NIS2Cybersecurity ActSecurity by design

NIS2 and custom software: what does it mean for your organisation?

NIS2 is the European directive on digital resilience. The Netherlands has transposed it into the Cybersecurity Act (Cyberbeveiligingswet), which comes into force on 15 August 2026 and replaces the Wbni. For custom software, this mainly means security by design, structured logging, timely incident reporting and attention to your supply chain. This page explains what the law means in practice for your software. This is not legal advice.

What are NIS2 and the Cybersecurity Act?

NIS2 is the second European directive on network and information security, laid down in EU Directive 2022/2555. It requires a broad group of organisations to improve their digital resilience and to report incidents.

The Netherlands has transposed NIS2 into the Cybersecurity Act. The Senate adopted it on 7 July 2026; the Act takes effect on 15 August 2026 and replaces the Network and Information Systems Security Act (Wbni). According to the Dutch Government, more than 8,000 organisations will face new obligations.

The law distinguishes essential and important entities in the sectors listed in Annexes I and II of the directive. You determine whether you fall within scope by consulting the official sources. The Digital Trust Center and the NCSC offer tools for this. We configure your custom software so you can meet the requirements, whether that is a new custom software development project or an existing application.

Duty of care

Appropriate technical and organisational measures to manage risks. For software, this means security by design.

Reporting obligation

A phased report of significant incidents: an early warning, a more detailed notification and a final report.

Supply chain responsibility

Security at your suppliers counts too. Agreements on security, updates and notifications are part of your duty of care.

What NIS2 practically requires of your software

The Act is technology-neutral, but it translates into concrete requirements for how software is built and managed.

Security by design

Security from the architecture up: secure standards, role-based access, encryption in transit and at rest, and secure management of keys and tokens.

Logging and detection

Structured logging and monitoring to detect anomalies and incidents quickly, and to substantiate a report with facts.

Vulnerabilities and updates

A process for finding and fixing vulnerabilities, with timely updates and responsible handling of vulnerability reports.

Incident process

The ability to record and assess incidents and report them within the statutory deadlines to the competent CSIRT and the supervisory authority.

The reporting obligation step by step

The NIS2 directive sets out a phased reporting obligation for significant incidents. You will find the exact deadlines and procedures in the Act and the NCSC guidance.

1
Early warning

An initial signal within 24 hours of becoming aware of a significant incident, so that the relevant authorities are informed early.

2
Incident notification

A more detailed notification within 72 hours, including an initial assessment of the nature, impact and measures taken.

3
Final report

A concluding report no later than one month afterwards, covering the root cause, the impact and the measures taken.

4
Prior registration

Under the Cybersecurity Act, organisations register in advance in the entity register via the NCSC, so that reports reach the right authority.

How we build with the Cybersecurity Act in mind

We build custom software with security by design and document the security measures, so that they support your duty of care and reporting obligation. Think of secure architecture, access management, logging, monitoring and vulnerability management. You can read about our broader approach in our information security policy.

Important: we do not provide legal advice and do not determine whether your organisation falls within the Act or qualifies as an essential or important entity. For that, we refer you to the Digital Trust Center, the NCSC and your own legal assessment. We will, however, ensure that your software technically supports and demonstrably evidences the required measures. You can discuss your situation via our contact form.

  • Security by design from the architecture up
  • Role-based access and the principle of least privilege
  • Encryption in transit (TLS 1.2 or higher) and at rest
  • Structured logging and monitoring for detection
  • Process for vulnerabilities, updates and recovery
  • Documentation that supports your duty of care and reporting obligation

Frequently asked questions about NIS2 and software

Answers to the questions we are asked most often about the Dutch Cybersecurity Act and what it means for custom software. This is not legal advice.

NIS2 is the second EU Network and Information Security Directive, set out in EU Directive 2022/2555. It requires a broad group of organisations to get their digital resilience in order and to report incidents. The Netherlands has transposed NIS2 into the Cybersecurity Act (Cyberbeveiligingswet). The House of Representatives (Eerste Kamer) adopted that Act on 7 July 2026, and it enters into force on 15 August 2026, replacing the Network and Information Systems Security Act (Wbni). According to the Dutch government, more than 8,000 organisations in the Netherlands will face new cybersecurity obligations as a result. We base this on the current text of the Act and the guidance from the Digital Trust Center and the NCSC, and for your legal classification we refer you to those sources.

The Act applies to essential and important entities in the sectors listed in Annexes I and II of the NIS2 Directive, such as energy, transport, drinking water, digital infrastructure, government, healthcare, and certain parts of industry and the digital sector. Whether you are covered depends on your sector and on criteria such as size. You can determine whether your organisation qualifies, and as an essential or important entity, by consulting the official sources. The Digital Trust Center and the NCSC offer tools for this. We do not give a legal opinion on your status, but we can help you set up your software and processes so that you can meet the duty of care and the reporting obligation.

The duty of care requires organisations to take appropriate technical and organisational measures to manage the risks to their network and information systems. For custom software, this translates into security by design: a secure architecture, role-based access, encryption in transit and at rest, structured logging and monitoring, secure management of keys and tokens, and a process for updates and vulnerabilities. Risk assessment, access management and recovery capabilities also belong here. We build these measures into the architecture from the outset and document them, so that you can demonstrably meet the duty of care.

The NIS2 Directive sets out a phased reporting obligation for significant incidents. In brief, an organisation first submits an early warning within 24 hours, followed by a more detailed notification within 72 hours, and a final report no later than one month later. In the Netherlands, reporting goes through the competent CSIRT and the supervisory authority, with a reporting portal via the NCSC. Software supports this by detecting incidents quickly, recording the relevant data and making the information needed for a report readily available. You will find the exact deadlines and procedures in the text of the Act and the NCSC guidance; we configure your software so that timely and well-founded reporting is possible.

NIS2 expects organisations to also take security in their supply chain into account. This means you set requirements for the parties that build or manage software for you, and that agreements on security, reporting and management are recorded. As a builder of custom software, we deliver transparent code, clear documentation and clear agreements on authorisation, logging, updates and incident handling. This allows you to substantiate the resilience of your software supply chain, and our role fits within your own duty of care and risk management.

We build custom software with security by design and document the security measures so they align with your duty of care and reporting obligations under the Cybersecurity Act. Think secure architecture, access management, logging, monitoring, vulnerability management, and the ability to substantiate and report incidents in good time. We do not provide legal advice and do not determine whether you fall under the Act; for that, please refer to the Digital Trust Center, the NCSC and your own legal assessment. What we do ensure is that your software technically supports and demonstrably evidences the required measures.

Ready to build software that supports your duty of care?

Tell us which systems and data you work with and where you encounter difficulties. We build security by design into the software, set up logging, monitoring and incident registration, and document the measures so your software meets the duty of care and reporting obligations of the Cybersecurity Act. For your legal classification, please refer to the Digital Trust Center and the NCSC.

Edit content