
NIS2 and the Dutch Cybersecurity Act in the Netherlands
How do you translate NIS2 into demonstrable execution?
The Dutch Cybersecurity Act has been in force since 15 August 2026 as a Dutch effect of NIS2. Kynexis Information Security helps organisations translate applicability, registration, duty of care and reporting into board-level responsibility, appropriate measures, chain control and demonstrable follow-up.
- The legal obligations are known, but ownership and concrete implementation are still fragmented.
- the board and management seek guidance on duty of care, reporting and oversight.
- Existing measures require linking with risks, suppliers and demonstrable evidence.
- You want to prevent NIS2 becoming a loose compliance project alongside the daily organisation.
What are the risks? Without coherent implementation, obligations on paper will remain and only when a oversight or incident is observed will there be a clear lack of execution, evidence and responsibility.
Our promise of service
An executable NIS2 approach that suits your organisation
NIS2 advice and implementation links the Dutch Cybersecurity Act to existing governance, risks, processes, technology and suppliers.
- Clear translation of applicable obligations
- Property and measures in practice
- Evidence and reporting for governance and oversight
NIS2 advisory and implementation
What is NIS2 advice and implementation?
The Dutch Cybersecurity Act has been in force since 15 August 2026 as a Dutch effect of NIS2. Kynexis Information Security helps organisations translate applicability, registration, duty of care and reporting into board-level responsibility, appropriate measures, chain control and demonstrable follow-up.
When does this service fit?
The central starting point for NIS2 regulation and implementation
This page brings together the main lines of NIS2 legislation in the Netherlands and the implementation routes of Kynexis Information Security. It is suitable for organisations exploring their entity status, preparing for the Dutch Cybersecurity Act or having to take demonstrable measures from customers and chain partners.
Implementation areas
Translating care obligations into concrete and demonstrable implementation
The content follows from the actual risks, services, sector and chain position of your organisation.
Governance and governance
Organize responsibility, knowledge, decision-making, oversight and reporting.
Risk management measures
Appropriate technical, operational and organisational measures to implement risk-driven.
Incident Notification
Set up detection, assessment, escalation, reporting periods, communication and reporting.
Continuity and recovery
Connect critical processes, backup, crisis organisation, recovery priorities and exercises.
Suppliers and Chain
Control requirements, contracts, assurance, access rights, incident agreements and exit.
Demonstrability
To establish and periodically evaluate decisions, checks, actions and evidence in a structured manner.
Your result
A manageable NIS2 approach with visible progress
You will get an executable route in which measures, owners, evidence and board-level decisions are linked. For example, compliance supports the continuity and digital resilience of the organisation.
- Clear translation of relevant obligations
- Prioritized implementation roadmap
- Owners of measures and evidence
- Operating process for incident reporting
- Periodic board-level reporting and improvement
NIS2 service
From initial orientation to independent review
Each route answers a different question. This leaves scope, depth and outcome for governance and organisation clear.
NIS2 Quickscan
Answer practical questions and receive an indicative picture. The result supports the choice for further floor.
See this route →NIS2 GAP Analysis
Compare the current arrangement with relevant obligations and make risks, priorities and evidence needs visible.
See this route →Independent securing roleNIS2 audit
Let independent and traceable evidence assess how measures, processes, governance and chain control work.
See this route →How we work
This is how we make NIS2 work.
- 01
Context and Status
Set sector, size, service, entity status and chain position.
- 02
GAP and priorities
Compare current measures and evidence with relevant obligations.
- 03
Implement
Enhance measures, processes, supplier agreements and reporting in a targeted way.
- 04
Practice and guarantee
Test effectiveness, inform the board and follow up improvements on a recurring basis.
NIS2 route
Permanent readiness for NIS2
The implementation builds on a well-founded GAP and ends with demonstrable operation and periodic improvement.
Applicability and registration
Supporting sector, size, services, entity status and registration obligation.
NIS2 GAP Analysis
To make differences, risks and need for evidence visible.
View this phase →NIS2 implementation
Ensure that mandatory care measures, incident reporting and supplier agreements work.
Fit for this implementation phaseNIS2 audit
Assess the demonstrable effect independently with evidence.
View this phase →Governance and improvement
Report progress, practice and periodically monitor improvements.
View this phase →Discuss your entity status, current layout and next implementation steps for demonstrable NIS2 control.
Plan an NIS2 intake →Frequently Asked Questions
Practical answers on NIS2 advisory and implementation
When did the Dutch Cybersecurity Act enter into force?
The Dutch Cybersecurity Act entered into force on 15 August 2026. Organisations must determine whether they are covered by the law and what registration, care and reporting obligations apply to them.
What is the difference between NIS2 and the Dutch Cybersecurity Act?
NIS2 is the European directive. The Dutch Cybersecurity Act transposes this directive into Dutch law and implements the obligations, oversight and enforcement for the Netherlands.
What does an NIS2 advisor do?
An NIS2 advisor helps translate applicability, obligations and risks into board-level choices, measures, incident reporting, chain agreements and evidence. Legal review is involved when the question so requires.
What is the difference between an NIS2 GAP analysis and implementation?
The GAP analysis provides an independent diagnosis of the current readiness. Implementation focuses on effectively improving, organising, implementing and demonstrating the necessary measures.
Is NIS2 also relevant to suppliers?
Yes. Entities must control risks in their chain and can therefore impose security and evidence requirements on suppliers. A supplier is not automatically directly covered by the Dutch Cybersecurity Act solely by that customer relationship; the individual sector, size and service remain key.
Can ISO 27001 be used for NIS2?
Yes. A working ISO 27001-ISMS provides a strong basis for risk management, policy, control and improvement. NIS2 specific topics such as entity status, reporting obligation and board-level obligations require targeted supplement.

Translate NIS2 early into owners, decisions and evidence. When the execution is only collected just before a test, structural control is usually not yet secured.