NIS2
Data Management
ISO certification
7 August 2026

NIS2 and Dutch SMEs

What Does the Cybersecurity Act Mean for Your Organization?

Digital resilience is more than just an IT task

Cybersecurity has long since ceased to be a matter solely for the IT department. With the enactment of the Cybersecurity Act, digital resilience has explicitly become the responsibility of board members and executive management.

The law will take effect on August 15, 2026, and is the Dutch implementation of the European NIS2 Directive. From that point on, many organizations in the Netherlands will be subject, directly or indirectly, to new cybersecurity requirements.

Not every small and medium-sized enterprise (SME) is directly subject to the Cybersecurity Act. Nevertheless, the impact could be much broader. Organizations that are subject to the law must also pay attention to risks within their supply chain. As a result, they will increasingly want to know how suppliers have organized their information security, risks, and measures.

The question, then, is not just whether your organization operates securely, but above all whether you can demonstrate that it does.

What does the Cybersecurity Act require of organizations?

NIS2 stands for Network and Information Security Directive 2. This European directive is intended to strengthen digital resilience within the European Union. In the Netherlands, the obligations under the directive are set forth in the Cybersecurity Act.

Organizations subject to the law are required, among other things, to fulfill a duty of care, a registration requirement, and a reporting requirement. They must take appropriate technical, operational, and organizational measures to manage cyber risks and mitigate the consequences of incidents.

These include, among other things:

  • Assessing and managing cyber risks;
  • Preventing, identifying, and resolving incidents;
  • Ensuring business continuity;
  • Managing supplier risks;
  • Controlling access to information and systems;
  • Training and raising awareness among employees.

Board members are also given clear responsibilities. They must approve measures, oversee their implementation, and possess sufficient knowledge to assess cyber risks and the chosen approach. This makes digital resilience a structural part of business operations.

Whether your organization is directly subject to the Cybersecurity Act depends, among other things, on its sector, size, and activities. The Act focuses on organizations that provide essential or important services within eighteen designated sectors. Organizations are responsible for determining whether they fall under the Act. If your organization is not directly subject to the Act, customers and supply chain partners may still impose additional requirements. After all, they need to be able to assess the risks posed by their suppliers and how those risks are managed.

Suppliers must also be able to demonstrate that their affairs are in order

For many small and medium-sized businesses, the impact of NIS2 will be most noticeable in customer inquiries, supplier assessments, contract terms, and audits.

For example, customers might ask:

  • Is there a current information security policy?
  • How are risks assessed and monitored?
  • How are incidents recorded and handled?
  • Who is responsible for implementing measures and improvement actions?
  • Are his procedures up to date and approved?
  • Can it be demonstrated that the agreed-upon actions were carried out?

It is precisely that last point that often proves difficult in practice. While policies are usually in place, the relevant information is scattered across documents, emails, Excel files, and various systems. Disparate pieces of information do not provide a complete picture. To achieve that, there must be coherence between policies, processes, records, and follow-up.

ISO 27001 as the Foundation for Structured Information Security

ISO 27001 helps organizations structure their information security efforts. An Information Security Management System (ISMS) defines, among other things, risks, responsibilities, policies, incidents, suppliers, audits, and corrective actions.

Many of these topics align with the organizational measures set forth in the Cybersecurity Act. If your organization already operates in accordance with ISO 27001, it often has a valuable foundation in place. However, ISO 27001 and the Cybersecurity Act are not the same. Certification does not automatically mean that all legal obligations are met. The standard does, however, provide a useful framework for demonstrably and continuously improving information security.

New developments also require attention. For example, employees are increasingly using AI to draft documents, perform analyses, and carry out other tasks. Clear guidelines regarding permitted uses, confidential information, oversight, and accountability help keep these risks manageable as well.

From Scattered Information to Demonstrable Mastery

Many organizations have formally documented their policies and procedures. The challenge begins when this information needs to be applied in day-to-day practice.

Which version of a procedure is current? Who is responsible for assessing a risk? Has a corrective action actually been implemented? Which incidents are still open? And how do you quickly gather the right information during an audit?

