Explainer
    Concepts
    Concepts

    Part of The company brain: where your organization's knowledge lives

    NIS2 and the Dutch Cybersecurity Act: what your data and AI layer must be able to prove

    The Dutch Cybersecurity Act (NIS2) has applied since 15 August 2026. What it requires, who is in scope and what your data platform and AI must be able to demonstrate.

    Max van Genderen6 min read
    Share on
    NIS2 and the Dutch Cybersecurity Act: what your data and AI layer must be able to prove

    The Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw) is the Dutch implementation of the European NIS2 directive. It has applied since 15 August 2026, with no transition period.1 More than 8,000 organisations in eighteen sectors must register, demonstrably manage their cyber risks and report significant incidents within fixed deadlines. The executive board carries final responsibility.

    Most articles about NIS2 focus on firewalls, workplaces and networks. Rightly so, but something is often missing: the layer where your data comes together and where your AI runs. That has become one of the most sensitive places in your organisation. It has access to almost everything, and more connections are added all the time.

    This article explains what the law requires, whether you are in scope, and what your data and AI layer must be able to demonstrate. It focuses on the Dutch implementation. Other EU member states have their own national laws with largely the same requirements.

    Is your organisation in scope?

    The law applies to medium-sized and large organisations in eighteen sectors. Medium-sized roughly means 50 or more employees or annual turnover above €10 million. The sectors include:

    • energy, drinking water and wastewater;
    • transport, including ports, aviation and logistics;
    • healthcare and pharmaceuticals;
    • digital infrastructure, cloud and ICT services;
    • the financial sector;
    • government;
    • manufacturing, food, chemicals, and postal and courier services.

    The law distinguishes between essential and important entities. The same duties apply to both. The difference lies in supervision and the level of fines.

    You must check for yourself whether you are in scope. The Dutch National Cyber Security Centre (NCSC) explains how to check this in two steps, pointing to the RDI self-assessment (in Dutch).2

    Not in scope? The law probably still affects you. The duty of care explicitly covers supply chain security. Customers who are in scope therefore set requirements for their suppliers, including software vendors, hosting providers and data consultancies.

    The four duties

    DutyWhat it means
    RegistrationRegister in the entity register via mijn.ncsc.nl, and keep the details up to date
    Duty of careA risk analysis, and appropriate technical and organisational measures to manage risks
    ReportingReport significant incidents: an early warning within 24 hours, a notification within 72 hours and a final report within one month. Also inform customers if they are affected
    Board responsibilityThe board approves the measures, oversees their implementation and completes appropriate training

    The reporting duty is separate from the GDPR. If a breach involves personal data, you must also report it to the Dutch Data Protection Authority within 72 hours.

    01IncidentSignificant for yourservices0224 hoursEarly warning0372 hoursIncident notification041 monthFinal reportYou report a significant incident in three steps, the first within 24 hours.

    Fines and supervision

    Regulators can impose fines:

    • up to €10 million or 2% of global annual turnover for essential entities;
    • up to €7 million or 1.4% for important entities.3

    Supervision is organised by sector, for example by the Dutch Authority for Digital Infrastructure (RDI), the Human Environment and Transport Inspectorate (ILT) or the Health and Youth Care Inspectorate (IGJ). Regulators have indicated they will mainly use the first year to get to know the new sectors. That doesn't make the law optional. It does mean that an organisation that can show a planned approach is in a better position.

    What the duty of care requires of your data and AI layer

    The duty of care lists a range of measures: risk analysis, incident response, business continuity, supply chain security, access and asset management, strong authentication, cryptography and testing whether measures work. For a data platform and AI, this translates into six questions you must be able to answer.

    1. AccessOne identity, revocable in one go2. Connections and agentsMinimal rights, centrally managed keys3. LoggingSee what happened, including AI4. RecoveryReproducible, with measured recovery time5. SuppliersSupply chain security and an exit scenario6. DemonstrabilityRecorded, not in people's headsWhat the duty of care concretely asks of the layer where your data and AI come together.

