// DUTCH CYBERSECURITY ACT / NIS2
NIS2, in plain language.
The Dutch Cybersecurity Act has applied since 15 August 2026. Organisations in scope must manage cyber risk, register, and report serious incidents.
What SKYEN delivers
For one agreed website or API: a written scope, human-validated findings, evidence and impact, practical fixes, one remediation session, a scoped retest, and a closure memo.
The three core duties
- Duty of careChoose suitable and proportionate measures to manage cyber risk.
- Registration dutyUse the official scope check and register through MijnNCSC when required.
- Reporting dutyPrepare the official route for reporting significant incidents.
Your organisation determines applicability and handles registration and incident reporting. SKYEN supplies technical evidence from an authorised web or API assessment; not a certificate or proof of complete compliance.