The question almost always arrives in this form: there is a list of questions on the table, there is a deadline attached, and someone wants to know whether this is actually mandatory. The short answer is that it probably is not legally mandatory for you, and that you will have to do it anyway.
Do I fall under the Dutch Cybersecurity Act?
The Cyberbeveiligingswet is the Dutch implementation of the European NIS2 directive and applies from 15 August 2026. The law targets organisations in designated sectors (among them healthcare, energy, transport, digital infrastructure and government), and mainly the larger parties within them.
If you are a company of twenty-five people servicing a hospital, you almost certainly do not fall under it yourself. Your customer does.
Whether you fall under it depends on your sector and your size. That is a legal question, and this page does not give an answer you can use with a regulator. If you are in doubt, that is worth a conversation with a lawyer, not with your IT supplier.
Then why am I getting this questionnaire?
Because the law obliges your customer to demonstrably assess the security of their entire supply chain. "Demonstrably" is the word that creates the work: your customer has to be able to show a regulator what they know about you and how they know it. Directors are personally liable for that.
The practical way out that almost everyone takes is to question their suppliers. Hence the list. An estimated 50,000 to 100,000 Dutch companies face these requirements this way without falling under the law themselves.
Can I refuse?
You can set the questionnaire aside. Your customer then cannot demonstrate that they assessed their supply chain, and that is exactly what they are judged on. In practice, not filling it in means the contract goes elsewhere at the next round.
So it is not a legal obligation but a contractual one. That distinction is useful to know, and changes nothing about what you have to do.
Who actually supervises this?
You: nobody, as long as you do not fall under the law yourself. Supervision is aimed at organisations in the designated sectors, and it is carried out per sector by the regulator appointed for it. There is no such thing as a fine for a supplier who falls short.
What does exist is the fine at your customer. The directive names amounts of up to ten million euro or two percent of worldwide annual turnover for essential entities, and up to seven million euro or 1.4 percent for important ones. Directors can also be held personally accountable. That explains the tone of the questionnaire you received: the sender has more at stake than you do.
For you, that risk translates into contract terms. Contracts increasingly carry a reporting deadline for incidents, a right to audit, and a right to terminate if you fall short. Those clauses are where the law actually reaches you, and there are not many of them; they are worth reading before you sign.
What is this going to cost me?
For most suppliers the cost is not in technology but in figuring things out. The basics customers ask for are largely functionality you already pay for and only have to switch on: multi-factor authentication is in virtually every mail package, disk encryption ships with Windows and macOS, and a backup schedule with a restore test mostly costs an afternoon of planning.
The real bill is the third questionnaire. Answer every list from scratch and you pay for the same hours each time. Record the answers once and you pay for them once.
What do I need to have arranged?
The measures at issue are set out in article 21(2) of the NIS2 directive. There are ten of them, and they are less exotic than the question forms suggest:
- risk analysis and security policy
- incident handling
- business continuity and backups
- supply chain security
- procurement, development and maintenance of systems
- testing whether the measures work
- cyber hygiene and training
- cryptography and encryption
- personnel, access control and assets
- multi-factor authentication and secure communication
Virtually every questionnaire you get from a customer is a translation of these. That is good news: you are in effect answering the same ten topics over and over in a different jacket.
Each of these ten has its own page in the guide, with what a customer asks about it and what you need to have on paper.
Where do I start?
Start by knowing where you stand. Go through the ten topics above and decide per topic whether it is arranged, half arranged, or not at all. That is exactly what your customer is asking you, only in their own form.
What you need after that is one place where that answer is recorded, so the next questionnaire is filling in rather than figuring out. How to tackle a customer questionnaire, and which first steps return the most, are covered elsewhere in this guide.
This page gives general information and is not legal advice. Whether your organisation falls under the Dutch Cybersecurity Act, and which obligations then apply, depends on your sector and your size.