    1. Who has access, and can you revoke it in one go?

    A data platform collects data from almost every system. Whoever has access to it has access to a lot.

    What you must be able to prove: one identity for all access, MFA mandatory and role-based rights. Whoever leaves loses access everywhere at once. AI never shows more than the user is allowed to see. See also Sensitive data in Power BI: row-level security, object-level security and the layer underneath.

    2. Which systems and agents have access, and with which keys?

    AI introduces a new kind of user: agents and integrations that retrieve data on their own. Every agent with its own API key is an extra way in.

    What you must be able to prove: an overview of all connections and agents, with minimal rights, and keys that are managed centrally and can be revoked in one place. See also Connect once, not per agent.

    3. Can you see what happened?

    Without logging, you can't detect an incident, investigate it or report it within 24 hours.

    What you must be able to prove: logging of who requested what, which data flows are running, and which questions were asked of AI, with which answers. Those logs are themselves secured and kept long enough.

    4. Can you recover, and how quickly?

    Business continuity is not just about backups, but also about whether you can rebuild your platform.

    What you must be able to prove: point-in-time recovery, a set-up fully defined in code and therefore reproducible, and a disaster recovery test carried out every year, with measured recovery time.

    5. How secure are your suppliers?

    Your data platform runs on a cloud provider, uses third-party AI models and is often set up by a partner. Each of them is part of your supply chain.

    What you must be able to prove: data processing agreements, minimal rights for suppliers, data in the EU, and demonstrable security at your partners, for example through ISO 27001 certification. Also document an exit scenario.

    6. Can you demonstrate how it's set up?

    A regulator doesn't ask whether you are secure, but whether you can prove it.

    What you must be able to prove: a documented security baseline, an up-to-date risk analysis, and policies for SSO, cloud use and supplier selection. A set-up that only exists in the heads of a few people cannot be demonstrated.

    What the board must do

    The Cybersecurity Act explicitly places responsibility with the board. Executives must approve the measures, oversee their implementation and have enough knowledge to assess the risks.

    In practice that means:

    • cyber and NIS2 status as a standing agenda item, ideally together with AI;
    • an incident protocol with fixed deadlines that matches the law's 24 and 72 hours;
    • annual training for executives and supervisors.

    How to combine this with oversight of AI is covered in AI governance for boards and supervisory boards: value, ethics and stop rules and Five questions a supervisory board can ask about AI every quarter.

    NIS2 and the AI Act

    The two laws complement each other. The AI Act is about what AI may do and how transparent it must be. NIS2 is about the security of the systems AI runs on. An AI application that complies with the AI Act but runs on a poorly secured platform is still a risk. Read more in What is the EU AI Act? and The AI Act in the Netherlands: which law applies and who supervises.

    Frequently asked questions

    Is there a transition period? No. The registration, care and reporting duties have applied since 15 August 2026.

    What is the difference between NIS2 and the Cybersecurity Act? NIS2 is the European directive. The Cybersecurity Act is the Dutch law that implements it. Your obligations follow from the national law.

    What is a significant incident? An incident that significantly disrupts or could disrupt your services, or that causes considerable damage. The exact thresholds are set out in ministerial regulations.

    We're not in scope. Do we still need to do anything? Probably. Customers who are in scope set requirements for their suppliers through the supply chain duty. Voluntary reporting to the NCSC is also possible.

    Where do you start? With three things: check whether you are in scope and register, an up-to-date risk analysis, and a working reporting process for 24 and 72 hours. Request a foundation scan.

    Next step

    Want to see what's already inside your organization?

    Leave your details. We'll reach out and plan a scan. Within thirty days you'll see one concrete result.

    No newsletter, no reselling. Just this conversation.

    Comments

    Comments are reviewed by the editors before they appear.

    Use your Google or Apple account, or your business email address.

    Sign in to comment