NIS2: what you need to know about the cybersecurity law and Software procurement
NIS2 is the largest European cybersecurity law in years and has applied in the Netherlands since 15 August 2026 via the Cybersecurity Act. What changes and what does it mean for Software procurement and management of Softwarevendors?
- August 18, 2026
- 5 min
- NIS2 – Cybersecurity Directive
The NIS2 Directive is the largest European cybersecurity law in years. In the Netherlands it is implemented in the Cybersecurity Act (Cbw), which came into effect on 15 August 2026. For those responsible for Software procurement, the law is directly relevant.
What is NIS2?
NIS2 stands for Network and Information Security Directive 2, the successor to the first NIS directive from 2016. The directive requires organizations in critical sectors to structurally strengthen their digital resilience. Member states had to transpose the directive by 17 October 2024 at the latest. The Netherlands did this with the Cybersecurity Act, effective since 15 August 2026, replacing the Network and Information Systems Security Act.
Who does the Cybersecurity Act apply to?
To over 8,000 organizations in the Netherlands that provide essential or important services in sectors such as energy, transport, healthcare, drinking water, digital infrastructure, financial services, and government. Suppliers experience the impact through the requirements their customers impose on the supply chain.
What changes?
Duty of care: appropriate measures to manage risks, including in the supply chain.
Notification duty: serious incidents must be reported quickly, with an initial notification within 24 hours.
Registration duty: organizations subject to the law must register with the NCSC.
Role of directors: directors are responsible for compliance and must undergo training in cybersecurity.
Higher fines: the directive mentions maxima of up to 10 million euros or 2% of global annual turnover for essential entities.
What does this mean for Software procurement?
Supply chain responsibility impacts Software procurement most directly. In practice, this means:
An up-to-date overview of all ICT suppliers and Software, including tools acquired outside IT
Security agreements in contracts with relevant Softwarevendors
Periodic assessment of the security of these parties
Agreements on incident reporting with critical Softwarevendors
How SoftVaro helps
Without a complete overview of your Software, compliance is difficult. SoftVaro maps your Software landscape and includes the terms your organization needs at every renewal. This article is not legal advice; coordinate application with your compliance or legal department.
Frequently Asked Questions
The most asked questions about this topic.
What does NIS2 have to do with Software procurement?
The law requires organizations to manage the risks in their supply chain, including their ICT suppliers and Softwarevendors. For this, you need an up-to-date overview of your Software and appropriate agreements in contracts.
Since when has the Cybersecurity Act been in effect?
The Cybersecurity Act, the Dutch implementation of NIS2, came into effect on 15 August 2026. Organisations covered must register via the NCSC portal.
What are the fines for non-compliance?
The NIS2 Directive mentions maximum fines up to 10 million euros or 2% of global annual turnover for essential entities and up to 7 million euros or 1.4% for important entities. Directors are responsible for compliance.
Ready to save on software?
SoftVaro negotiates the best deal on your behalf with over 4,000 suppliers. Independent, transparent, within 24 hours.