On the eve of 2026, cybersecurity is an indispensable priority for organisations, regardless of their sector or size. The rise of new digital threats, the use of artificial intelligence either for attacks or for protection, and the ever wider European regulatory landscape forces organisations to reinforce their digital resilience thoroughly and permanently. The focus lies not only on technological solutions here; it is precisely organisation, compliance and contractual agreements that are subjected to stricter demands by legislators and society alike. This means that the responsibility for cybersecurity will fall increasingly on in-house counsel.
A Europe Fit for the Digital Age
In the past decade, the European Commission already launched its digital strategy under the motto ‘A Europe Fit for the Digital Age’. This strategy includes a large package of laws and regulations, devised to strengthen the digital resilience of Europe. The package includes NIS2, DORA, CRA, the AI Act and the Data Act. Together, these laws form an integrated and interconnected framework intended to make the European digital space safer, more reliable and future-proof. Whereas previous regulations tended to be more reactive in nature, the new policy focuses expressly on prevention, transparency and collaboration between public and private actors. In December 2025, the European Commission added one more initiative through its proposal for a Digital Omnibus Regulation.
NIS2 holds a key position in all this. [1] NIS2 is currently being implemented into national legislation. In the Netherlands, this is the Cybersecurity Act (Cyberbeveiligingswet, ‘Cbw’), of which the proposal was sent to the Lower House of Parliament in the summer of 2025. The Cbw will have several underlying laws and regulations, including the Cybersecurity Decree (Cyberbeveiligingsbesluit, ‘Cbb’) with an elaboration of the duty of care, the obligation for directors to register and to train, and ministerial regulations. The Cbw is currently expected to enter into effect in quarter 2 of 2026, to replace the Security of Network and Information Systems Act (‘Wbni’).
Although the obligations set out in NIS2 will only formally apply once the Cbw has taken effect, it is wise for organisations to take action already now, as the coming period will be dominated by preparation and implementation. The Act will introduce a number of concrete obligations, such as the performance of risk analyses, revising governance structures, and recording responsibilities to suppliers and clients in contracts.
Besides, sectors may be faced with additional sector-specific requirements, depending on the nature of their services and the extent of social impact. Organisations that operate in several sectors or are part of an international group may therefore have to comply with several frameworks of obligations.
Scope of application
An important part of NIS2 is the demarcation of the scope of application and the obligations applicable within this scope. Depending on the sector (Annex I or II) and the size of the organisation, the Directive distinguishes between essential and important entities. In practice this distinction is mainly reflected in the supervisory regime, which is larger for essential entities than for important entities. For entities active in specific digital sectors, the duty of care and the reporting obligation are given concrete shape in the Implementing Regulation (EUR) 2024/2690.
It is crucial that in-house counsel start by determining which sector(s) their organisation is part of. After all, an entity or a group of entities may provide various services and may therefore fall under several regimes at the same time. It is important to consider the service objectively, rather than depart from the sector under which the organisation intends to fall. It is the actual activities that are decisive.
Complex business models
For group entities this may become a fairly complex exercise, especially if the jurisdiction must also be determined. The main rule of NIS2 is that an entity falls under the jurisdiction of the Member State where it is established. However, an exception to this main rule are – in summary – digital services providers; these fall under the jurisdiction of their main establishment. In order to determine the main establishment, NIS2 provides a step-by-step plan to arrive at the correct entity. Given the complexity that this may involve in practice, the Dutch National Coordinator for Counterterrorism and Security (NCTV) has written a manual for complex business models (Handreiking complexe bedrijfsmodellen) to support organisations in this assessment.
Duty of care within the chain
The obligations arising from NIS2 apply not only to the designated essential and important entities, but also affect the broader chain of suppliers, service providers and clients of these organisations. The ‘supply chain duty of care’ – the duty to pass on security measures by contract – imposes the indirect obligation on these parties too to take appropriate security measures and make clear agreements on information security, audit options, incident reporting and data integrity. This means that existing contracts will have to be revised and that all parties involved will have to collaborate more closely. Each party within the chain will have to adopt its own role, identify the relevant risks, and anticipate future obligations in good time.
