The sector list comes straight from the European NIS2 directive and has been carried over into the Dutch act. The list is long, but the distinction is manageable: there are highly critical sectors ("essential") and critical sectors ("important"), and a threshold on size applies.
Which sectors are essential?
The highly critical sectors from annex I of the directive:
- energy (electricity, gas, oil, heating, hydrogen)
- transport (air, rail, water, road)
- banking and financial market infrastructure
- healthcare, including laboratories and manufacturers of medical devices that are critical during an emergency
- drinking water and waste water
- digital infrastructure (data centres, cloud providers, DNS, internet exchange points)
- management of ICT services for business customers, such as managed service providers
- public administration
- space
Which sectors are important?
The critical sectors from annex II:
- postal and courier services
- waste management
- chemicals (production and distribution)
- food (production, processing and distribution)
- manufacturing: medical devices, electronics, machinery, transport equipment
- digital providers: online marketplaces, search engines, social networks
- research organisations
For the duty of care the distinction matters little; essential entities are mainly subject to stricter supervision up front.
Is there a threshold on company size?
Yes. As a rule an organisation only falls under the law from fifty staff or ten million euro annual turnover upwards. Below that the law usually stays out of the picture, with exceptions for parties that are critical on their own, such as DNS service providers or parties that are the sole supplier of an essential service in a region.
What is the difference between essential and important?
Not the duty of care. Both groups have to take the same ten measures; the difference is in supervision and in the sanction. At essential entities the regulator may turn up without cause: audits, inspections and security scans in advance. At important entities that happens in principle only once there is an indication that something is wrong, so after the fact.
The maximum fines differ too. The directive names up to ten million euro or two percent of worldwide annual turnover for essential entities, and up to seven million euro or 1.4 percent for important ones.
For you as a supplier the distinction mostly shows in tone and tempo. An essential customer has a regulator who can ask unprompted what their chain assessment looks like, so that customer needs your answer sooner, more completely, and more often.
I supply a customer who does fall under it. Am I in the law then?
No. There is no category of "supplier to an essential entity" in the law. You are not in it, you are not registered, and the regulator has no powers towards you.
What does happen: your customer has to weigh the risks of their suppliers, and that translates into requirements they formulate themselves. The more critical your service is to their primary process, the heavier those requirements turn out. A party with administrative access to their systems gets a different conversation than a party supplying office stationery. See also assessing your own suppliers: the same reasoning applies one link further along, and that question comes back to you.
My sector is not on the list. Am I done then?
No, and that is exactly why this law affects so many companies. Whoever does fall under it has to demonstrably assess the security of their entire supply chain. A machine builder supplying an energy company, a cleaning company in a hospital, a software agency with a municipality as its customer: they fall under nothing themselves and still get the requirements on their plate, through their customer's questionnaire.
How do I know whether my customer falls under it?
Usually because they tell you, since that is precisely why a questionnaire arrives. If you want to estimate it in advance, two questions are enough: is your customer's main activity in one of the lists above, and do they have fifty staff or more? Two yesses means almost certainly yes.
There are borderline cases too. An organisation can fall under the law for part of its activities and not for the rest, and some parties count regardless of size because they are critical on their own. In the meantime, do not assume it will be fine: the answer changes nothing about what you have to do, because the questions you get are about the same ten topics, and those are sensible without a law as well. See the first steps.
Whether or not you are on the list: the questions you can expect are about the ten duty of care measures.
This page gives general information and is not legal advice. Whether an organisation falls under the Dutch Cybersecurity Act depends on its exact activities, its sector and its size.