NIS2 and Dutch SMEs
What Does the Cybersecurity Act Mean for Your Organization?
Digital resilience is more than just an IT task
Cybersecurity has long since ceased to be a matter solely for the IT department. With the enactment of the Cybersecurity Act, digital resilience has explicitly become the responsibility of board members and executive management.
The law will take effect on August 15, 2026, and is the Dutch implementation of the European NIS2 Directive. From that point on, many organizations in the Netherlands will be subject, directly or indirectly, to new cybersecurity requirements.
Not every small and medium-sized enterprise (SME) is directly subject to the Cybersecurity Act. Nevertheless, the impact could be much broader. Organizations that are subject to the law must also pay attention to risks within their supply chain. As a result, they will increasingly want to know how suppliers have organized their information security, risks, and measures.
The question, then, is not just whether your organization operates securely, but above all whether you can demonstrate that it does.
What does the Cybersecurity Act require of organizations?
NIS2 stands for Network and Information Security Directive 2. This European directive is intended to strengthen digital resilience within the European Union. In the Netherlands, the obligations under the directive are set forth in the Cybersecurity Act.
Organizations subject to the law are required, among other things, to fulfill a duty of care, a registration requirement, and a reporting requirement. They must take appropriate technical, operational, and organizational measures to manage cyber risks and mitigate the consequences of incidents.
These include, among other things:
- Assessing and managing cyber risks;
- Preventing, identifying, and resolving incidents;
- Ensuring business continuity;
- Managing supplier risks;
- Controlling access to information and systems;
- Training and raising awareness among employees.
Board members are also given clear responsibilities. They must approve measures, oversee their implementation, and possess sufficient knowledge to assess cyber risks and the chosen approach. This makes digital resilience a structural part of business operations.
Whether your organization is directly subject to the Cybersecurity Act depends, among other things, on its sector, size, and activities. The Act focuses on organizations that provide essential or important services within eighteen designated sectors. Organizations are responsible for determining whether they fall under the Act. If your organization is not directly subject to the Act, customers and supply chain partners may still impose additional requirements. After all, they need to be able to assess the risks posed by their suppliers and how those risks are managed.
Suppliers must also be able to demonstrate that their affairs are in order
For many small and medium-sized businesses, the impact of NIS2 will be most noticeable in customer inquiries, supplier assessments, contract terms, and audits.
For example, customers might ask:
- Is there a current information security policy?
- How are risks assessed and monitored?
- How are incidents recorded and handled?
- Who is responsible for implementing measures and improvement actions?
- Are his procedures up to date and approved?
- Can it be demonstrated that the agreed-upon actions were carried out?
It is precisely that last point that often proves difficult in practice. While policies are usually in place, the relevant information is scattered across documents, emails, Excel files, and various systems. Disparate pieces of information do not provide a complete picture. To achieve that, there must be coherence between policies, processes, records, and follow-up.
ISO 27001 as the Foundation for Structured Information Security
ISO 27001 helps organizations structure their information security efforts. An Information Security Management System (ISMS) defines, among other things, risks, responsibilities, policies, incidents, suppliers, audits, and corrective actions.
Many of these topics align with the organizational measures set forth in the Cybersecurity Act. If your organization already operates in accordance with ISO 27001, it often has a valuable foundation in place. However, ISO 27001 and the Cybersecurity Act are not the same. Certification does not automatically mean that all legal obligations are met. The standard does, however, provide a useful framework for demonstrably and continuously improving information security.
New developments also require attention. For example, employees are increasingly using AI to draft documents, perform analyses, and carry out other tasks. Clear guidelines regarding permitted uses, confidential information, oversight, and accountability help keep these risks manageable as well.
From Scattered Information to Demonstrable Mastery
Many organizations have formally documented their policies and procedures. The challenge begins when this information needs to be applied in day-to-day practice.
Which version of a procedure is current? Who is responsible for assessing a risk? Has a corrective action actually been implemented? Which incidents are still open? And how do you quickly gather the right information during an audit?
When documents, records, and actions are scattered across different systems, answering such questions takes an unnecessary amount of time. Furthermore, there is a risk that tasks will be left undone, employees will work with outdated information, or responsibilities will be unclear.
Effective information management changes that. It provides insight into:
- What information is current and available;
- Who is responsible for a document, process, or action;
- What changes have been made;
- What risks and measures are associated with a process;
- Which actions are still pending;
- What has been verifiably assessed and implemented.
