15 August 2026: the Dutch Cybersecurity Act (NIS 2 NL) has entered into force
As of 15 August 2026, the Dutch NIS 2 law (Cyberbeveiligingswet) applies. For groups in Luxembourg with activities or providers in the Netherlands, obligations now apply on both sides of the border.
On 15 August 2026, the Dutch Cybersecurity Act (Cyberbeveiligingswet, CBW) — the national transposition of NIS 2 — entered into force. Companies operating in Luxembourg with activities, establishments or providers in the Netherlands must now comply with NIS 2 requirements in both jurisdictions.
The facts
The CBW broadens the scope of “essential” and “important” entities, introducing obligations on risk management, incident reporting and governance of the digital supply chain. In Luxembourg, the NIS 2 transposition law of 5 May 2026 has applied since 10 May 2026 (competent authority: ILR; SERIMA portal). NIS 2 is therefore fully applicable both in Luxembourg and in the Netherlands.
Legal framework and basis
- Directive (EU) 2022/2555 (“NIS 2”), notably Articles 20, 21, 23, 26–29 and Annexes I/II.
- Netherlands: Cyberbeveiligingswet (CBW), in force as of 15 August 2026.
- Luxembourg: law of 5 May 2026 transposing NIS 2; ILR as competent authority; SERIMA portal.
For a concise overview of the directive and entity categories, see our page on NIS 2 and key obligations.
What this changes for Luxembourg businesses
- LU–NL groups. If you have a subsidiary, a covered activity (Annexes I/II) or ICT B2B providers based in the Netherlands, your obligations apply on both sides: technical and organisational measures, logging, backups, vulnerability management, third‑party governance, and the 24 h/72 h/1‑month notification sequence.
- Contracts and vendors. Dutch provider contracts (cloud, outsourcing, SaaS) must embed NIS 2 requirements (cooperation, internal escalation timelines, audit, reversibility, resilience). A targeted cybersecurity and contractual audit helps identify critical gaps.
- Governance and accountability. Boards must supervise and periodically validate the cybersecurity programme (Art. 20 NIS 2). Fractional CISO leadership supports structured compliance and incident alignment across jurisdictions.
- Incident operations. Align playbooks to cover SERIMA (LU) and CBW (NL) requirements to avoid late or incomplete filings. For Luxembourg specifics, refer to NIS 2 in Luxembourg and the ILR’s role.
Concrete actions for this week
- Map your NL footprint. List subsidiaries, branches, covered activities and Dutch providers; categorise “essential/important” and identify the competent authorities/portals in NL.
- Synchronise 24 h/72 h/1‑month playbooks. Update escalation, notification templates and run a cross‑border tabletop focused on evidence (logs, IOCs, impact) and the 24‑hour decision.
- Review Dutch supplier contracts. Insert NIS 2 clauses: security, cooperation with investigation and notification, internal escalation < 4 h, audits, reversibility, security SLAs, RTO/RPO, restoration tests, vulnerability management.
- Align board/DPO/CISO. Have the board validate a LU–NL status, remediation plan and quarterly internal checks through end‑2026; record decisions.
- Stress‑test the supply chain. Inventory critical B2B providers operating in the Netherlands; require measures and evidence (test reports, attestations, access logs); prioritise cloud/IaaS, outsourcing, MSP/SOC, identity services.
In summary
Dutch entry into force creates a cross‑border “double trigger” for LU–NL groups. Risk is now about 24/72‑hour clocks and the ability to evidence proportional and effective measures (tests, logs, risk assessments, up‑to‑date contracts). Our fractional CISO service can steer cross‑border NIS 2 implementation.
Article generated by Luxgap regulatory watch. For tailored guidance on this topic, contact us.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →