Does NIS2 apply to me?
Since 15 August 2026, the Cyberbeveiligingswet (Cbw), the Dutch implementation of NIS2, has been in force in the Netherlands. Answer six short questions and see straight away whether it is likely to apply to your organisation. It takes about two minutes.
Your answers stay in your own browser. We store nothing and send nothing anywhere.
This is a first indication, not legal advice. The official check is the NIS2 self-assessment by the RDI (in Dutch). In doubt? Just ask us. Your first question is free.
Two things decide it: your sector and your size.
The Dutch Cybersecurity Act applies to medium-sized and large organisations in designated sectors. Some organisations are always covered, however small: providers of public electronic communications, trust services, DNS services and domain name registries, and government organisations.
Medium-sized or larger, and in a designated sector
If you operate in a sector covered by the law, it applies from 50 employees, or if your annual turnover and balance sheet total both exceed €10 million. Companies in which you hold a majority stake (or that hold one in you) count in full; smaller stakes count proportionally.
If you are not in a designated sector, the law does not apply to your organisation, however large it is.
Essential or important
Large organisations (from 250 employees, or turnover above €50 million and a balance sheet total above €43 million) in a highly critical sector are usually essential. Medium-sized organisations and organisations in the other critical sectors are usually important.
Both must have their security in order and report serious incidents. Essential entities are supervised proactively; important entities mainly after the fact.
Through your clients
Even if the law doesn't apply to you, you'll often still feel its effects. Organisations that are covered must also manage the risks in their supply chain. Expect questionnaires, contract clauses and sometimes an audit.
What if it applies to you?
You register your organisation with the NCSC, take appropriate security measures (the duty of care) and report serious incidents. Management is ultimately responsible. We help you step by step, often using ISO 27001 as the framework.