Wouter Parent of Kynexis Information security was a guest at NCOD Audit on 13 August 2026 to discuss the Dutch Cybersecurity Act, NIS2 and concrete follow-up steps for organisations. The main message: start with the organisation and its risks. From that point of view, appropriate technical, organisational and board-level measures will be followed.

Watch the broadcast

Dutch Cybersecurity Act and NIS2 in practice

Wouter Parent was guest speaker at NCOD Audit on 13 August 2026. The video will only be loaded from YouTube when you choose it.

View the recording directly on YouTube →

NIS2 starts with knowing what your organisation is critical of

The Dutch Cybersecurity Act enters into force on 15 August 2026. This will transpose the European NIS2 Directive into national law in the Netherlands. Organisations governed by the law are subject to a registration obligation, reporting obligation, duty of care and explicit board-level responsibility.

An organisation can introduce dozens or hundreds of security measures. The first question should lie with the business management: What processes remain available to allow the organisation to do its job? The RDI states that the duty of care begins with a risk analysis. On this basis, the organisation shall choose measures that reflect its situation.

  • determine whether the organisation is covered by the Dutch Cybersecurity Act and whether an essential or important entity is involved
  • identify critical business processes
  • perform a risk analysis for these processes
  • determine the systems, information and suppliers needed
  • assess how risks are currently controlled
Read the central explanation about NIS2 and the Dutch Cybersecurity ActStart with the NIS2 Quickscan
Start with the question of which processes remain available. Then, picture risks, systems, information, suppliers and current control in coherence.

The Dutch Cybersecurity Act also means governance

A demonstrable NIS2 approach consists of technical, operational and organisational control. The organisation has clear who is responsible for what risk, who may accept a residual risk, what information the board receives and how the functioning of measures is assessed.

Clear roles, responsibilities, contractual agreements and reportings make this control manageable. A RACI model can help to make it clear who is responsible, responsible, advisory or informed. The Board remains ultimately responsible, even when work is delegated to a CISO or IT partner.

View cybersecurity managementRead about demonstrable assurance

A firewall and IT contract are not board-level reporting

Digital dependencies directly affect service provision, turnover, security, privacy and continuity. Therefore, the answer that there is a firewall and a good contract with an IT service provider does not provide a very good insight into the actual control of cyber risks.

Board-level information supports decisions. This requires insight into risks, critical processes, suppliers, measures, residual risks, incidents, recovery capability and progress. This makes information security a regular part of board-level risk management.

  • the main digital risks and critical dependencies
  • current management measures and residual risk mitigation measures
  • incidents, near-incidents, continuity and recovery
  • necessary improvement measures, ownership and progress

Make cyber risks understandable to board members

A CISO, security manager or IT manager can know exactly where a technical vulnerability is. For board-level decision-making, you translate that information into the implications for the organisation.

What happens when a production line stops for three weeks, a critical supplier fails or necessary data is not available? Clear language and examples from the company's own business will help board members assess risk performance, prioritise and make resources available.

Mandatory NIS2 board member training: knowledge must be demonstrable

The Dutch Cybersecurity Act makes board-level knowledge demonstrably relevant. Executive board members subject to this obligation should have sufficient knowledge and skills to assess cyber risks and security measures. They shall be given appropriate training and must be able to show a certificate.

According to the current RDI explanation, existing board members must comply with these requirements within two years of the entry into force of the Dutch Cybersecurity Act. New board members will be given two years from their appointment. The RDI clarifies that supervisory directors, supervisory directors and non-executive directors are excluded from this specific obligation. For them, knowledge of digital risks from their supervisory role remains valuable in terms of content.

Read the FAQ on the NIS2 training requirement for board membersView the NIS2 board member trainingView general boardroom cyber sessions at Kynexis

Risk analysis, NIS2 GAP analysis and improvement plan

When the critical processes, risks and dependencies are known, the question arises as to where the organisation is now in relation to the desired situation. An NIS2 GAP analysis or baseline assessment makes that difference visible.

A good analysis results in more than a list of points of interest. The outcome is translated into a manageable improvement plan with priorities, owners, proof and realistic planning. The key questions are clear: Where are we now, where do we want to stand and how do we get there?

View the NIS2 GAP analysisView the NIS2 audit

In summary: make NIS2 controlable

The Dutch Cybersecurity Act is ultimately about controlling digital risks that may affect the organisation. Therefore, start with the critical processes, associated threats, systems, information, suppliers and responsibilities.

From there, a logical route to NIS2 advice and implementation is created: To determine scope, analyse risk performance indicators, organise governance, assess current control and improve it step by step. Kynexis Information Security approaches the Dutch Cybersecurity Act as part of professional digital risk management.

Sources and deepening

Based on official frameworks and practical implementation

The source pages provide the formal background. Kynexis Information Security translates this information into an executable approach for your organisation, sector and risk profile.

View Government - Dutch Cybersecurity Act in force from 15 August 2026View RDI - Duty of care Dutch Cybersecurity ActView RDI - Board-level responsibility and governanceView NCOD Audit - broadcast Dutch Cybersecurity Act and NIS2