Since the Dutch Cybersecurity Act became a reality, I have heard many of the same responses. Often well meant, but almost always based on a misconception. Those misconceptions are precisely why businesses act too late. So here are the five most persistent ones, with an explanation of how things really stand.
Having been an entrepreneur myself, I understand exactly where these assumptions come from. You are busy enough already, and another law is the last thing you want. That is exactly why it helps to know where you stand.
Misconception 1: “We are too small; this is for the big companies”
This is by far the response I hear most often. I understand it: “cyber law” immediately brings banks, energy companies and data centres to mind. But the Dutch Cybersecurity Act affects around 8,000 organisations in 18 sectors. If you have more than 50 employees or turnover above €10 million and operate in a designated sector — such as manufacturing, ICT, transport, healthcare or food production — you are probably covered.
Even if you are not directly covered, it can still affect you. Larger businesses that are covered must include their entire supply chains. Do you supply such a business? Then they will impose requirements on you. In practice, there is no such thing as “too small”.
Misconception 2: “NIS2? The IT department will handle it”
If only it were that simple. NIS2 is about much more than a few technical settings. It concerns risk management, policies, responsibilities and agreements — in short, how you run your business.
And that is where the issue lies: management has ultimate responsibility. The law states that directors and management are personally liable if things go wrong and arrangements are found to be inadequate. “I did not know” or “IT should have handled that” is not a valid excuse. This is a management responsibility, not merely an IT matter.
Misconception 3: “We have antivirus and a firewall, so we are safe”
It is good that you have them. But the Dutch Cybersecurity Act requires more than a few sound technical measures. The law establishes registration, duty-of-care and reporting obligations. The duty of care comprises ten measures, from risk analyses and incident response plans to access management and business continuity. Significant incidents must be reported to the regulator within strict deadlines.
Already working with ISO 27001, DORA or NEN 7510? Then you have a substantial head start because there is considerable overlap. A firewall alone, however, is not enough. What matters is being able to demonstrate that your arrangements are sound.
Misconception 4: “There will probably be another extension”
I understand this one, because implementation has taken a long time. The European deadline was October 2024, and debate delayed the Dutch legislation. But it is now here: the Senate has approved the Dutch Cybersecurity Act, and it takes effect on 15 August 2026.
That is not a distant date — it is just a few weeks away. And the fines are substantial: up to €10 million or 2% of worldwide annual turnover , along with personal liability for management. Waiting for another extension is a gamble you would rather avoid.
Misconception 5: “Becoming compliant takes months and a fortune in consultants”
This may be the best misconception, because I have good news. Yes, hiring a consultant and starting from scratch can easily take months and tens of thousands of euros. But it no longer has to be that way.
Most of the groundwork — policy documents, risk analyses and measures — is largely the same for almost every SME. If it is already prepared, you only need to review it and adapt it to your situation. That is exactly why we built Normatik : a platform that guides you through the process step by step without requiring in-depth information security knowledge. In plain language, with a dashboard showing exactly where you stand. Compliant in weeks rather than months, at a fraction of the cost.
Finally
What do all these misconceptions have in common? They almost always cause businesses to wait too long. That is a shame, because good information security ultimately benefits you, regardless of the law. It makes you consider what would happen if your most important systems were unavailable for a day, and who is responsible for what. Questions you will want to be able to answer anyway.
Wondering whether the Dutch Cybersecurity Act applies to you, but have no idea where to start? Send me a message and I will be happy to help without obligation. Before you know it, it will be 15 August.