directive to Dutch law

NIS2 is the European directive that raises the bar on cybersecurity well beyond its predecessor. A directive only works through national legislation, so the Netherlands had to transpose it. That should have happened by 17 October 2024; it became August 2026. The Cyberbeveiligingswet replaces the old Wbni and passed parliament together with the law on the resilience of critical entities.

  1. The NIS2 directive enters into force

    The successor to the first NIS directive becomes European law. Member states have until October 2024 to transpose it into national legislation.

  2. European transposition deadline

    The Netherlands misses the deadline: the old Wbni stays in place longer than planned. Registering with the NCSC is possible on a voluntary basis from this point.

  3. The Dutch Senate adopts the Cyberbeveiligingswet

    Together with the law on the resilience of critical entities. That makes the start date final.

  4. New

    The Cyberbeveiligingswet takes effect

    The duty of care, the reporting duty, and the registration duty apply to more than 8,000 organisations across eighteen sectors. Registration runs through mijn.ncsc.nl.

The Cyberbeveiligingswet is the Dutch transposition of the NIS2 directive and replaces the Wbni.

Who is covered

The law reaches organisations in eighteen sectors, from energy, drinking water, and transport to healthcare, digital infrastructure, and government. Within those sectors a size test applies: mid-sized and large organisations are covered, as a rule of thumb from roughly fifty employees or ten million euros in annual turnover. Some organisations, such as providers of essential digital services, are covered regardless of size.

The law distinguishes essential and important entities. The duties are largely the same; the difference sits mainly in supervision (proactive for essential entities, after the fact for important ones) and in the fine ceilings. In doubt about your status? The supervisor RDI's FAQ is the place to check.

The three duties

1. The duty of care. You demonstrably manage cyber risks with appropriate measures: a current risk analysis, security of your network and information systems, a working incident procedure, business continuity, and supply chain security. Demonstrably is the key word. Policy that sits in a binder but is not followed does not count as control.

2. The reporting duty. A significant incident triggers a tight schedule: an early warning within 24 hours, a full report with a first assessment of severity and impact within 72 hours, and a final report within a month. Meeting those deadlines only works if you spot incidents quickly and set up the reporting route in advance.

3. The registration duty. Organisations covered by the law register through mijn.ncsc.nl. Voluntary registration has been possible since October 2024; from 15 August it is mandatory.

The board is on the hook

The Cyberbeveiligingswet places responsibility squarely with the board. Directors must approve the security measures themselves, oversee their implementation, and follow training to be able to assess the risks. For serious negligence, board members can be held personally accountable. Delegating cybersecurity to IT and looking away is formally over.

The fines underline it: up to 10 million euros or 2 percent of global annual turnover for essential entities, up to 7 million euros or 1.4 percent for important entities.

Where AI use meets the law

NIS2 never mentions AI, and yet AI sits right in the middle of it. AI tools are part of your attack surface and your data processing, and every AI vendor is part of the supply chain your duty of care must cover. An employee pasting customer data into a public chatbot creates exactly the kind of risk this law expects you to see, weigh, and manage. And when it goes wrong, a data leak through an AI tool can be a reportable incident, with the 24-hour clock starting immediately.

The hard part: most organisations do not know which AI tools are in use. You cannot manage what you cannot see. How NIS2 and AI use come together is covered in NIS2 and AI.

What to arrange now

  1. Establish whether you are covered, and whether you count as essential or important.
  2. Register through mijn.ncsc.nl. The first formal step, and the easiest one.
  3. Update your risk analysis, including the supply chain and the AI use on the work floor.
  4. Set up the reporting route. Who assesses an incident, who reports, and can you make 24 hours?
  5. Bring the board along. Approving the measures and following training is not a formality but a legal requirement.

Getting sight of AI use does not have to be manual work. The AI Tools module shows which AI tools are in use, how often, and at what risk, checked against a catalog of more than 700 assessed tools.

Search tool, vendor or categoryโ€ฆ
700+ tools
ChatGPT๐Ÿ‡บ๐Ÿ‡ธ
HighAllowed
Claude๐Ÿ‡บ๐Ÿ‡ธ
MediumAllowed
DeepSeek๐Ÿ‡จ๐Ÿ‡ณnew
CriticalNot allowed
Perplexity๐Ÿ‡บ๐Ÿ‡ธnew
MediumNo decision yet
Mistral๐Ÿ‡ซ๐Ÿ‡ท
LowNo decision yet
Midjourney๐Ÿ‡บ๐Ÿ‡ธ
MediumNo decision yet

Every tool, scored for risk

700+ AI tools, each scored Low to Critical, with nothing pre-approved or pre-blocked until someone decides.

More about AI Tools

Demonstrable without the busywork

The common thread in the Cyberbeveiligingswet is demonstrability: not just taking measures, but being able to show they work. That is exactly where most organisations get stuck, because collecting evidence is manual work that has to happen on top of the day job.

BeeSensible turns that around. What happens on the work floor becomes the substantiation: which AI tools are in use, which sensitive data got a highlight before it left the building, and how it was handled. Always as counts, never the text, never one person.

See

Which AI tools are actually in use, how often, and at what risk. Every tool scored against a catalog of more than 700.

See the AI Tools module
Decide

Every tool's status is the organisation's own call: allowed, limited, not allowed. The risk score is advice, never a verdict.

Help

That decision shows up while someone works: a notice on the tool, a highlight while you type. Never a block.

See Realtime Privacy
Substantiate

The same observations become substantiation: aggregated figures per framework and per measure. Never the text, never one person.

Dashboard ยท Accountability GDPRNIS2AI Act
  • Register of AI services

    Vendor, hosting, and a decision per tool

    Substantiated
  • AI literacy

    Highlights at the moment of typing and figures on how they were handled

    Substantiated
  • Appropriate security

    Critical data highlighted and handled before sending

    Substantiated
  • Data breach procedure

    BeeSensible provides the early signal; reporting and follow-up remain your own process

    Not substantiated
One set of observations, usable as substantiation in every framework. BeeSensible supports compliance; it does not make you compliant by itself.

Further reading: NIS2 and AI: what the directive means for your AI use and blocking AI creates shadow AI.

FAQ

Common questions

When does the Cyberbeveiligingswet take effect?

On 15 August 2026. The Dutch Senate adopted the law on 7 July 2026, together with the law on the resilience of critical entities. From that date, the duty of care, the reporting duty, and the registration duty apply.

Does my organisation fall under the law?

The law reaches more than 8,000 organisations across eighteen sectors, including energy, healthcare, transport, digital infrastructure, and government. Rule of thumb: mid-sized and large organisations in those sectors are covered, from roughly fifty employees or ten million euros in turnover. Some organisations are covered regardless of size.

What does the duty of care involve?

You must demonstrably manage cyber risks with appropriate measures: risk analysis, security of network and information systems, incident handling, business continuity, and supply chain security. Demonstrably is the key word: policy on paper is not enough.

How does the reporting duty work?

For a significant incident you give an early warning within 24 hours, a full report with a first assessment within 72 hours, and a final report within a month. Reports go to the CSIRT and the supervisor.

How high are the fines?

Up to 10 million euros or 2 percent of global annual turnover for essential entities, up to 7 million euros or 1.4 percent for important entities. On top of that, boards can be held personally accountable for serious negligence.

What does AI use have to do with NIS2?

AI tools are part of your attack surface, your data processing, and your supply chain, three things the duty of care wants under control. A data leak through an AI tool can become a reportable incident, and AI tools nobody approved are a supplier risk you cannot manage as long as you cannot see them.