Knowledge baseNetwork

NIS2 in practice: how we handle the Dutch Cyber Security Act

12 August 20265 min read

"NIS2 — that's something for big companies." It is the most common, and the most misplaced, reaction to the law that enters into force on 15 August 2026 as the Dutch Cyber Security Act (Cyberbeveiligingswet), the national implementation of the European NIS2 directive. For most sectors a size threshold does indeed apply. But in digital infrastructure it is not how big you are that counts, it is what you deliver: anyone providing DNS services, for instance, is an essential entity — regardless of size. We know this first-hand, because we fall under the law ourselves.

Three obligations

At its core the law comes down to three duties:

  • Registration duty — you register your organisation with the NCSC, including details of your services and networks.
  • Duty of care — ten mandatory measures (article 21), from risk management and incident handling to supply-chain security and MFA. Not as a paper exercise, but demonstrably in place.
  • Reporting duty — significant incidents are reported in phases: an early warning within 24 hours, a full notification within 72 hours, a final report within a month.

For the digital-infrastructure sector the RDI is the regulator, and for essential entities its supervision is proactive — the regulator can come and look without anything having gone wrong first. For DNS service providers and comparable parties there is also a European implementing regulation that sets technical requirements per measure and defines when an incident is "significant". Interpretation is no longer a matter of taste there.

The ten measures, briefly

Risk analysis and security policy; incident handling; business continuity with backups, a recovery plan and crisis management; supply-chain security; secure development and vulnerability management; periodic assessment of whether your measures work; cyber hygiene and training; cryptography; access policy and asset management; and MFA with secured communication. Anyone already serious about information security will recognise the list — what is new is that it becomes demonstrable and enforceable, with personal accountability for the board.

How we set it up

The law has a proportionality principle: measures must fit your size, cost and risk profile. That is not an excuse to do less, but a pointer to do it differently. A few choices from our own setup:

  • Policy under version control — our risk management policy, risk register and incident procedure live as text files in git. Adopted versions get a signed tag; anything outside such a tag does not count as adopted. That same repository holds our complete ISMS: we are not ISO 27001 certified, but our ISMS is set up along that standard, so certification is a step rather than a rebuild.
  • Technology where classic segregation of duties is not feasible — configuration in version control (our network equipment's configuration is automatically backed up to git with Oxidized, every change as a commit), automated validation before anything goes live, and logging and alerting on changes. A second pair of eyes does not have to be human to stop a mistake.
  • A fixed annual cycle — the risk register is updated yearly and after major changes, the effectiveness of measures is assessed yearly, and an incident-response exercise is on the calendar every year. A procedure that has never been rehearsed is a document — not a procedure.
  • Concrete, not abstract — MFA or passkeys on all management systems, critical patches within seven days, encrypted backups with an annual restore test. A backup you have never restored from does not count.

What this means for you

Even organisations outside the law's scope will feel it — through customers or suppliers. Supply-chain security is one of the ten measures, so NIS2-covered organisations will start asking their suppliers questions: where is my equipment and how is the power supply secured, how quickly do I hear about an incident, who is my point of contact, and what happens during a DDoS attack? Choose a supplier that has to answer those same questions to its own regulator, and you are effectively buying that homework with the service.

We answer them routinely — for colocation, IP transit and the infrastructure behind them. If you are working on NIS2 yourself and want to know how your infrastructure supplier fits into that story: get in touch and we will walk through the questions your auditor is going to ask.

Frequently asked questions

Frequently asked questions

Does my company fall under NIS2?

That depends on your sector and your size. Most sectors have a floor of 50 employees or 10 million euro in revenue, but in digital infrastructure — DNS service providers, registries, trust services — the service counts, not the size. The Dutch government offers an online self-assessment to check your own situation.

What do I have to report, and when?

Significant incidents are reported to the NCSC in phases: an early warning within 24 hours, a full incident notification within 72 hours and a final report within a month. For digital-infrastructure parties, what counts as "significant" is spelled out concretely in a European implementing regulation.

Is an ISO 27001 certificate the same as NIS2 compliance?

No. The overlap is large — risk analysis, incident process, supplier management — but NIS2 has obligations of its own, such as the registration duty and the phased reporting duty, and the law demands demonstrability towards the regulator. A certificate helps with that demonstrability, but does not replace the legal obligations. We are not certified ourselves, but our ISMS is set up along ISO 27001.

Answer not found?

Ask an engineer directly — we usually respond within one business day.