When documents, records, and actions are scattered across different systems, answering such questions takes an unnecessary amount of time. Furthermore, there is a risk that tasks will be left undone, employees will work with outdated information, or responsibilities will be unclear.

Effective information management changes that. It provides insight into:

  • What information is current and available;
  • Who is responsible for a document, process, or action;
  • What changes have been made;
  • What risks and measures are associated with a process;
  • Which actions are still pending;
  • What has been verifiably assessed and implemented.

In this way, information management evolves from an administrative task into a practical tool for risk management, compliance, and continuous improvement.

From Policy to Demonstrable Implementation

Policies and procedures are only valuable if they are actually put into practice. With LeanForms and LeanBMS, you can centrally record risk analyses, incident reports, supplier evaluations, audits, and corrective actions.

Intelligent workflows ensure that notifications and actions are automatically routed to the right person. Reminders help ensure timely follow-up, and up-to-date statuses and reports let you see immediately where action is needed.

These records can be linked to the corresponding processes, documents, and responsibilities. This creates a single, cohesive environment in which the following is clear:

  • What measures have been agreed upon;
  • Who is responsible for what;
  • Which actions are still pending;
  • What was actually carried out;
  • Where risks or opportunities for improvement lie.

Instead of having to gather information after the fact, you’ll always have access to an up-to-date and reliable overview. This makes information security easier to manage and demonstrates compliance to customers, auditors, and supply chain partners.

Make digital resilience part of your business operations

The Cybersecurity Act is not a one-time compliance project. New risks, incidents, suppliers, and technological developments require constant attention.

For Dutch small and medium-sized enterprises, therefore, it is not just a matter of whether an organization falls directly under the law. It is also a matter of trust. Can you demonstrate to customers and partners that risks are being managed, responsibilities are clear, and measures are being demonstrably followed?

By integrating information management, risk management, and information security, you gain greater control over the entire organization. Not only will you be better prepared to meet legal and contractual requirements, but you’ll also be working toward more efficient audits, fewer operational risks, and a stronger position within the supply chain.

FMEA: Digital innovation for stronger risk management

Integrating risk management into standards such as ISO or Wkb requires up-to-date and structured information. Digital solutions help capture, track and structurally improve risks centrally.

The Failure Mode and Effects Analysis(FMEA), developed by NASA and later widely applied in the automotive industry, is a structured method to:

  • Identify possible failure modes, causes and consequences
  • Analyze and prioritize risks
  • Plan targeted improvement actions

Managing an FMEA digitally in an information management system makes risk management a continuous process. This allows you to:

  • Induct new employees with current risk information.
  • Prepare internal and external audits efficiently.
  • Analyze incidents and complaints in a structured manner.
  • Continuously optimize maintenance plans and inspection lists based on the latest insights and data.

Frequently Asked Questions

Share
Inspiratiemiddag MKG LeanForms
Quality Management
Process optimization

MKG & LeanForms Inspiration Afternoon

When shop floor data, process knowledge, and systems come together, clarity emerges. This interconnection was the focus of the MKG and LeanForms inspiration afternoon on July 1, 2026. At the Brainport Industries Campus (BIC) in Eindhoven, the discussion centered on how to make information from the field immediately usable within your processes.

Quality Management

What is quality management system?

Quality management is a catch-all term for many business owners. It is seen by managers as a necessary evil to hang the certificate on the wall. A proof of good behavior for the customers. However, if the principles of quality management are properly applied, they contribute daily to more efficient operations. And therefore to the bottom line. This is precisely why every organization can benefit from practical quality management. And surely that makes everyone happy.

Quality Management

Prospective risk analysis, smart execution one less worry!

With a prospective risk analysis, you analyze risks. The power of a good PRI is in its integration with daily activities.

Quality Management
Process optimization

RI&E: From obligation to dynamic tool

Preparing a risk inventory and evaluation (RI&E) has been a legal requirement for some time, but despite this, many companies struggle to set up their RI&E correctly.