Organisations within scope must register in the national entity register through MijnNCSC from 15 August. Voluntary registration is already available.
Turn new obligations into practical action.
The Dutch Cybersecurity Act takes effect on 15 August 2026. From that date, organisations within scope must meet requirements for registration, risk management, incident notification and board accountability.
Legal position and improvement
Understand the duties that apply. Keep improving resilience.
Applicable duties depend on factors including sector, organisational size and statutory exceptions. Use the official NIS2 Self-Assessment and NCSC guidance for that assessment. The Digital Resilience Check does not assess the legal position; it looks at practical readiness and is equally useful where registration is not mandatory.
NorthBridge translates the outcome into business practice. Critical processes, dependencies, people, technology, suppliers and recovery capability come together in a risk- and impact-led improvement route.
What the Act requires
Three statutory duties and board accountability.
A risk assessment must underpin proportionate technical, operational and organisational measures.
Significant incidents are reported in stages. The early warning is due as soon as possible and no later than 24 hours after detection.
The board approves the measures and oversees their implementation. Executive directors must acquire and maintain the required knowledge and skills.
The NorthBridge route
From statutory duties to a practical improvement route.
NorthBridge connects relevant statutory principles and voluntary improvement goals to critical business processes, risk and existing decision-making. This creates a coherent route for ownership, priorities, delivery, evidence and reassessment.
Business context
Legal duties and voluntary improvement goals are connected to critical services, processes, information and supply-chain dependencies.
Ownership and decisions
Roles, reporting lines, decision-making and risk acceptance are clearly assigned.
Risk assessment and baseline
Policy, people, technology, suppliers, incident response and recovery are assessed as one system.
Priorities and roadmap
Urgent measures are distinguished from structural improvements and investment decisions.
Delivery and evidence
NorthBridge guides implementation, tracks measures and organises reassessment and accountability.
Proportionate measures based on risk
Technology follows context, risk and the existing architecture.
Technical measures support discovery, prevention, detection and recovery. Their value depends on a clear scope, appropriate configuration, expert interpretation and demonstrable follow-through. NorthBridge connects that technical practice to business impact and ownership.
A defined, authorised assessment identifies relevant vulnerabilities and translates them into risk, business impact and concrete mitigating measures.
Digital resilience →Segmentation, firewall policy, strong authentication and managed access reduce the attack surface and help protect critical systems.
Network & Security →Monitoring and IDS/IPS help identify anomalies and known threat patterns. Pre-assigned ownership, escalation and response determine what happens next.
Detection and network security →Data location, jurisdiction, concentration risk, supplier arrangements and a viable exit belong in the risk picture for critical services.
Cloud & Infrastructure →Know your position. Strengthen resilience.
Make 15 August a concrete decision point.
Use the official channels to establish which statutory duties apply to your organisation. Use the check alongside that assessment to prioritise practical improvements — even where registration is not mandatory.
Official source basis
The statutory facts on this page are based on current information from the Dutch Government, NCSC, NCTV, RDI and the European NIS2 Directive. Always use the official channels for scope, registration and incident notification.