Heart of NIS2: the duty of care
The duty of care is the heart of NIS2; the essential obligation imposed on organisations to have their security measures in order. These security measures consist of appropriate and proportionate technical, operational and organisational measures to control the security risks of their network and information systems. Their purpose is not just to prevent incidents, but also to mitigate the consequences of a potential incident for relations and other parties involved as much as possible.
These obligations include the preparation of policies on risk analysis and information system security; establishing procedures for incident handling; and taking measures to ensure supply chain security. The concrete demands that these measures will have to meet will be elaborated in regulations to come, to give organisations sufficient reference to realize their responsibility.
To establish whether a measure is suitable, the entity must be able to substantiate that it actually contributes to controlling the risks relevant to that entity. The effectiveness and the proportionality of the measure will be considered. Effectiveness concerns the suitability of the measure to control the relevant risk. This can be derived from European standards, the state of the art, and the results of the risk analyses performed by the entity. Proportionality relates to the proportion between the measure and the nature and seriousness of the risk, the likelihood of incidents, and the potential social and economic consequences of them. The size of the entity and any adverse effects of the measure – such as disruption of critical processes – also play a role here.
An important new aspect that is included in the Cybersecurity Decree is the power of specialist ministers to prohibit the use of certain suppliers or technologies. If this power will indeed be maintained in the law to be adopted, organisations must be prepared for this. They may do so by providing contractual substitution and exit clauses, which allows the timely and controlled switching of suppliers in the event of such a prohibition.
Finally, it is stressed that cybersecurity becomes a director’s responsibility; the board of directors has to approve risk-management measures, supervise performance, and have sufficient knowledge and expertise through demonstrable education and training.
Reporting obligation
While the duty of care concerns the prevention and limitation of risks, NIS2 also obliges organisations to report significant incidents that do occur. Reports must be made in time, both to the Computer Security Incident Response Team (‘CSIRT’) and to the competent supervisor for the sector concerned.
For the Netherlands, the CSIRT will be the Nationaal Cyber Security Centrum (NCSC). However, it is possible to designate another CSIRT depending on the sector. There are specialised teams like Z-CERT for the health care sector, the IBD for municipalities, and CERT-Watermanagement for the water boards.
NIS2 only describes in general terms when something is a significant incident. According to this definition, this is an incident that may lead to (i) a severe disruption of the services, (ii) considerable financial loss for the entity concerned, or (iii) affecting other (natural or legal) persons by causing considerable material or non-material damage. This includes incidents of which the consequences are not yet visible, but may occur, and should therefore be reported after all.
It is possible to elaborate per sector when something is a significant incident. For example, in the Implementing Regulation an incident is regarded as significant if trade secrets leak out or are at risk of leaking out, or if there is a successful, presumably malicious and unauthorized access to network and information systems that may lead to severe operational disruptions. The sectoral criteria must be evaluated at least once per four years. Besides, a shorter reporting period applies than many organisations are used to: within 24 hours after becoming aware of the significant incident. This is followed by a strict process with fixed deadlines and demands on the provision of information. In some cases, the Netherlands even goes beyond what NIS2 prescribes. Organisations with entities in several countries should therefore be aware of it that demands on reporting may differ from jurisdiction to jurisdiction.
To in-house counsel, this means that incident playbooks, decision-making processes and guidelines on communication may need to be adjusted to the new Dutch requirements, and possibly to requirements in other jurisdictions. Good preparation is of the essence: you do not want to have to ascertain the demands for each jurisdiction within the short time available for filing a report.
Besides reporting to the CSIRT and the supervisory authority, entities must also inform their business relations about significant incidents that may have adverse consequences to the provision of services to them.
Towards a proactive legal role
NIS2 requires in-house counsel to adopt a pro-active role; if they begin identifying risks, refining contracts and optimizing internal decision-making processes now, they will enhance the digital resilience of their organisation and minimize the impact of incidents. Only by connecting law, policy and practice will a future-resistant cybersecurity approach emerge in which in-house counsel play an indispensable role in protecting critical processes and complying with stricter reporting obligations. Do not sit and wait, but take the initiative and prepare your organisation for the new challenges that cyber laws bring.