Article
18 Aug 2026
The Cyberbeveiligingswet is in force. Here is what actually changed
The Dutch NIS2 law took effect on 15 August 2026. What it requires, who it covers and why the flexible workforce is now part of the equation.

On 15 August 2026 the Cyberbeveiligingswet came into force, and with it the Netherlands completed its implementation of the European NIS2 directive. For most people the date passed quietly. For thousands of Dutch organisations it moved cybersecurity from good practice to legal duty.
The law applies to essential and important entities in designated sectors: food production and processing, transport, logistics and post, waste management, manufacturing, energy, water, healthcare, digital infrastructure and parts of public administration including municipalities and water authorities. Size thresholds apply, generally from around 50 employees or more than 10 million euro in annual turnover or balance sheet total, with sector-specific exceptions.
Three obligations now hold. A duty of care: risk management measures including cyber hygiene and training. A duty to report: serious incidents go to the NCSC within a strict chain of 24 hours, 72 hours and one month. A duty to register: in-scope entities enter the entiteitenregister. Supervision sits with the RDI, proactive for essential entities and after the fact for important ones, and fines run to legal maxima of 10 million euro or 2% of worldwide turnover for essential entities and 7 million or 1.4% for important ones.
The part most coverage misses sits in the duty of care. The law looks at how work is actually done, and in the sectors it covers, work is done to a large degree by temporary and hired-in workers. That makes the flexible workforce part of the compliance picture from day one, which is where the coming months get interesting for everyone who supplies, hires or manages flexible labour.
Whether your organisation possibly falls under the law depends on sector and size. Our sector pages walk through it.