LinkedIn·Tuesday, 4 August 2026·22d ago
Belgium beat the Netherlands to NIS2. Not by a few weeks, but by almost 22 months 🙈 Belgium was the first EU Member State to fully…
Jelle De Laender
Helping companies stay in control of security & compliance - ISO 27001 Implementer & Auditor - Cybersecurity Advisor - Creator of Semonto
Belgium beat the Netherlands to NIS2.
Not by a few weeks, but by almost 22 months 🙈
Belgium was the first EU Member State to fully transpose NIS2. Its law has applied since 18 October 2024.
The Dutch Cyberbeveiligingswet enters into force on 15 August 2026 👏
There is no general grace period, although board members have two years to meet the formal training requirement.
What does this mean for Dutch SaaS companies?
First, “SaaS” is not the legal test.
NIS2 explicitly recognises SaaS as a possible cloud computing model, but a service still needs to meet the statutory definition. Sector, service type, company size, group structure and jurisdiction all matter.
A practical first warning light is 50 or more employees, or more than €10 million in annual turnover or balance sheet total. Exceptions apply, so this is a starting point, not a conclusion.
For SaaS providers, the categories to examine closely are cloud computing, managed services and managed security services.
Even if you are not directly in scope, your NIS2-regulated customers will increasingly push cybersecurity requirements down the supply chain.
For organisations in scope, the headline obligations are clear:
- Register in the national entity register.
- Perform a risk assessment and implement appropriate and proportionate measures.
- Cover incident response, continuity, supply-chain security, secure development, access, assets, cryptography, awareness and effectiveness reviews.
- Report significant incidents, starting with an early warning within 24 hours.
- Make cybersecurity a board responsibility, including approval, oversight and training.
- Be ready to demonstrate that the measures actually work.
Where does ISO/IEC 27001 fit?
A mature ISO 27001 ISMS provides a serious head start. It gives you the governance, risk process, ownership, supplier controls, incident procedures, evidence, internal audits, management reviews and continual improvement that NIS2 expects.
But ISO 27001 is not a NIS2 certificate.
It does not determine your legal scope, register your organisation, meet the statutory reporting clock or automatically cover every NIS2 requirement. Your certified scope can also be narrower than the services and dependencies covered by the law (although, I always recommend to have your ISO 27001 scope broad and covering the full company and services).
The real advantage is not the certificate on the wall.
It is having a living management system that lets you integrate NIS2 into existing risk management, supplier assurance and incident response, instead of starting another last-minute compliance project.
The question for Dutch SaaS boards is therefore not only:
“Are we ISO 27001 certified?”
It is:
“Can we show that our ISMS covers the right services, risks and legal obligations by 15 August?”
NIS2 is not about collecting another badge. It is about being in control before an incident, during it and after it.
💬 3↻ 1
View on LinkedIn Cross-referenced
Related on the wire
Such a small gesture. Such a simple notification. Yet, it works. Every now and then, I get this email from Homey about a free, open-source…
HTTP is not dead yet. But Chrome is becoming a lot less patient with it 👮♀️ Starting with Chrome 154, users will see a warning before…
Six months ago, if you’d told me I would take part in the Dodentocht, the 100 km “Death March”, I’d have said you were talking nonsense 🤣…
The AI Act is probably the first major European regulation where organisations with a mature ISO 27001 ISMS get a genuine head start. Not…
When we think about information security, we often think about ISO 27001, governance, risk management, awareness, firewalls, EDR, or…
We all do stupid things sometimes. A few months ago, someone challenged me to sign up for the Dodentocht ☠️ For those who don't know it:…