In this way, information management evolves from an administrative task into a practical tool for risk management, compliance, and continuous improvement.
From Policy to Demonstrable Implementation
Policies and procedures are only valuable if they are actually put into practice. With LeanForms and LeanBMS, you can centrally record risk analyses, incident reports, supplier evaluations, audits, and corrective actions.
Intelligent workflows ensure that notifications and actions are automatically routed to the right person. Reminders help ensure timely follow-up, and up-to-date statuses and reports let you see immediately where action is needed.
These records can be linked to the corresponding processes, documents, and responsibilities. This creates a single, cohesive environment in which the following is clear:
- What measures have been agreed upon;
- Who is responsible for what;
- Which actions are still pending;
- What was actually carried out;
- Where risks or opportunities for improvement lie.
Instead of having to gather information after the fact, you’ll always have access to an up-to-date and reliable overview. This makes information security easier to manage and demonstrates compliance to customers, auditors, and supply chain partners.
Make digital resilience part of your business operations
The Cybersecurity Act is not a one-time compliance project. New risks, incidents, suppliers, and technological developments require constant attention.
For Dutch small and medium-sized enterprises, therefore, it is not just a matter of whether an organization falls directly under the law. It is also a matter of trust. Can you demonstrate to customers and partners that risks are being managed, responsibilities are clear, and measures are being demonstrably followed?
By integrating information management, risk management, and information security, you gain greater control over the entire organization. Not only will you be better prepared to meet legal and contractual requirements, but you’ll also be working toward more efficient audits, fewer operational risks, and a stronger position within the supply chain.
FMEA: Digital innovation for stronger risk management
Integrating risk management into standards such as ISO or Wkb requires up-to-date and structured information. Digital solutions help capture, track and structurally improve risks centrally.
The Failure Mode and Effects Analysis(FMEA), developed by NASA and later widely applied in the automotive industry, is a structured method to:
- Identify possible failure modes, causes and consequences
- Analyze and prioritize risks
- Plan targeted improvement actions
Managing an FMEA digitally in an information management system makes risk management a continuous process. This allows you to:
- Induct new employees with current risk information.
- Prepare internal and external audits efficiently.
- Analyze incidents and complaints in a structured manner.
- Continuously optimize maintenance plans and inspection lists based on the latest insights and data.
Whether your organization is subject to the Cybersecurity Act depends, among other things, on its sector, size, and activities. The Act applies to organizations within eighteen designated sectors. Organizations must assess for themselves whether they are subject to the Act. Even if they are not, you may still be subject to additional information security requirements through customers or supply chain partners.
Organizations subject to the Cybersecurity Act must also address risks within their supply chain. As a supplier, you may therefore receive requests or requirements regarding, for example, information security, risk management, incidents, and the follow-up on measures. It is therefore becoming increasingly important not only to implement measures but also to be able to demonstrate how they are organized and carried out.
No. ISO 27001 certification does not automatically mean that your organization complies with all the requirements of the Cybersecurity Act. However, the standard does provide a solid foundation for areas such as risk management, incident management, supplier management, and continuous improvement. The additional measures required depend on the obligations that apply to your organization.
Simply documenting policies and procedures is not enough. It is also important to clearly show who is responsible for measures, what actions have been taken, what remains outstanding, and what changes or audits have been conducted. By structurally linking processes, documents, records, and actions, it becomes easier to demonstrate implementation to management, customers, and auditors.
Frequently Asked Questions
MKG & LeanForms Inspiration Afternoon
When shop floor data, process knowledge, and systems come together, clarity emerges. This interconnection was the focus of the MKG and LeanForms inspiration afternoon on July 1, 2026. At the Brainport Industries Campus (BIC) in Eindhoven, the discussion centered on how to make information from the field immediately usable within your processes.
What is quality management system?
Quality management is a catch-all term for many business owners. It is seen by managers as a necessary evil to hang the certificate on the wall. A proof of good behavior for the customers. However, if the principles of quality management are properly applied, they contribute daily to more efficient operations. And therefore to the bottom line. This is precisely why every organization can benefit from practical quality management. And surely that makes everyone happy.
Prospective risk analysis, smart execution one less worry!
With a prospective risk analysis, you analyze risks. The power of a good PRI is in its integration with daily activities.
RI&E: From obligation to dynamic tool
Preparing a risk inventory and evaluation (RI&E) has been a legal requirement for some time, but despite this, many companies struggle to set up their RI&E correctly.
