What is the scope of the Cybersecurity Act?

The scope of the Cybersecurity Act is the set of criteria (sector, type of service, size and a number of exceptions) that determines whether an organisation is an essential or important entity under the Dutch implementation of NIS2. Since 15 August 2026, every organisation within that scope has had to register itself and comply with the duty of care and the incident reporting obligation; no ministry designates you first, and there is no transition period. According to the Dutch government, more than 8,000 organisations are affected. This page goes deeper into the scope test itself. The wider content of the Cybersecurity Act (Cyberbeveiligingswet, Cbw) is covered in the main article.


🧱 Which two questions decide whether you are in scope?

The basic rule in Article 2 of NIS2 is a two-part test, and both answers must be β€œyes”:

  • Sector test β€” does your organisation carry out an activity or provide a service listed in Annex I (sectors of high criticality) or Annex II (other critical sectors)?
  • Size test β€” is your organisation at least a medium-sized enterprise under the EU SME Recommendation 2003/361/EC?

What counts is what you do, not what you call yourself. A food manufacturer that also produces cleaning agents, or a machine builder that also builds electrical control panels, can fall within scope through several activities at once. Size is measured across the whole enterprise, not just the department carrying out the regulated activity.


πŸ“ How does the size test work?

The Cybersecurity Act follows the thresholds of the SME Recommendation. Watch the combination of or and and:

Category Staff (FTE) Financial criterion Consequence
Small or micro Fewer than 50 Turnover or balance sheet total of at most EUR 10 million Out of scope in principle
Medium-sized 50 to 249 Or: turnover and balance sheet total both above EUR 10 million In scope: usually an important entity
Large 250 or more Or: turnover above EUR 50 million and balance sheet total above EUR 43 million Annex I: essential; Annex II: important

A company with 40 employees, EUR 14 million turnover and a EUR 12 million balance sheet is therefore medium-sized after all, because both financial ceilings are exceeded. With EUR 14 million turnover but a balance sheet of EUR 6 million it stays small. Under the SME Recommendation, the figures of the latest closed financial year apply, and a change of status in principle only takes effect once a threshold has been crossed in two consecutive financial years.


🏒 How do subsidiaries, holdings and partners count?

This is where most self-assessments go wrong. You count not only your own legal entity but also the enterprises you are connected to:

  • Linked enterprises β€” where there is decisive control (a majority of voting rights, the right to appoint or dismiss the board, or dominant influence through articles or contract), you add 100% of headcount, turnover and balance sheet, including the parent and sister companies
  • Partner enterprises β€” with a holding of 25% to 50% without control, you add the figures pro rata; a 40% stake means 40%
  • Autonomous enterprises β€” holdings below 25% are not counted
  • No exception for public stakes β€” the Recommendation’s rule that a public body holding 25% or more removes SME status is disapplied (NIS2 Article 2(1); Cbw Article 8(2) and Article 12(2))

A small Dutch subsidiary of 30 employees that belongs to an international group of 2,000 and, for example, distributes chemical substances is therefore in scope as a large entity.


🏭 Which sectors matter for OT?

For industrial automation and process control, these sectors are the most relevant:

Sector Annex Who is covered (core)
Energy I Electricity (generation, grid operation, supply), district heating and cooling, oil, gas, hydrogen
Transport I Air, rail, water and road, including ports, traffic management and intelligent transport systems
Drinking water I Suppliers and distributors of water for human consumption, unless distribution is a non-essential part of their activity
Waste water I Undertakings collecting, disposing of or treating urban, domestic or industrial waste water, unless this is non-essential to their activity
Waste management II Waste management undertakings, only where it is their principal economic activity
Chemicals II Manufacture and distribution of substances and mixtures (REACH definitions) and production of articles from them
Food II Wholesale distribution and industrial production and processing of food
Manufacturing II Medical devices and NACE C26 (electronics and optics), C27 (electrical equipment), C28 (machinery), C29 (motor vehicles), C30 (other transport equipment)

Manufacturers outside these NACE codes, for example in metals, plastics or paper, are not caught via the manufacturing sector. They can still end up in scope through another activity, such as manufacturing or distributing chemical substances. A group relationship only changes the size, not the sector: the sector test applies to the activities of the enterprise itself.


βš–οΈ Are you an essential or an important entity?

The obligations are the same for both categories; the difference lies in supervision and the maximum fine.

Situation Annex I (high criticality) Annex II (other critical)
Medium-sized Important Important
Large Essential Important
Critical entity under the Wwke Always essential Always essential
Qualified trust service provider, TLD registry, DNS service provider Essential, regardless of size β€”
Provider of public electronic communications Medium-sized or larger: essential; smaller: important β€”
Supervision Ex ante and ex post Ex post only
Maximum fine Essential: EUR 10 million or 2% of worldwide turnover Important: EUR 7 million or 1.4% of worldwide turnover

🚨 Who is in scope regardless of size?

