Sinds 15 augustus 2026 is NIS2 in Nederland wet: de Cyberbeveiligingswet, zonder overgangstermijn, voor ruim 8.000 organisaties. Bij de meeste daarvan is de registratie bij het NCSC inmiddels gedaan, en daarmee is de aandacht weer verslapt. Begrijpelijk, maar de registratie is het makkelijkste deel. Wat de wet werkelijk vraagt, staat niet in het register.
Since 15 August 2026, NIS2 has been law in the Netherlands: the Cyberbeveiligingswet (Cybersecurity Act), with no transition period, for more than 8,000 organisations. Most of them have completed their registration with the NCSC by now, and attention has moved on. Understandable, but registration is the easy part. What the law really asks for is not in the register.
De wet kent vier verplichtingen. Een zorgplicht: passende en evenredige maatregelen, gebaseerd op een eigen risicobeoordeling, voor de beveiliging van netwerk- en informatiesystemen én voor de continuïteit van de dienstverlening. Een meldplicht: bij een significant incident een vroege waarschuwing binnen 24 uur, een vervolgmelding binnen 72 uur en een eindverslag binnen een maand, via het portaal van het NCSC, dat de melding doorzet naar het sectorale CSIRT en de toezichthouder. Een registratieplicht in het nationale entiteitenregister, waarbij wijzigingen binnen veertien dagen moeten worden doorgegeven. En een bestuursplicht: het bestuur keurt de maatregelen goed, houdt toezicht op de uitvoering en volgt een training, uiterlijk binnen twee jaar na inwerkingtreding.
The law has four obligations. A duty of care: appropriate and proportionate measures, based on your own risk assessment, for the security of network and information systems and for the continuity of services. A notification duty: for a significant incident, an early warning within 24 hours, a follow-up notification within 72 hours and a final report within a month, through the NCSC portal, which forwards the notification to the sectoral CSIRT and the supervisory authority. A registration duty in the national entity register, with changes to be reported within fourteen days. And a board duty: the management body approves the measures, oversees their implementation and completes training, within two years of entry into force at the latest.
Wie toezicht houdt, hangt af van de sector: de Rijksinspectie Digitale Infrastructuur (RDI) voor onder meer digitale infrastructuur, energie en overheid, de ILT voor vervoer en water, DNB en AFM voor de financiële sector. Voor overheidsorganisaties wordt de zorgplicht ingevuld met de BIO2, die sinds eind 2025 de oude BIO vervangt en niet langer met vaste beveiligingsniveaus werkt, maar met een eigen risicoafweging.
Who supervises depends on the sector: the Dutch Authority for Digital Infrastructure (RDI) for digital infrastructure, energy and government among others, the ILT for transport and water, DNB and AFM for the financial sector. For public bodies, the duty of care is specified by BIO2, which has replaced the old BIO since late 2025 and no longer works with fixed security levels but with the organisation's own risk assessment.
De registratie is een administratieve stap. Hij geeft toegang tot de dienstverlening van het NCSC of het sectorale CSIRT: dreigingsinformatie en bijstand bij incidenten. Dat is nuttig, maar het zegt niets over de vraag waar de toezichthouder straks naar kijkt: of de maatregelen passen bij de risico's, en of het bestuur daar aantoonbaar over heeft besloten. Bij essentiële entiteiten is dat toezicht proactief, de toezichthouder komt dus langs zonder dat er iets is gebeurd. Bij belangrijke entiteiten is het reactief, na een incident of een signaal. In beide gevallen is de vraag dezelfde, en een registratiebevestiging beantwoordt hem niet.
Registration is an administrative step. It gives access to the services of the NCSC or the sectoral CSIRT: threat information and assistance during incidents. That is useful, but it says nothing about the question the supervisory authority will eventually ask: whether the measures fit the risks, and whether the board has demonstrably decided on them. For essential entities that supervision is proactive, so the regulator comes by without anything having happened. For important entities it is reactive, after an incident or a signal. In both cases the question is the same, and a registration confirmation does not answer it.
Ten eerste: een risicobeoordeling die een bestuursbesluit is, geen IT-document. Benoem welke diensten nooit mogen uitvallen, welke informatie nooit mag uitlekken en welke leveranciers daarbij kritiek zijn, en leg vast welke risico's je accepteert en welke niet. Dat besluit is de kern van de zorgplicht; alle maatregelen hangen eraan.
