In short: the Dutch Cyber Security Act (Cyberbeveiligingswet, Cbw), the national implementation of NIS2, applies since August 15, 2026 to more than 8,000 organizations in 18 sectors. Most SMEs are not covered directly, but meet the law through their customers: anyone supplying a Cbw organization must be able to demonstrate 10 security measures. For your website, software and hosting that comes down to updates, MFA, logging, backups, an incident process and documentation.
What the Cyber Security Act regulates since August 15, 2026 and who is covered
NIS2 is the European directive (2022/2555) that brings the cyber security of essential and important organizations across the EU to a single level. The Netherlands was late with the transposition: the Cyber Security Act was passed by the Senate in 2026 and entered into force on August 15, 2026, together with the Critical Entities Resilience Act for physical resilience.
The law applies to medium-sized and large organizations (from 50 employees or €10 million in turnover) in 18 sectors: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space, postal and courier services, waste management, chemicals, food, manufacturing (including medical devices, electronics, machinery and vehicles), digital providers and research. Some organizations are covered regardless of size, such as DNS services, trust service providers and telecom operators.
Those covered have 4 duties:
- Duty of care. Take appropriate measures based on a risk analysis, along the 10 measures listed further down.
- Duty to report. Give early warning of significant incidents to the NCSC within 24 hours, notify within 72 hours and close with a final report within 1 month.
- Duty to register. Register with the supervisory authority, such as the RDI, DNB, the IGJ or the ILT, depending on the sector.
- Board accountability. The board approves the measures, oversees them, follows training and is personally accountable in case of negligence.
The fines are substantial: up to €10 million or 2% of global turnover for essential entities, up to €7 million or 1.4% for important entities. Whether your own organization is covered can be checked with the Dutch government's NIS2 self-assessment.
Why SMEs are pulled in through the supply chain
One of the 10 measures is supply chain security. A Cbw organization must assess the risks of its direct suppliers: who has access to its systems or data, who supplies software, who hosts the website. That means a hospital, a transport company or a bank sends questionnaires in 2026 to every party in its chain. Including the 12-person developer that built the customer portal, the marketing agency that manages the website and the 30-person manufacturer that supplies parts.
That is the reality for SMEs: not the law itself, but the contract. Whoever cannot fill in the questionnaire convincingly loses the deal to a competitor who can. Whoever can has a sales argument. In logistics and in finance we see procurement teams now asking for MFA, backups, an incident process and a penetration test report by default, before a quote is even read.
For software suppliers the Cyber Resilience Act (CRA) adds to this: for products with digital elements placed on the European market, a reporting obligation for actively exploited vulnerabilities applies from September 11, 2026 and the full set of requirements from December 11, 2027. Bespoke software for 1 client usually falls outside it, apps and SaaS products you sell as a product do not.
The 10 measures suppliers must demonstrate
The Cbw prescribes no technical standard, but names 10 areas where measures must be appropriate. This is what a customer asks you in practice and the evidence you want to have ready.
| Measure | What a customer asks | Evidence you show |
|---|---|---|
| 1. Risk analysis and security policy | Do you have a policy and do you know where your risks are? | Policy document of 5 to 10 pages, risk register, annual review |
| 2. Incident handling | What do you do when hacked and when do I hear about it? | Incident procedure, contact list, 24-hour notification window for customers |
| 3. Business continuity and backups | How fast are you back after a ransomware attack? | Backup schedule, dated restore test, RTO and RPO per system |
| 4. Supply chain security | Who are your suppliers and how do you assess them? | Supplier list covering hosting, SaaS and processors, data processing agreements |
| 5. Secure development and maintenance | How do you prevent vulnerabilities in what you build? | Update policy, dependency scanning, code review, pentest report, security.txt |
| 6. Measuring effectiveness | Do you check whether your measures work? | Annual internal audit or external scan, action list |
| 7. Cyber hygiene and training | Are your people trained? | Training log, phishing test, mandatory password manager |
| 8. Cryptography | Is data encrypted in transit and at rest? | TLS 1.2 or higher, HSTS, encrypted storage and backups, key management |
| 9. Access management and assets | Who can access what, and is it current? | Role matrix, offboarding checklist, inventory of systems and domains |
| 10. MFA and secured communication | Is multi-factor authentication mandatory everywhere? | MFA or passkeys on CMS, hosting, DNS, email and code, SSO where possible |
An ISO 27001 or NEN 7510 certificate shortens this conversation, but is unnecessary for most SMEs. A tidy file along these 10 points satisfies almost every questionnaire.
Translating it to your website, online store and software
What do those 10 measures mean concretely for the digital side of your business? This is the list we work through with every client.
Updates and patching. CMS, plugins, frameworks, dependencies, operating system and runtime updated within 30 days, critical vulnerabilities within 7 days. Automated where possible (Dependabot, Renovate), with a log of what was updated when. A WordPress site with 40 plugins that have not been updated in 2 years is the first thing an auditor finds.
