In 2022, the European Union decided that cybersecurity levels must improve in every member state and enshrined this in the NIS2 Directive. The original deadline for all member states was October 2024, but after extensive debate about its implementation, the Dutch Senate only approved it this week. The deadline, however, is already 15 August. That means tens of thousands of businesses must start immediately. In the Netherlands, the NIS2 Directive is implemented through the Dutch Cybersecurity Act. The aim is to improve digital resilience and reduce the risk of service outages. Think of an airport, hospital, bank or data centre going offline, but also food production or water supplies.

So far, this sounds logical, and many large organisations will already be working on it. However, tens of thousands of other businesses will also be covered without yet realising it. For example, are you a food sector business with turnover above €10 million? Then you also belong to an important sector and must comply. Certain educational institutions, IT companies and smaller businesses in the supply chain must comply too. The overview below shows the sectors. On the left are sectors subject to proactive supervision; on the right are important sectors assessed when problems occur, or reactively.

The Dutch Cybersecurity Act is a fact — it takes effect on 15 August!

Having been an entrepreneur myself, I know most business owners are now thinking: I am on the right, so it is not that bad. The problem is that directors and management are personally liable under the law, and not knowing is no excuse. Fines can also be substantial. Even if you are in the supply chain of a covered business, you may need to act.

There is good news too. Ultimately, you benefit from it yourself, and meeting the law does not have to be that difficult. It provides a framework, but you can still decide much of the detail yourself. It is a matter of working through every step, which forces you to think about how things are organised in your business. For many businesses, this will reveal matters that are barely arranged, if at all. We already see companies outside the law's scope choosing to go through the exercise anyway, so they can show all their stakeholders that they are doing everything possible to prevent cyber problems.

The Dutch Cybersecurity Act is a fact — it takes effect on 15 August!

With Normatik we have developed a simple tool in which you can record everything. You simply work through all the obligations and document how they are addressed. That naturally reveals what has not yet been arranged. With our years of ISO 27001 experience, including internal audits, we can advise on the best way to organise particular matters. We can also check that everything is properly covered. We can even provide cyber hygiene training for management.

We are also building an AI component that lets you simply put your existing documents into your preferred AI tool, after which the information is assessed and entered in the right place in Normatik.

Wondering whether the Dutch Cybersecurity Act applies to you? Check here. If the answer is yes but you have no idea where to start, send me a message and I will be happy to help. Before you know it, it will be 15 August.