The Cyberbeveiligingswet is the Dutch implementation of the European NIS2 directive. Its start date is 15 August 2026.
What changes from that date?
Organisations in the designated sectors (among them healthcare, energy, transport, digital infrastructure and government) take on a duty of care. It has two parts that in practice are joined at the hip: they have to have their own security in order, and they have to assess the security of their supply chain. Directors are personally liable for it.
That second part is why this law also affects companies that do not fall under it themselves.
I supply such an organisation. What will I notice?
That your customer wants to know something about you, and wants it on paper. In practice that comes down to a questionnaire, a request for policy documents, or a clause in the next contract renewal.
An estimated 50,000 to 100,000 Dutch companies deal with this without falling under the law themselves. See also Do I have to meet NIS2 as a supplier?.
Am I too late if I only start now?
No. There is no date on which a door closes for you, because you do not fall under the law yourself; there is only a difference between answering at your own pace and answering in the week a contract has to be renewed.
You will be running after the questions rather than ahead of them, though. From the start date your customer has to be able to show that they assess their supply chain, and procurement and compliance departments begin well before that date, because they need time to process the answers themselves. At many suppliers the first list landed before the law even applied.
If you wait for your largest customer's deadline, you do the work under time pressure, and then it costs more than it needs to.
Is there a transition period?
Not for the duty of care. The obligations apply from the moment the act takes effect; there is no year of grace in which an organisation does not yet have to meet the requirements. What does take time is registering entities and building up supervision: in practice regulators start with guidance and with the heaviest sectors, not with spot checks on everyone from day one.
For you as a supplier that changes little. Your customer is not waiting for the regulator to start assessing their chain; they start once their own compliance department puts the subject on the agenda, and at most organisations that happened long ago.
Does anything change after the start date?
Not the duty of care itself. The ten topics are set out in the directive and do not change from year to year; arrange them once and they stay arranged.
What does move is the sharpness of the questions. Regulators publish sector guidance, trade associations produce their own standard lists, and customers who have one round behind them probe further the second time: no longer whether you make backups, but when you last tested restoring them and what came out of it. So expect the questionnaires to get more specific rather than to go away. See proving your measures work.
What if my customer is in another EU country?
Then the national implementation of the same NIS2 directive applies there. The topics are identical, because they are set out in article 21(2) of the directive itself; so are the deadlines for incident reporting. The differences are in execution: which regulator, which registration duty, and how strictly it is enforced.
In practice that means a German or Belgian customer sends you a questionnaire based on the same ten topics, often in English. Your answers do not have to differ for that; the translation is in the wording, not in the substance.
My customer has not asked anything yet. Am I fine?
Most likely it only means your turn has not come. Procurement and compliance departments start with the suppliers closest to the primary process and work outwards from there. A party with access to systems or data comes up sooner than a party supplying office stationery.
There is one situation where silence means something else: when your customer does not yet know they fall under the law themselves. That happens at organisations that have just grown past the fifty-employee threshold or sit in a sector where the boundary is not obvious. See which sectors fall under it. The question still comes, only later and in more of a hurry.
Where do I start?
Knowing where you stand is the one thing you can do without a budget or a project. Go through the ten duty of care measures and decide per topic whether it is arranged, half arranged, or not at all. That costs a morning and immediately gives you an order in which to tackle the open points.
After that you have something to share when the first questionnaire arrives, instead of an afternoon spent finding out who knows the answer.
This page gives general information and is not legal advice. Whether your organisation falls under the Cyberbeveiligingswet, and which obligations then apply exactly, depends on your sector and size.