The Dutch Cybersecurity Act has passed: your action list to 15 August
The waiting is over. The Dutch Senate adopted the Cybersecurity Act on 7 July 2026 and it takes effect on 15 August 2026, with no transition period. That leaves you roughly five weeks. This page is not theory about what the law is (you'll find that in the broader explainer), but a concrete list of what you do now — in order.
The Dutch Senate (Eerste Kamer) adopted the Cybersecurity Act (bill 36.764) on 7 July 2026, together with the Critical Entities Resilience Act. Only FVD voted against. The law takes effect on 15 August 2026, replaces the old Network and Information Systems Security Act (Wbni), and takes the group of obligated organisations from roughly 1,000 to over 8,000 (source: Rijksoverheid, 7 July 2026).
Why this is urgent now
There is no transition period. The obligations apply from the day the law takes effect, so from 15 August 2026. That is the point that catches organisations off guard most often: there is no one-year grace period to get everything in order. Anyone who only starts on 15 August is behind from day one.
At the same time, five weeks is enough to take the most important steps, provided you start now and do the right things first. Below is the order that works in practice, from "do I even take part" to "can I prove my measures work".
The action list
1. Confirm whether you are in scope
Test your sector and size against the criteria: if you operate in a designated sector and you are medium-sized or large (rule of thumb: 50 or more staff, or more than €10 million turnover), you are in principle in scope. Some organisations are in scope regardless of size. When in doubt, the safe assumption is to prepare. The broader explainer lists the sectors and the two categories (essential and important).
2. Register with the NCSC
If you are in scope, registration via mijn.ncsc.nl is mandatory from 15 August 2026. That registration puts you on the regulator's radar and gives you access to your CSIRT's support during incidents. Prepare it now: gather the details you need and assign an owner, so registration is done on day one.
3. Refresh your risk assessment
The duty of care starts with a current risk assessment: which systems are critical, which threats are relevant (ransomware, supply chain, targeted phishing on the board), and which measures belong to them? A policy document from last year is not enough. Update it to today's situation and record the choices.
4. Set up the reporting chain and rehearse it once
A significant incident must be reported quickly. The deadlines are tight:
| Deadline | What |
|---|---|
| Within 24 hours | Early warning to the CSIRT/NCSC |
| Within 72 hours | Fuller incident notification with an initial assessment |
| Within 1 month | Final report with cause, impact and measures taken |
Paper is not enough here. Decide who gets called, who files the report, and who communicates to the board and the press, then rehearse that chain once with a short tabletop exercise. That exercise is also usable evidence towards the regulator.
5. Involve the board formally
Under the Cybersecurity Act, the management body must approve the measures, oversee them and undergo training. Board-level involvement is no longer a formality but a legal requirement, with personal liability as the backstop. Record decision-making and training on cyber risk in a logbook.
6. Gather evidence that the technology works
The duty of care asks not only for measures, but also for assessing their effectiveness. For the technical side, an independent penetration test is the strongest piece of evidence: it shows which vulnerabilities actually existed, which were genuinely exploitable, and — after the retest — which were actually resolved. Plan a test on your most critical application(s) and keep the report and the retest statement. Unsure about the cadence? Read how often you should run a penetration test.
Want demonstrable evidence that your technical measures work before 15 August? A manual penetration test delivers a report and retest statement you can use straight away towards the regulator and your auditor.
Schedule a free intake →7. Look at your supply chain
The law makes you co-responsible for the security of your suppliers. Inventory your critical suppliers (SaaS, hosting, application management), ask for their pentest reports or certifications, and lock security arrangements into your contracts. Start with the suppliers involved in your most critical processes.
Working in healthcare or government?
Then the Cybersecurity Act runs alongside existing frameworks. For municipalities it aligns with ENSIA and the BIO — we wrote about that in NIS2 and municipalities: what does the regulator expect?. For healthcare it aligns with NEN 7510. In every case the underlying requirement is the same: prove that the measures work.
The law is real now; the date is fixed and there is no transition period. Those who get registration, the reporting chain and the evidence in order over the coming weeks are ready in time — those who wait for the regulator to call choose the most expensive route.
Conclusion
Passing the Cybersecurity Act is not a milestone to wait out, but the starting gun. Five weeks is short, but plenty to lay the groundwork: knowing whether you take part, registering, refreshing your risks, rehearsing the reporting chain, involving the board, and proving the technology holds up. Start with the step that takes longest to arrange — usually that is the technical evidence.
Not sure where to start? A free 30-minute intake gives clarity on your situation and the fastest first steps, with no obligation.
NIS2 evidence that holds up.
A manual penetration test on your critical applications, with a report and retest statement you can use directly towards the regulator. Fixed price, retest included.
Schedule a free intake →