Insights · NIS2 & contracts

NIS2 in the Netherlands from 15 August: what belongs in your vendor contracts

Three European regimes converge in the same contract: the Dutch Cybersecurity Act implementing NIS2, DORA for financial services and the Cyber Resilience Act for products with digital elements. Different requirements, one page.

Published 20 July 2026 · Reading time ± 7 minutes · General information, not legal advice

On 15 August 2026 the Dutch Cybersecurity Act and the Critical Entities Resilience Act enter into force; the Senate adopted both on 7 July 2026. The Dutch implementation of NIS2 is therefore a fact — and the conversation shifts from «when is it coming» to «is it in our contracts».

Who it affects, and what it requires

The Cybersecurity Act is expected to apply to roughly 8,000 organisations across eighteen sectors, split into essential and important entities; the companion act designates around 500 organisations as critical entities. The law imposes three duties: registration in the entity register, a duty of care and a notification duty. That notification duty runs to a tight rhythm: an early warning within 24 hours, a notification within 72 hours and a final report within one month. Board members must be trained, with a transition period of at most two years.

The duty of care comprises ten measures. For anyone managing vendors, measure four matters most: supply chain security. The other nine — risk analysis and security policy, incident handling, business continuity including back-up and recovery, security in acquisition and maintenance of systems, assessing the effectiveness of measures, cyber hygiene and training, cryptography, personnel and access policy, and multi-factor authentication — almost all cascade to suppliers the moment you outsource.

The law does not apply to your suppliers — yet they will get the requirements

This is the most commonly misunderstood point. The Cybersecurity Act does not apply directly to your suppliers. It obliges organisations that are in scope to manage supply chain risk, and that happens through contracts. Specifically, an in-scope organisation must assess which direct suppliers pose a digital or physical risk, make and document agreements with those suppliers on security measures — in practice through an SLA or an agreements-and-procedures dossier — and communicate clearly which measures apply. The approach must be risk-based and take into account the supplier's own security practices and development procedures.

Scope is limited to direct suppliers, not the entire chain behind them. But the practical consequence is significant: suppliers outside the law's scope will receive security requirement lists from their customers over the coming months. If you are a supplier, the question is not whether that list arrives, but whether you have an answer.

NIS2 penalties are substantial. The directive sets a maximum of at least ten million euro or at least 2% of worldwide annual turnover for essential entities, and seven million euro or 1.4% for important entities — whichever is higher. Check the precise Dutch amounts in the act itself with your legal adviser.

DORA: the most concrete contract requirements in existence

If you work in or for financial services, DORA has applied since 17 January 2025 and contract content is not optional. Article 30 prescribes what belongs in every ICT contract: a clear and complete description of all functions and services including whether subcontracting is permitted; the regions and countries where the service is performed and data is stored, plus advance notice of change; provisions on availability, authenticity, integrity and confidentiality of data; access to and return of data in an easily accessible format on termination or insolvency; service level descriptions; incident assistance at no extra cost or at a price determined in advance; cooperation with authorities; termination rights with minimum notice periods; and participation in security awareness and resilience training.

For critical or important functions more is added: quantitative and qualitative performance targets, reporting obligations for developments that materially affect service delivery, continuity plans, participation in threat-led penetration testing, unrestricted audit, access and inspection rights for both the institution and the supervisor, and exit strategies with mandatory transition periods. Practically, the 2026 register of information had to be filed before 20 March 2026, with 31 December 2025 as the reference date.

Even if DORA does not apply to you, Article 30 is the best freely available checklist for an ICT contract that exists.

Cyber Resilience Act: your vendors will already be reporting

The Cyber Resilience Act entered into force on 10 December 2024. Reporting obligations apply from 11 September 2026 and the main obligations from 11 December 2027. From September, manufacturers must report actively exploited vulnerabilities and severe incidents on the same rhythm you know: early warning within 24 hours, full notification within 72 hours and a final report within fourteen days or one month respectively. From December 2027, CE marking becomes a procurement gate for products with digital elements — and therefore a contractual warranty you can demand.

The practical effect is that your software vendors fall under a reporting regime from September. Make sure your contract entitles you to receive those reports too — otherwise your vendor notifies the regulator neatly while you read about it in the press.

What this means for your contract clause

Three regimes, one clause. The minimum: notification deadlines aligned to your own 24-hour duty, audit and inspection rights, mandatory disclosure of and consent to subprocessors, transparency on data locations and changes to them, exit arrangements with a transition period and data return in a usable format, requirements for secure development and maintenance, vulnerability handling and patch timelines, and multi-factor authentication and encryption as hard requirements.

None of that is an exotic wish list any more — it is the new baseline. The only question is whether it is already in your live contracts, and that question is answered by working through your portfolio, not by writing a policy. Our clause check is built for exactly that.

Want your contracts tested against the new security requirements?

We review your vendor portfolio for notification deadlines, audit rights, subprocessors and exit — and deliver a concrete list of what is missing per contract.