The Dutch cyber security act: what can your client demand?
You're probably not in scope, but the questionnaire arrives anyway. What the law actually says about suppliers, what the government thought this would cost you (nothing), and what the market now charges for it.
Since 15 August 2026 the Netherlands has had its Cyber Security Act, the Dutch implementation of the European NIS2 rules. If your company has fewer than fifty people you're probably not in scope yourself — and yet a questionnaire from a client with 'NIS2' in the subject line may soon land in your inbox. A lot is being sold around that questionnaire right now: certificates, training, subscriptions. This article explains what the law itself says about suppliers, what your client can and cannot impose on you, what the government thought this would cost you, and what the market now charges for it. With the articles of law included, so you can check.
Are you in scope yourself?
Probably not. The law targets just over 8,000 organisations in designated sectors, and the threshold is 50 employees or 10 million euros in turnover or balance sheet total. There was no transition or grace period: the duty simply started on 15 August 2026.
Two things are often told wrong here. First, 15 August is a start date and not a deadline — from that day the duty applies; it isn't that something had to be finished by then. Second, the registration duty applies only to organisations in scope themselves; they register via mijn.ncsc.nl using Dutch eHerkenning at level EH2+, and must report changes within fourteen days. If you're not in scope, there is nothing for you to register.
Unsure whether you're in scope? That depends on your sector and your size, and it's one of the few questions in this file with a clear answer. Check with your trade association before you buy anything.
So why does the questionnaire reach you anyway?
Because your client's duty of care doesn't stop at their own front door. The Dutch Cyber Security Decree states in article 10(2) that an organisation in scope must test whether its direct suppliers and service providers meet the security requirements — and one word there is often missed: the entity 'checks this periodically'.
That means you don't fill in a form and move on. You enter a recurring cycle. And you don't choose the moment the question arrives: usually at a contract renewal, a tender, or suddenly, because the department at your client that has to arrange this has a deadline of its own.
of Dutch small and medium businesses have security agreements with no chain partner at all (ABN AMRO/MWM2 Cybertrends 2026, fieldwork March 2026, n=777)
There is no statutory questionnaire — and that's deliberate
This is the part that surprises most owners. There is no national standard supplier questionnaire, and there is no statutory certification duty. Article 7(5) establishes that your client draws up the security requirements itself, based on its own risk overview. Two clients in the same sector can therefore quite legitimately ask you for different things.
That's not sloppiness on the legislator's part. During the public consultation it was proposed to make supplier screening and chain audits mandatory, and that proposal was explicitly rejected because, according to the explanatory notes, it 'would lead to increased regulatory burden and considerably higher costs'. The ministerial regulations deliberately leave the chain article undeveloped.
Something practical follows from that. 'We comply with NIS2' is an empty label for a supplier, because there is nothing for you as a supplier to comply with. What counts is whether you can answer that one client's questions with something you can show.
If you get a questionnaire with fifty questions, you're entitled to ask where those requirements come from. They come from your client's risk overview, not from the law. That's not a cheeky question — it's exactly how the law is built.
The one thing the law does say about suppliers
One supplier property is named explicitly. Article 21(4) of the Cyber Security Act instructs organisations to take into account the general quality of products and the cybersecurity practices of their suppliers, 'including their secure development procedures'.
Translated into practice: if something is built for you — a website, a webshop, an integration, a piece of automation — then how it's built is part of your answer to your client. It's also the only element you can be sure will come back. If you're going to prepare for anything, prepare for this:
- Who has access to the systems where your client's data is handled, and how is that access revoked when someone leaves?
- Is two-step verification used to log in, and where is that written down?
- Who builds along from outside your company, and what has been agreed with them?
- Are there backups, and has anyone ever tested restoring them?
- What happens when something goes wrong, and at what point does your client hear about it?
That list doesn't cost you a certificate. It costs you an afternoon, a document with a date and a name on it, and the discipline to update it once a year.
What the law costs your client — and what was estimated at zero on your side
In the explanatory notes, the Dutch government calculated what this costs the companies in scope: €142,000 per company per year, structurally, and €1.071 billion for the 7,550 companies together. The lion's share sits in the duty of care: 1,758 hours a year at €63 an hour plus €30,646 in external costs. In time, that's roughly one full-time position, every year again.
per year per company in scope — the government's own estimate in the explanatory notes to the Cyber Security Decree (Staatsblad 2026, 189)
Now the interesting bit. What that calculation does not include is the bill at the suppliers. The Dutch regulatory burden advisory board pointed this out; the answer in the explanatory notes is that it only concerns suppliers relevant to the organisation's systems, 'so the estimate is that on this point the Act and the Decree do not cause a higher regulatory burden'. The burden in the chain has officially been estimated at zero.
