Cybersecurity & NIS2
NIS2 in the Netherlands: Does a Small Advisory Firm Need to Register?
The Dutch Cyberbeveiligingswet is now in force. But advising critical-sector clients does not automatically make a consultancy a NIS2 entity. The real test is sector, activity, size — and how the business model may evolve.

Reviewed by Oleksandr Sobovyi, Founder & CEO of CORVUS AI — editorial responsibility statement below.
The Dutch Cyberbeveiligingswet enters into force on 15 August 2026. For thousands of organisations, registration and cybersecurity governance are now legal obligations. But working with critical sectors does not, by itself, make a company a NIS2 entity.
Consider a hypothetical Dutch consultancy with 12 employees — call it the Firm. It advises companies working in artificial intelligence, defence technology, autonomous systems and critical infrastructure. It provides legal, regulatory and strategic advice, but does not operate cloud infrastructure, manage clients' networks or provide managed security services.
Does the Firm have to register under the Cyberbeveiligingswet?
On those facts, probably not.
But the reasoning matters more than the answer.
The first question is what the company actually does
The Cyberbeveiligingswet (Cbw) implements the EU NIS2 Directive in the Netherlands. From 15 August 2026, organisations falling within its scope are subject to registration, cybersecurity risk-management and incident-reporting obligations.
The scope analysis starts with the organisation's own activities.
The Cbw covers entities operating within 18 critical and highly critical sectors, including energy, transport, banking, financial-market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space, postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research.
The important distinction is between serving a regulated sector and operating in one.
A consultancy does not become an energy-sector entity merely because an energy company is its client. Nor does advising a defence manufacturer or critical-infrastructure operator automatically transform the adviser into a NIS2 entity.
The NCSC makes this distinction explicit in its registration guidance: the relevant sector is the sector in which the organisation itself operates, rather than the sectors to which it supplies services. The registration process uses the organisation's KvK/SBI information as a starting point, but the organisation remains responsible for checking whether the resulting classification is correct.
For the Firm, ordinary legal, regulatory and strategic consultancy therefore does not, on the assumed facts, create Cbw coverage merely because its clients operate in defence, AI or critical infrastructure.
Then comes the size test
Sector classification is only the first part of the analysis.
For most categories, the Cbw also applies a size threshold. NCSC guidance states that an organisation with 50 or more employees, or with annual turnover or a balance-sheet total exceeding €10 million, will probably satisfy the relevant size criterion. Micro and small enterprises are generally outside the scope.
The Firm has 12 employees and remains below the financial thresholds.
It therefore has two reasons pointing in the same direction:
Sector: ordinary consultancy is not, on the assumed facts, a covered Cbw activity.
Size: the company is below the ordinary size threshold.
The preliminary conclusion is therefore:
The Firm — Cbw/NIS2 status: currently outside scope; no mandatory entity registration.
That conclusion should not be treated as permanent.
Small does not always mean exempt
There are important exceptions to the size rule.
Certain entities can fall within the Cbw irrespective of their size. NCSC identifies, among others, providers of public electronic communications networks and services, trust-service providers, DNS service providers, top-level-domain registries and public authorities. A competent minister can also designate an organisation that would not otherwise fall within the ordinary size criteria.
For a consultancy such as the Firm, however, the more realistic future risk is business-model drift.
Suppose the company moves beyond advisory work and begins to:
administer clients' ICT environments;
provide managed cybersecurity services;
operate infrastructure or platforms falling within a covered digital category;
acquire or restructure into a group containing covered entities; or
provide services whose substance is different from the company's existing consultancy classification.
The original NIS2 analysis may then cease to be reliable.
That is why "not in scope" should be a documented legal conclusion, not an assumption left indefinitely in a compliance spreadsheet.
If the Cbw applies, registration is only the beginning
An organisation within scope faces three core obligations: registration, duty of care and incident reporting.
1. Registration
Covered entities must register in the national entity register through MijnNCSC.
For a commercial organisation using eHerkenning, NCSC requires EH2+ and authority to act for the relevant organisation. The eHerkenning credential must be connected to the company's KvK number.
The registration is more than a company-name form.
Organisations provide information concerning their sector and subsector, entity classification, relevant EU Member States, contact details and network information including public IP addresses or ranges, domain names and, where applicable, Autonomous System Numbers.
Changes must subsequently be reported through MijnNCSC within 14 days.
For organisations already within scope, this is no longer a preparatory exercise: the registration obligation applies from 15 August 2026.
2. Duty of care
The more significant obligation is the zorgplicht, or duty of care.
Covered organisations must conduct a cybersecurity risk assessment and implement appropriate and proportionate technical, operational and organisational measures to manage risks affecting the network and information systems used to provide their services.
This moves NIS2 compliance well beyond conventional IT security.
In practice, organisations need a governance system covering areas such as incident handling, business continuity, backup and disaster recovery, supply-chain security, vulnerability management, access controls, secure authentication, encryption, security policies and testing of the effectiveness of security measures.
Management cannot simply delegate the issue to the IT department. NCSC guidance states that members of the management body must approve the measures and supervise their implementation.
Cybersecurity therefore becomes a corporate governance obligation, not merely a technical function.
3. Incident reporting
Significant incidents must be reported to the relevant CSIRT and supervisory authority.
The system is phased. The first stage is an early warning within 24 hours. NCSC describes significant incidents as those capable of seriously disrupting services, causing financial loss or producing substantial damage to other organisations.
This needs to be incorporated into incident-response procedures before an incident occurs.
A cyber incident can also engage several legal regimes simultaneously. If personal data are compromised, for example, the organisation must separately assess its notification obligations under the GDPR. Contractual notification obligations to customers, insurers, authorities or other counterparties may run in parallel.
A single ransomware incident can therefore create several clocks running at once.
The more important issue for suppliers: indirect NIS2 exposure
Being outside the Cbw does not mean being commercially unaffected by it.
This is particularly relevant to the Firm.
Cbw entities must manage cybersecurity risks in their supply chains. NCSC specifically warns suppliers that organisations within scope may impose cybersecurity requirements on them even where the suppliers themselves are not directly regulated by the Cbw.
A small consultancy serving regulated organisations may therefore encounter NIS2 through:
procurement questionnaires;
security requirements in contracts;
supplier due diligence;
access-control requirements;
incident-notification clauses;
business-continuity requirements;
cybersecurity audits; and
demands for evidence of internal security controls.
The legal distinction is important.
Direct Cbw obligation and contractual NIS2-driven obligation are not the same thing.
But from a commercial perspective, both can determine whether a supplier remains eligible to work with a critical-sector customer.
What should the Firm do now?
Registering "just in case" would not be the right starting point. NCSC's own guidance states that an organisation outside the relevant critical sectors does not need to register.
The Firm should instead take four proportionate steps.
First, document the scope analysis. Prepare a short Cbw/NIS2 Applicability Assessment recording the company's activities, sector analysis, size thresholds, exceptions considered and the conclusion that the company is currently outside scope.
Second, verify the KvK/SBI classification. NCSC uses SBI codes when pre-populating sector information during registration. An inaccurate or excessively broad business classification can therefore create unnecessary uncertainty and should be corrected at source where appropriate.
Third, adopt baseline cybersecurity controls voluntarily. Being outside the Cbw is not a reason to ignore cyber risk. For an advisory business handling commercially sensitive, legal or technology information, risk assessment, MFA, access controls, backups and incident preparedness are sensible governance measures irrespective of formal NIS2 status.
Fourth, create an incident-classification procedure. It should distinguish at least between a cybersecurity incident, a GDPR personal-data breach, a Cbw-reportable incident if the company's status changes, and contractual notification obligations owed to clients.
The strategic point
The wrong NIS2 question is:
"Are we a small company?"
The better question is:
"What services do we actually provide, in which regulated category, at what scale, and could our business model move us into scope?"
For a small Dutch legal and technology consultancy such as the Firm, the answer today may legitimately be no mandatory Cbw registration.
But that conclusion should be defensible.
For companies operating close to AI, defence, digital infrastructure and other regulated markets, a two-page applicability assessment can be considerably more valuable than either registering unnecessarily or discovering too late that the business model changed while the compliance analysis did not.
CORVUS AI advises AI, defence-tech and dual-use companies, and their advisers, on NIS2/Cbw scope determinations, AI Act governance and cross-border EU–Ukraine regulatory exposure. If your business model touches a regulated sector — even at one remove — a documented applicability assessment is the first deliverable, not the last.
What matters. What’s next.
Disclaimer
This article has been prepared by CORVUS AI for general informational and educational purposes only. It is intended to make complex legal and regulatory developments easier to understand.
It does not constitute legal advice and does not create a professional adviser–client relationship. The information should not be relied upon as a substitute for advice based on the specific facts, circumstances and applicable law relevant to your organisation or project.
The article reflects our understanding of the law and regulatory framework as of the date of publication. Legislation, case law, regulatory guidance and administrative practice may subsequently change. While reasonable care has been taken in preparing this article, CORVUS AI does not warrant that the information is complete or remains current after the date of publication. We do not undertake to update this content.
To the fullest extent permitted by applicable law, CORVUS AI excludes liability for loss arising from reliance on this article. Nothing in this article constitutes an offer or solicitation to provide regulated legal services in any jurisdiction where doing so would be unlawful.
AI-assisted preparation: This article was prepared with the assistance of AI tools. Its legal analysis, conclusions and final text were subject to human review and editorial control and were reviewed and approved prior to publication by Oleksandr Sobovyi, Founder & CEO of CORVUS AI. CORVUS AI retains editorial responsibility for the published content.
For advice tailored to your organisation, project or specific circumstances, please contact CORVUS AI.
NCSC — Does the Cyberbeveiligingswet apply to my organisation?
