V&V Group
NIS2 check

Does NIS2 apply to me?

Since 15 August 2026, the Cyberbeveiligingswet (Cbw), the Dutch implementation of NIS2, has been in force in the Netherlands. Answer six short questions and see straight away whether it is likely to apply to your organisation. It takes about two minutes.

Your answers stay in your own browser. We store nothing and send nothing anywhere.

1Is your organisation a government body?

For example, a ministry, province, municipality or water authority.

2Do you provide any of these services?

DNS services, a top-level domain registry (such as .nl), trust services (such as electronic signatures or certificates) or a public telecoms network or service.

3Which sector are you active in?

Pick the sector that best fits your main activity.

4How many employees does your organisation have?

In full-time equivalents (FTE). Count companies in which you hold a majority stake (or that hold one in you) in full, and smaller stakes proportionally.

5Which best describes your annual turnover and balance sheet total?

Count related companies the same way here.

6Do you work for clients that are covered by the Dutch Cybersecurity Act themselves?

For example, a care provider, energy company, municipality, transport company or hosting provider.

How the law works

Two things decide it: your sector and your size.

The Dutch Cybersecurity Act applies to medium-sized and large organisations in designated sectors. Some organisations are always covered, however small: providers of public electronic communications, trust services, DNS services and domain name registries, and government organisations.

Medium-sized or larger, and in a designated sector

If you operate in a sector covered by the law, it applies from 50 employees, or if your annual turnover and balance sheet total both exceed €10 million. Companies in which you hold a majority stake (or that hold one in you) count in full; smaller stakes count proportionally.

If you are not in a designated sector, the law does not apply to your organisation, however large it is.

Essential or important

Large organisations (from 250 employees, or turnover above €50 million and a balance sheet total above €43 million) in a highly critical sector are usually essential. Medium-sized organisations and organisations in the other critical sectors are usually important.

Both must have their security in order and report serious incidents. Essential entities are supervised proactively; important entities mainly after the fact.

Through your clients

Even if the law doesn't apply to you, you'll often still feel its effects. Organisations that are covered must also manage the risks in their supply chain. Expect questionnaires, contract clauses and sometimes an audit.

What if it applies to you?

You register your organisation with the NCSC, take appropriate security measures (the duty of care) and report serious incidents. Management is ultimately responsible. We help you step by step, often using ISO 27001 as the framework.