← Back to blog
Security

The Dutch Cybersecurity Act makes directors personally liable: what to put in order now

By Zarioh Digital Solutions4 min read
Share

Since 15 August 2026, the Dutch Cybersecurity Act, the national implementation of the EU NIS2 directive, has applied without a transition period. Eight thousand organisations fall under it directly, with thousands more suppliers caught through the chain. Yet barely a third of the organisations in scope are actively working on compliance. What the duty of care, the reporting obligation and director liability concretely mean for your organisation.

The Cyberbeveiligingswet, the Dutch implementation of the EU NIS2 directive, has simply been law since 15 August 2026. No pilot, no transition period, no leniency for organisations that are not yet ready. Around eight thousand organisations in the Netherlands fall directly under new cyber risk obligations from that date, with roughly five hundred more covered by the related Critical Entities Resilience Act. On top of that, tens of thousands of suppliers are drawn in through contractual requirements imposed by their clients.

What sets this law apart from earlier regulation is where the responsibility sits. No longer only with the IT department or the outsourced provider, but explicitly with the board. That changes the conversation you need to have as a director or owner, and the pace at which you need to have it.

Does it apply to you, even if nobody told you

The eight thousand organisations directly covered sit in sectors such as energy, healthcare, digital infrastructure, transport and financial services. But the law reaches further than that list. If you supply services or products to an organisation that does fall under it, clients often pass the requirements straight through into their contracts. An IT supplier, a logistics company or a software vendor that never thought it fell under the Cyberbeveiligingswet can end up with the same obligations anyway, through procurement terms.

The advice is simple, but often skipped: ask your largest clients and your trade association directly, rather than assuming this law is someone else's problem.

Duty of care: appropriate measures, but who decides what is appropriate

The duty of care requires organisations to take appropriate technical and organisational measures against cyber risk, including risk in the supply chain. The law does not prescribe a fixed checklist. You decide, and must be able to justify, what is appropriate given the size of your organisation, the sensitivity of your data and how dependent you are on your systems.

In practice this means, at minimum, a current overview of your systems and suppliers, a risk assessment you repeat periodically, and an incident response plan that exists on paper and has actually been rehearsed. A plan that has never been tested counts for little once something genuinely goes wrong.

Reporting duty: the clock starts at the first suspicion

Once a significant incident occurs, a tight timeline begins. Within 24 hours you must submit an early warning to the National Cyber Security Centre. Within 72 hours a more detailed assessment of the nature and impact of the incident follows. Within a month you deliver a final report covering the cause, the measures taken and the lessons learned.

Anyone reading this for the first time tends to underestimate how tight 24 hours is at the moment an incident has just been discovered and nobody yet knows exactly what happened. A reporting procedure you have defined in advance, including who inside your organisation is authorised and required to report, saves valuable time at that point.

Director liability: no longer just an IT file

The law requires board members to approve the risk measures taken, oversee their implementation and complete training on cyber risk themselves. Failing to do so can lead to personal liability, separate from the liability of the organisation itself. Fines for the organisation reach up to 10 million euros or 2 percent of global annual turnover for the most heavily regulated category of organisations, and up to 7 million euros or 1.4 percent for the lighter category, with the higher amount always applying.

For many board members, this is new territory. Research among cybersecurity experts shows that board members typically have only a basic understanding of cybersecurity, while the law now expects them to be able to account for it in substance. A training session once completed for appearances' sake no longer suffices.

Why barely a third is actually ready

Industry research into compliance with the law paints an uncomfortable picture. Of the organisations covered by the Cyberbeveiligingswet, an estimated third or so is actually actively working on compliance. More than half are still at the very beginning. The risk experts point to is that organisations treat the law as a paperwork exercise: supplying documents to satisfy the letter of the law without the underlying resilience improving.

That distinction is exactly what matters. A policy document sitting in a folder protects nobody. An organisation that knows its systems, has assessed its suppliers and has rehearsed its reporting procedure is in a fundamentally different position when an incident hits.

What you can do this month

Start by establishing whether your organisation, directly or through a client, falls under the law. Then build a current overview of systems, data and suppliers, and tie it to a risk assessment the board has actually seen and approved. Draft a reporting procedure with clear responsibilities, so nobody has to work out in the moment who calls the National Cyber Security Centre. Plan training for board members that is not a single video watched in passing, but demonstrably completed.

Zarioh helps organisations set up the security, monitoring and incident response that this duty of care requires. Want to know where your organisation stands against the Cyberbeveiligingswet? Get in touch for a no-obligation conversation.

Z

Zarioh Digital Solutions

IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony, and share what we learn in practice. Follow us on LinkedIn

Related articles

← Back to all articles
Share