MFA on everything that grants access. The CMS, the hosting panel, DNS, the domain registrar, email, the code repository, the PSP and the analytics account. Preferably passkeys or an authenticator app, not SMS. Abolish shared accounts, give every employee their own login with the rights the role requires.
Logging and monitoring. Access logs, error logs and security events stored centrally for at least 90 days. Uptime monitoring with alerts, a WAF or DDoS protection and a notification on login attempts outside the normal pattern. Without logs you cannot reconstruct an incident, and therefore cannot report it.
Backups following 3-2-1. Daily, encrypted, in a different location than production, with a restore test every quarter and a note of how long the restore took. A backup that has never been restored is an assumption.
Incident process. One page: who detects, who decides, who communicates, who reports. Contact details for hosting, developer, insurer and the customers who want to be informed within 24 hours. A template for the notification. A dry run once a year.
Hosting. A provider in the EU with ISO 27001 certification, a data processing agreement, separated test and production environments, secrets kept out of the code and the principle of least privilege. Where your data lives and who can reach it should fit in 1 sentence.
Secure development. Code review before every release, automated dependency scans, the OWASP Top 10 as a checklist, an annual penetration test by a certified party and a security.txt on your domain so researchers can report vulnerabilities.
Good website maintenance already covers the first 4 points, and what that should cost is in website maintenance cost. What the Cbw mainly adds is the evidence: not just doing it, but showing that you do.
What it costs and how to document it
For an SME with a website, an online store or 1 custom application and a normal hosting setup, the basics take 3 to 8 working days: a quick scan along the 10 measures, technical hardening (MFA, logging, backups, updates, headers), a set of 5 to 10 policy documents and filling in the first questionnaire. With a specialist that comes to €3,000 to €8,000 excl. VAT, plus €100 to €400 per month for monitoring, updates and backups. An annual penetration test costs €2,500 to €7,500, depending on scope. ISO 27001 certification, only needed when large customers ask for it, starts at €10,000 to €25,000 in the first year.
The file you maintain consists of 6 pieces: policy and risk register, inventory of systems and suppliers, update log, backup and restore test log, incident procedure with drill report, and the most recent pentest or scan report. Date it, review it annually, and you can fill in any questionnaire within an hour.
RABZI estimate: the NIS2 quick scan from security and compliance costs €1,250 excl. VAT and delivers a report along the 10 measures with a priority list. Hardening, policy documents and MFA or SSO start at €4,950, a penetration test through a certified partner with remediation and CRA preparation from €12,500. The ongoing side, EU hosting with monitoring, backups and updates, runs through cloud, hosting and DevOps from €95 per month per environment.
How RABZI builds this into maintenance and DevOps
We do not treat the Cbw as a separate project but as part of how we build and operate. Every website, online store and application we deliver has MFA on all accounts, automated updates with a log, central logging, daily encrypted backups with a quarterly restore test, a security.txt and a data processing agreement with the hosting provider. With every delivery you get a 1-page security statement you can attach directly to your customer's questionnaire.
Clients on our maintenance or managed hosting plans get an annual reassessment on top, and in case of an incident, a partner standing next to you within the reporting window. Other compliance topics that often land on the table together with NIS2, such as the cookie rules, we handle in the same round.
Frequently asked questions
Is my SME covered by the Dutch Cyber Security Act? Only if you operate in 1 of the 18 sectors and have at least 50 employees or €10 million in turnover, or provide a designated service such as DNS or trust services. Most SMEs are not covered directly but receive the requirements through customers that are. Use the Dutch government's NIS2 self-assessment to be sure.
What do I do when a customer sends a NIS2 questionnaire? Fill it in honestly based on your file: policy, inventory, update log, backup test, incident procedure and scan report. If something is missing, state what you will arrange and by when. Customers are not looking for perfection but for control and a plan. A supplier who says 'no, but next month yes' keeps the contract.
Is an ISO 27001 certificate mandatory for suppliers? No. The Cyber Security Act requires appropriate measures, not a certificate. Large customers sometimes ask for one as evidence, but a file along the 10 measures with a recent penetration test satisfies almost every questionnaire. Certification only becomes worthwhile when several large customers make it a condition.
What does it cost for an SME to become NIS2-ready? Budget €3,000 to €8,000 once for the quick scan, technical hardening and policy documents, plus €100 to €400 per month for monitoring, updates and backups. An annual penetration test costs €2,500 to €7,500. At RABZI the NIS2 quick scan starts at €1,250 and hardening with policies at €4,950.
Conclusion
NIS2 and the Dutch Cyber Security Act reach SMEs not through the regulator but through the customer. Those who have the 10 measures in order and can prove it keep their contracts and win new ones. Those who cannot are quietly removed from the supplier list in 2026. The basics are not rocket science: updates, MFA, logging, backups, an incident process and a file you update every year. Want to know where you stand? Book an intro call, we run the quick scan and you have a report and a priority list within 2 weeks.