Home / Dutch Cybersecurity Act & NIS2

Turn new obligations into practical action.

The Dutch Cybersecurity Act takes effect on 15 August 2026. From that date, organisations within scope must meet requirements for registration, risk management, incident notification and board accountability.

Legal position and improvement

Understand the duties that apply. Keep improving resilience.

Applicable duties depend on factors including sector, organisational size and statutory exceptions. Use the official NIS2 Self-Assessment and NCSC guidance for that assessment. The Digital Resilience Check does not assess the legal position; it looks at practical readiness and is equally useful where registration is not mandatory.

NorthBridge translates the outcome into business practice. Critical processes, dependencies, people, technology, suppliers and recovery capability come together in a risk- and impact-led improvement route.

What the Act requires

Three statutory duties and board accountability.

Registration duty

Organisations within scope must register in the national entity register through MijnNCSC from 15 August. Voluntary registration is already available.

Duty of care

A risk assessment must underpin proportionate technical, operational and organisational measures.

Incident notification

Significant incidents are reported in stages. The early warning is due as soon as possible and no later than 24 hours after detection.

Board accountability

The board approves the measures and oversees their implementation. Executive directors must acquire and maintain the required knowledge and skills.

Check applicability through the official NCSC starting point and the RDI NIS2 Self-Assessment. Our check begins with implementation and does not determine legal scope.

The NorthBridge route

From statutory duties to a practical improvement route.

NorthBridge connects relevant statutory principles and voluntary improvement goals to critical business processes, risk and existing decision-making. This creates a coherent route for ownership, priorities, delivery, evidence and reassessment.

Business context

Legal duties and voluntary improvement goals are connected to critical services, processes, information and supply-chain dependencies.

Ownership and decisions

Roles, reporting lines, decision-making and risk acceptance are clearly assigned.

Risk assessment and baseline

Policy, people, technology, suppliers, incident response and recovery are assessed as one system.

Priorities and roadmap

Urgent measures are distinguished from structural improvements and investment decisions.

Delivery and evidence

NorthBridge guides implementation, tracks measures and organises reassessment and accountability.

Proportionate measures based on risk

Technology follows context, risk and the existing architecture.

Technical measures support discovery, prevention, detection and recovery. Their value depends on a clear scope, appropriate configuration, expert interpretation and demonstrable follow-through. NorthBridge connects that technical practice to business impact and ownership.

Vulnerabilities and prioritisation

A defined, authorised assessment identifies relevant vulnerabilities and translates them into risk, business impact and concrete mitigating measures.

Digital resilience →
Network segmentation and access

Segmentation, firewall policy, strong authentication and managed access reduce the attack surface and help protect critical systems.

Network & Security →
Detection and incident follow-through

Monitoring and IDS/IPS help identify anomalies and known threat patterns. Pre-assigned ownership, escalation and response determine what happens next.

Detection and network security →
Cloud and supply-chain dependency

Data location, jurisdiction, concentration risk, supplier arrangements and a viable exit belong in the risk picture for critical services.

Cloud & Infrastructure →

Know your position. Strengthen resilience.

Make 15 August a concrete decision point.

Use the official channels to establish which statutory duties apply to your organisation. Use the check alongside that assessment to prioritise practical improvements — even where registration is not mandatory.

Official source basis

The statutory facts on this page are based on current information from the Dutch Government, NCSC, NCTV, RDI and the European NIS2 Directive. Always use the official channels for scope, registration and incident notification.