NISDESK Β· NL
NIS2 Compliance in Netherlands
In short: NIS2 applies in Netherlands to medium and large organisations (50+ employees or over β¬10M turnover) in the 18 sectors of Annexes I and II. The competent authority is NCSC-NL (Nationaal Cyber Security Centrum). Significant incidents go to NCSC-NL: early warning within 24 hours, notification within 72 hours, final report within one month.
Dutch essential and important entities work with sector authorities and NCSC-NL to fulfil NIS2 scope, security and incident-reporting obligations.
Are you in scope?
NIS2 covers medium and large organisations in 18 sectors. Fines reach β¬10M or 2% of global turnover. Check your scope, obligations and a readiness score for free.
Get the free NIS2 checklist for Netherlands
We email a link to the free printable checklist. No spam β unsubscribe anytime.
National authority & CSIRT
In Netherlands, NIS2 supervision is handled by NCSC-NL (Nationaal Cyber Security Centrum). The national CSIRT is NCSC-NL. Significant incidents must be reported within 24 h (early warning), 72 h (notification) and one month (final report) per NIS2 Article 23.
NIS2 sectors in Netherlands
Each sector has specific obligations. Explore them for Netherlands:
Frequently asked questions
Which sectors are covered by NIS2 in Netherlands?
NIS2 covers 18 sectors: Annex I (highly critical β energy, transport, banking, financial markets, health, water, digital infrastructure, ICT service management, public administration, space) and Annex II (other critical β postal services, waste management, chemicals, food, manufacturing, digital providers, research). Transposed via Cybersecurity Wet (Wbni amendment, 2024); NCSC-NL is the national CSIRT and sector-specific bodies act as competent authorities.
Who supervises NIS2 compliance in Netherlands?
In Netherlands, the primary competent authority is NCSC-NL (Nationaal Cyber Security Centrum). The national CSIRT is NCSC-NL, which handles significant incident notifications and cybersecurity coordination.
What are the NIS2 incident reporting deadlines in Netherlands?
Organisations must submit an early warning to NCSC-NL within 24 hours of a significant incident, a formal notification within 72 hours, and a final report within one month β per NIS2 Article 23.
What are the NIS2 fines in Netherlands?
Essential entities face fines up to β¬10 million or 2% of global annual turnover. Important entities face up to β¬7 million or 1.4% of global annual turnover. Exact enforcement varies by national transposition.
Official sources
- NIS2 Directive (EU) 2022/2555 β EUR-Lex
- DORA Regulation (EU) 2022/2554 β EUR-Lex
- ENISA β EU Agency for Cybersecurity
Last reviewed: 2026-07-03
For decision-support purposes only. Exact scope depends on national transposition β use our free scope checker for a personalised assessment.