Part of The company brain: where your organization's knowledge lives
NIS2 and the Dutch Cybersecurity Act: what your data and AI layer must be able to prove
The Dutch Cybersecurity Act (NIS2) has applied since 15 August 2026. What it requires, who is in scope and what your data platform and AI must be able to demonstrate.

The Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw) is the Dutch implementation of the European NIS2 directive. It has applied since 15 August 2026, with no transition period.1 More than 8,000 organisations in eighteen sectors must register, demonstrably manage their cyber risks and report significant incidents within fixed deadlines. The executive board carries final responsibility.
Most articles about NIS2 focus on firewalls, workplaces and networks. Rightly so, but something is often missing: the layer where your data comes together and where your AI runs. That has become one of the most sensitive places in your organisation. It has access to almost everything, and more connections are added all the time.
This article explains what the law requires, whether you are in scope, and what your data and AI layer must be able to demonstrate. It focuses on the Dutch implementation. Other EU member states have their own national laws with largely the same requirements.
Is your organisation in scope?
The law applies to medium-sized and large organisations in eighteen sectors. Medium-sized roughly means 50 or more employees or annual turnover above €10 million. The sectors include:
- energy, drinking water and wastewater;
- transport, including ports, aviation and logistics;
- healthcare and pharmaceuticals;
- digital infrastructure, cloud and ICT services;
- the financial sector;
- government;
- manufacturing, food, chemicals, and postal and courier services.
The law distinguishes between essential and important entities. The same duties apply to both. The difference lies in supervision and the level of fines.
You must check for yourself whether you are in scope. The Dutch National Cyber Security Centre (NCSC) explains how to check this in two steps, pointing to the RDI self-assessment (in Dutch).2
Not in scope? The law probably still affects you. The duty of care explicitly covers supply chain security. Customers who are in scope therefore set requirements for their suppliers, including software vendors, hosting providers and data consultancies.
The four duties
| Duty | What it means |
|---|---|
| Registration | Register in the entity register via mijn.ncsc.nl, and keep the details up to date |
| Duty of care | A risk analysis, and appropriate technical and organisational measures to manage risks |
| Reporting | Report significant incidents: an early warning within 24 hours, a notification within 72 hours and a final report within one month. Also inform customers if they are affected |
| Board responsibility | The board approves the measures, oversees their implementation and completes appropriate training |
The reporting duty is separate from the GDPR. If a breach involves personal data, you must also report it to the Dutch Data Protection Authority within 72 hours.
You report a significant incident in three steps, the first within 24 hours.
Fines and supervision
Regulators can impose fines:
- up to €10 million or 2% of global annual turnover for essential entities;
- up to €7 million or 1.4% for important entities.3
Supervision is organised by sector, for example by the Dutch Authority for Digital Infrastructure (RDI), the Human Environment and Transport Inspectorate (ILT) or the Health and Youth Care Inspectorate (IGJ). Regulators have indicated they will mainly use the first year to get to know the new sectors. That doesn't make the law optional. It does mean that an organisation that can show a planned approach is in a better position.
What the duty of care requires of your data and AI layer
The duty of care lists a range of measures: risk analysis, incident response, business continuity, supply chain security, access and asset management, strong authentication, cryptography and testing whether measures work. For a data platform and AI, this translates into six questions you must be able to answer.
What the duty of care concretely asks of the layer where your data and AI come together.
1. Who has access, and can you revoke it in one go?
A data platform collects data from almost every system. Whoever has access to it has access to a lot.
What you must be able to prove: one identity for all access, MFA mandatory and role-based rights. Whoever leaves loses access everywhere at once. AI never shows more than the user is allowed to see. See also Sensitive data in Power BI: row-level security, object-level security and the layer underneath.
2. Which systems and agents have access, and with which keys?
AI introduces a new kind of user: agents and integrations that retrieve data on their own. Every agent with its own API key is an extra way in.
What you must be able to prove: an overview of all connections and agents, with minimal rights, and keys that are managed centrally and can be revoked in one place. See also Connect once, not per agent.
3. Can you see what happened?
Without logging, you can't detect an incident, investigate it or report it within 24 hours.
What you must be able to prove: logging of who requested what, which data flows are running, and which questions were asked of AI, with which answers. Those logs are themselves secured and kept long enough.
4. Can you recover, and how quickly?
Business continuity is not just about backups, but also about whether you can rebuild your platform.
What you must be able to prove: point-in-time recovery, a set-up fully defined in code and therefore reproducible, and a disaster recovery test carried out every year, with measured recovery time.
5. How secure are your suppliers?
Your data platform runs on a cloud provider, uses third-party AI models and is often set up by a partner. Each of them is part of your supply chain.
What you must be able to prove: data processing agreements, minimal rights for suppliers, data in the EU, and demonstrable security at your partners, for example through ISO 27001 certification. Also document an exit scenario.
6. Can you demonstrate how it's set up?
A regulator doesn't ask whether you are secure, but whether you can prove it.
What you must be able to prove: a documented security baseline, an up-to-date risk analysis, and policies for SSO, cloud use and supplier selection. A set-up that only exists in the heads of a few people cannot be demonstrated.
What the board must do
The Cybersecurity Act explicitly places responsibility with the board. Executives must approve the measures, oversee their implementation and have enough knowledge to assess the risks.
In practice that means:
- cyber and NIS2 status as a standing agenda item, ideally together with AI;
- an incident protocol with fixed deadlines that matches the law's 24 and 72 hours;
- annual training for executives and supervisors.
How to combine this with oversight of AI is covered in AI governance for boards and supervisory boards: value, ethics and stop rules and Five questions a supervisory board can ask about AI every quarter.
NIS2 and the AI Act
The two laws complement each other. The AI Act is about what AI may do and how transparent it must be. NIS2 is about the security of the systems AI runs on. An AI application that complies with the AI Act but runs on a poorly secured platform is still a risk. Read more in What is the EU AI Act? and The AI Act in the Netherlands: which law applies and who supervises.
Frequently asked questions
Is there a transition period? No. The registration, care and reporting duties have applied since 15 August 2026.
What is the difference between NIS2 and the Cybersecurity Act? NIS2 is the European directive. The Cybersecurity Act is the Dutch law that implements it. Your obligations follow from the national law.
What is a significant incident? An incident that significantly disrupts or could disrupt your services, or that causes considerable damage. The exact thresholds are set out in ministerial regulations.
We're not in scope. Do we still need to do anything? Probably. Customers who are in scope set requirements for their suppliers through the supply chain duty. Voluntary reporting to the NCSC is also possible.
Where do you start? With three things: check whether you are in scope and register, an up-to-date risk analysis, and a working reporting process for 24 and 72 hours. Request a foundation scan.
Sources
Every claim in this article can be checked at the source.
- 1
- 2
- 3
- 4
- 5
Browse further
- Topic
- Concepts