Two pages earlier in that same document, the companies surveyed say the opposite: firms that work extensively on a project basis with chain partners expect that concluding agreements with those parties will structurally take more time, and the consulted small-business panel warns that smaller suppliers 'will find it difficult to meet the requirements'. It's right there, in the official gazette, in the same document.
The market has since put a price on that zero
The law prescribes no supplier certificate, but the Dutch employers' organisations MKB-Nederland and VNO-NCW built one themselves through their Samen Digitaal Veilig initiative: NIS2 Supply Chain. There's a free starter package, and the paid levels start at €725 a year and rise with headcount. The external audit is not included. Affiliated trade associations — 96 of them, including the technical installation, construction, transport and metal sector bodies — give their members a discount.
In fairness: a label like that can simply be handy. One recognisable answer beats ten different forms, and the route towards it forces you to write down things you should have written down anyway. But it is not a legal requirement, and nobody can demand it of you by appealing to the law. In short: the legislator estimated the chain costs at zero, and the market prices that same chain per supplier per year.
Then the heaviest variant, which is sometimes requested: ISO 27001. The whole of the Netherlands holds 1,568 valid ISO 27001 certificates, including every bank, insurer, multinational and hospital (ISO Survey 2024). For a company under fifty people that certificate is an exception, not a norm. You see that in the price: the audit alone costs a small company roughly €4,000 to €12,500 in the first year, plus €2,000 to €4,500 a year in interim checks.
valid ISO 27001 certificates in the entire Netherlands — including every bank, insurer and multinational (ISO Survey 2024)
Two things sold as legal requirements that aren't
- 'You need a certificate.' No. The law has no certification duty for suppliers, and there is no standard a supplier has to meet. A label makes answering easier; it is not an entry requirement.
- 'The board training has to be given by an independent, external party.' That requirement was in the draft and was removed. The explanatory notes say so literally: the requirement of an independent trainer was dropped after the public consultation. The training duty itself does remain — it comes from the European directive — but who gives it is free. And that duty applies to the board of the organisation in scope, not to you as a supplier.
Rule of thumb for every offer landing in your inbox now: ask which article of law contains the obligation. If the seller can't name it, they're selling a service, not a duty. That's allowed — but it's a different thing.
What you can usefully do now
- Go through your client list and mark who is likely in scope: healthcare, government, energy, water, transport, larger companies. That's where the questionnaires come from.
- Put the basics on paper: access, two-step verification, backups, what happens during an incident, and who is responsible for what. Every document with a date and a name on it.
- Add who from outside builds on your systems, and what you agreed with them. That's the one point the law names explicitly.
- Always answer a questionnaire with a reference to a document. An answer without a source is a promise; an answer with a source is evidence.
- If you don't have something, write that down with a date by which you will. An honest gap with a plan beats an empty field — and beats a promise you can't keep at the next round.
- Only buy something once you've had the same question twice. Then you know which question it is, and you're not paying for an answer nobody asked for.
And staying calm is allowed too
There's no wave of panic, and that's measurable. The share of Dutch business owners seeing cybercrime as a (very) high risk was 35% in 2023, 40% in 2024, 33% in 2025 and 37% in 2026 — the study itself calls that last move 'not significant' (ABN AMRO/MWM2 Cybertrends 2026, n=777). Four flat years. Anyone telling you the world suddenly changed is selling something.
But the chain risk is real, and the Netherlands saw an example this year. On 7 April 2026 ChipSoft was hit by ransomware — the supplier that runs the patient records of roughly 76% of all Dutch hospitals. Eleven to fifteen hospitals took their patient portals offline (sources: security.nl and NOS, April 2026). The point isn't the sector but the mechanism: the security of all those organisations may have been perfectly fine, and they were down anyway. That's why your client asks you these questions. Not because they distrust you.
Ready to get started?
Request a free consultation. We look together at where you are losing time.
Schedule free callRecognise this in your business?
Schedule a free consultation. We look together at where you lose time — and whether AI is the answer.
Schedule free call