The size test does not apply to a number of organisations considered too important to leave out:

  • Core digital services β€” providers of public electronic communications networks and services, trust service providers, TLD registries and DNS service providers
  • Critical entities β€” organisations designated as critical entities under the Wwke, for instance in critical infrastructure such as energy and drinking water
  • Government β€” ministries, provinces, municipalities and water boards; public bodies are assessed against their own criteria instead of the size test
  • Designation β€” a small organisation that is the sole provider of a critical service, or whose disruption would seriously affect public safety, public health or create systemic risk, can be specifically designated

πŸ”— Does the law also reach suppliers that are not in scope themselves?

Yes, indirectly. Under the duty of care, regulated entities must secure their supply chain, including suppliers outside the EU. That flows into purchasing terms, audits and questionnaires for system integrators, OEMs and maintenance contractors with remote access to SCADA and OT environments. A small integrator outside the scope therefore still receives contractual requirements, often based on IEC 62443-2-4 or ISO 27001. See Supplier Security and Supply Chain Risk. Check your own position too: anyone providing ICT management for others as a managed service provider falls under Annex I once medium-sized. Product requirements for manufacturers come separately from the Cyber Resilience Act.


πŸ› οΈ How do you work through the scope test step by step?

  1. Government or designated? β€” if you are a public body, a critical entity under the Wwke or specifically designated, you are in scope; go to step 6
  2. Core digital service? β€” telecoms, trust service, TLD registry or DNS: you are in scope regardless of size; go to step 6
  3. Sector? β€” compare all your activities, including ancillary ones, with Annexes I and II; no match means out of scope, but assess your supply-chain role (step 8)
  4. Size? β€” calculate headcount, turnover and balance sheet including linked and partner enterprises; small means out of scope in principle
  5. Category β€” Annex I and large means essential; the other combinations are important
  6. Establishment β€” the Dutch law applies in principle to entities established in the Netherlands; for DNS, cloud, data centre and managed services, among others, the location of the main establishment in the EU is decisive, and telecoms providers fall under the country where they provide their services
  7. Validate and register β€” check the outcome with the NIS2 Zelfevaluatie NL self-assessment tool and register via MijnNCSC using eHerkenning; report changes within 14 days
  8. Document β€” record the reasoning for your board and regulator, and review annually whether growth, acquisitions or new activities change the outcome

If you are in scope, the measures in the Cybersecurity Decree and the deadlines in Cybersecurity Act Incident Reporting follow. Start with a complete asset inventory and the sector support offered by the NCSC or your sector CSIRT.


❓ Frequently asked questions

Does NIS2 apply to my organisation if we have fewer than 50 employees?

An organisation with fewer than 50 employees can still fall under NIS2 and the Dutch Cybersecurity Act if its turnover and balance sheet total both exceed EUR 10 million. Staff of linked and partner enterprises also count, and for DNS service providers, critical entities and public bodies, among others, the size threshold does not apply at all.

Where can I find the official self-assessment for the Dutch Cybersecurity Act?

The official NIS2 Zelfevaluatie NL was developed by the Dutch Authority for Digital Infrastructure (RDI) and is hosted on regelhulpenvoorbedrijven.nl. The self-assessment indicates whether the Cybersecurity Act is likely to apply to you and whether you are essential or important; the result is indicative, and responsibility stays with your organisation.

Does a foreign parent company count towards the Cybersecurity Act size test?

Yes, a parent company with decisive control is a linked enterprise, so its headcount, turnover and balance sheet count in full towards the Cybersecurity Act size test. A small Dutch branch of a large group is therefore rarely small in the legal sense.

Is a machine builder covered by the Dutch Cybersecurity Act?

A machine builder active in NACE C28 falls under Annex II of the Cybersecurity Act as soon as the enterprise is at least medium-sized, and is then an important entity. On top of that, a machine builder often receives contractual supply-chain obligations from customers in energy, drinking water or chemicals.

Should I register if I am unsure whether the Cybersecurity Act applies?

The registration obligation of the Cybersecurity Act applies only to organisations that are actually in scope. If in doubt, document your scope assessment in writing, use the self-assessment and, where needed, ask the regulator for clarity, because failing to register when you should can lead to an order subject to penalty or a fine.

Is a supplier of a NIS2 organisation covered by the law itself?

A supplier is only covered by NIS2 and the Cybersecurity Act in its own right if it passes the sector and size tests. Regulated customers must, however, manage their supply-chain risks, so suppliers are affected indirectly through contracts, audits and security requirements.


πŸ“Œ In summary

Whether your organisation falls under the Cybersecurity Act is something you determine yourself with a two-part test: an activity from Annex I or II of NIS2 and at least medium size, calculated including linked and partner enterprises.

Annex I combined with large size makes you essential, the other combinations important, and for public bodies, critical entities and core digital services size does not count. Document the outcome, check it with the NIS2 Zelfevaluatie NL and register via MijnNCSC; even organisations outside the law will feel its requirements through customers in the supply chain.