Updated 2 August 2026
On 15 August 2026 the Netherlands becomes the latest EU country where NIS2 obligations bite: the Cyberbeveiligingswet enters into force with no transition period. Two days ago, on 31 July, Germany’s BSI registration grace period expired — leaving thousands of companies formally in breach. Belgium and Denmark are already auditing.
If you sell into — or operate in — the EU, here is exactly where the clock stands in each market, and what to do about it this week.
The deadline map, country by country
| Country | Law | Where the clock stands (Aug 2026) |
|---|---|---|
| Netherlands | Cyberbeveiligingswet | In force 15 August 2026. NCSC registration, duty of care and the 24-hour reporting clock apply from day one |
| Germany | NIS2UmsuCG / BSIG | In force since 6 Dec 2025. Registration deadline 6 March 2026; BSI grace period ended 31 July 2026. Late registration risks fines up to €500k |
| Belgium | Law of 26 April 2024 | Enforcement phase. Essential entities’ first CyFun/ISO verification was due 18 April 2026; CAB audits running |
| Denmark | NIS2-loven | In force since 1 July 2025; CFCS registration closed 1 Oct 2025; audits of essential entities started early 2026 |
| Sweden | Cybersäkerhetslagen (2025:1506) | Implementing now — new national law applies |
| Norway (EEA) | Digitalsikkerhetsloven today; NIS2 pending | NIS2 not yet in force; preparation window |
Dutch companies: your 13-day checklist
- Scope-check today: 18 sectors, roughly 50+ staff or €10M+ turnover, assessed per legal entity.
- Prepare NCSC registration so you can file the moment the portal opens on 15 August.
- Stand up the 24/72-hour reporting drill: the early-warning clock starts at discovery — including Friday night.
- Run a gap analysis against the ten Article 21 measures; it is your documented starting point if the regulator asks.
- Brief the board: approval, oversight and training are now statutory management duties with personal liability attached.
German companies: late, but not lost
Only around 11,500 of an estimated 29,500 in-scope companies had registered with the BSI by the original March deadline. If you are one of the missing thousands: register now anyway. A corrected omission is a footnote; a continuing one is a finding. Then document a remediation plan — the 24-hour reporting capability first, because it is the one obligation you cannot improvise mid-incident.
Belgium and Denmark: the audit phase is the deadline now
Both countries are past every registration milestone. What matters now is evidence: Belgium’s CCB works through the CyberFundamentals framework (7 to 217 controls depending on your level) with accredited assessment bodies; Denmark’s CFCS began supervising essential entities early this year. In an audit, demonstrable progress beats perfect paperwork that does not exist yet.
Not directly in scope? You are probably in someone’s supply chain
Article 21 makes supply-chain security a mandated measure, so regulated customers across the EU are pushing security requirements into supplier contracts. For SMBs this is the real NIS2 wave: the questionnaire from your biggest customer. Being able to evidence MFA, tested backups and an incident process is increasingly the price of keeping the contract.
FAQ
Does the Dutch law really apply immediately on 15 August 2026?
Yes. There is no transition period: registration, duty of care and incident reporting obligations apply from the entry into force. Preparation time was the period before 15 August.
We missed the German registration deadline — what is the actual risk?
Late registration can be fined up to €500,000, and broader risk-management violations up to €10 million or 2% of global turnover for particularly important entities. Registering late and documenting a plan materially reduces exposure.
Which regulator do we report incidents to?
The national CSIRT/authority of each country where you are an in-scope entity: NCSC (Netherlands), BSI (Germany), CCB (Belgium), CFCS (Denmark). The rhythm is the same everywhere: 24-hour early warning, 72-hour notification, one-month final report.
Is ISO 27001 certification enough for NIS2?
It covers much of Article 21 but does not replace registration, the reporting workflows or management’s personal obligations. See our NIS2 vs ISO 27001 comparison.
Native-language guides: Netherlands · Germany · Belgium · Denmark · Norway · Sweden · NIS2 services hub
General information, not legal advice. Refer to each country’s statute and regulator guidance for your specific situation.