First: a risk assessment that is a board decision, not an IT document. Name which services must never fail, which information must never leak and which suppliers are critical to that, and record which risks you accept and which you do not. That decision is the core of the duty of care; every measure hangs on it.
Ten tweede: test de meldroute voordat je hem nodig hebt. Wie bepaalt of een incident significant is, wie meldt, wie informeert klanten en wie het bestuur? Een middag met een realistisch scenario laat zien of de eerste 24 uur werken. Meestal blijkt dat de techniek er is, maar dat niemand het mandaat heeft.
Second: test the notification route before you need it. Who decides whether an incident is significant, who notifies, who informs clients and who informs the board? An afternoon with a realistic scenario shows whether the first 24 hours work. Usually it turns out the technology is there, but nobody has the mandate.
Ten derde: plan de bestuurderstraining nu in, en maak hem nuttig. Een verplichte training kan een formaliteit zijn, of het moment waarop het bestuur de eigen risicobeoordeling bespreekt en keuzes maakt over wat beveiliging mag kosten. Dat tweede is wat de wet bedoelt, en wat een toezichthouder herkent.
Third: schedule the board training now, and make it useful. Mandatory training can be a formality, or the moment at which the board discusses its own risk assessment and makes choices about what security may cost. The latter is what the law intends, and what a supervisory authority recognises.
Tegelijk met de Cyberbeveiligingswet is de Wet weerbaarheid kritieke entiteiten (Wwke) in werking getreden, de Nederlandse uitwerking van de Europese CER-richtlijn. Die raakt een kleinere groep: zo'n vijfhonderd organisaties die door hun ministerie als kritieke entiteit worden aangewezen, in sectoren als energie, vervoer, drinkwater, zorg, bankwezen en levensmiddelen. Na aanwijzing heb je negen maanden voor een eigen risicobeoordeling en tien maanden voor passende technische, organisatorische en fysieke maatregelen, en geldt een meldplicht van 24 uur bij aanzienlijke verstoringen. Het gaat hier niet alleen om cyber, maar ook om sabotage, extreem weer en uitval in de keten.
Alongside the Cyberbeveiligingswet, the Wet weerbaarheid kritieke entiteiten (Wwke) entered into force, the Dutch implementation of the European CER Directive. It affects a smaller group: around five hundred organisations designated as critical entities by their ministry, in sectors such as energy, transport, drinking water, healthcare, banking and food. After designation you have nine months for your own risk assessment and ten months for appropriate technical, organisational and physical measures, and a 24-hour notification duty applies to significant disruptions. This is not only about cyber, but also about sabotage, extreme weather and failures in the supply chain.
Wie dit leest als business continuity in wettelijke vorm, heeft het goed begrepen: een bruikbare business impact analyse en geoefende continuïteitsplannen zijn precies wat de wet vraagt. Kritieke entiteiten vallen bovendien ook onder de Cyberbeveiligingswet, dus beide trajecten horen in één hand.
If you read this as business continuity in legal form, you have understood it correctly: a usable business impact analysis and exercised continuity plans are exactly what the law asks for. Critical entities also fall under the Cyberbeveiligingswet, so both tracks belong in one hand.
Niet bij de wettekst en niet bij een checklist van honderd punten. Begin bij het besluit: wat mag bij jou nooit uitvallen of uitlekken, en wat is dat je waard? Daarna volgt de rest, in een volgorde die past bij budget en draagkracht. Wie dat doet, ontdekt dat de Cyberbeveiligingswet nauwelijks iets vraagt wat een behoorlijk bestuurde organisatie niet toch al had moeten regelen. De wet maakt het alleen aantoonbaar verplicht.
Not with the legal text and not with a hundred-item checklist. Start with the decision: what must never fail or leak in your organisation, and what is that worth to you? The rest follows, in an order that fits budget and capacity. Do that, and you will find the Cyberbeveiligingswet asks for hardly anything a well-governed organisation should not have arranged anyway. The law merely makes it demonstrably mandatory.
Plan een vrijblijvende kennismaking van 30 minuten. Je krijgt geen verkooppraatje, wel drie concrete observaties over je huidige weerbaarheid.
Book a free 30-minute introduction. No sales pitch: you will leave with three concrete observations about your current resilience.