In our earlier blog post, we set out what the NIS2 Directive (cybersecurity) and the CER Directive (physical security of critical infrastructure) actually entail, and the goals Europe is pursuing with them. We're now at an important turning point: from 15 August 2026, both the Cybersecurity Act (Cyberbeveiligingswet, the Dutch implementation of NIS2) and the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten, the Dutch implementation of CER) enter into force. Together, they form a new foundation for national security, continuity and risk management in vital sectors.
For organisations in energy, transport, digital infrastructure, financial services, healthcare, drinking water, government, and various production and logistics chains, this means: more obligations, stricter oversight, and a broader scope of risk, including insider risk.
In short: NIS2 and CER require organisations to structurally address human behaviour, access and integrity as well. That is insider risk management.
This blog covers:
On 15 August 2026, the Cybersecurity Act (Cbw), the Dutch implementation of NIS2, enters into force. From that point, organisations that fall under the Act must meet three core obligations:
Duty of care: organisations must carry out a risk assessment and take appropriate technical and organisational measures to safeguard continuity and information security. Think of monitoring, access management, encryption, incident response, supply chain security and awareness. Access management and monitoring relate directly to insider risk: who has access to which systems, and is misuse of that access flagged in time?
Duty to report: for a significant incident, a phased reporting timeline applies: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month. Cyber incidents must be reported to the CSIRT (NCSC-NL) and the relevant sector regulator. Factors such as impact, duration and financial damage determine whether an incident is reportable.
Supervision: sector regulators will actively check compliance. Penalties can run into the millions of euros.
The following organisations fall under the NIS2 Directive:
To help organisations determine whether they fall under the NIS2 Directive, the Dutch government has published the NIS2 self-assessment tool.
The CER Directive, implemented nationally through the Critical Entities Resilience Act (Wwke), also enters into force on 15 August 2026. Where NIS2 focuses on digital risk, CER focuses on physical threats that can disrupt critical entities, such as sabotage, terrorism, supply chain disruptions, natural disasters and the failure of essential services. Organisations don't determine for themselves whether they are critical; this is decided by the responsible ministries based on risk assessments. Sabotage doesn't have to come from an external attack: an employee or contractor with legitimate access who deliberately disrupts a critical process also falls under the physical threats CER is designed to mitigate.
Organisations that fall under CER must:
CER and NIS2 overlap on key points: both call for structural attention to human factors, access rights, critical processes and incident response.
Both NIS2 and CER name human factors as one of the biggest risks to critical infrastructure. That makes insider risk management not just sensible, but also a compliance matter.
Why insider risk is now central to both frameworks:
The implementation of NIS2 and CER makes one thing clear: organisations must not only strengthen their defences against external actors, but also structurally manage their insider risk. Signpost Six is already your partner in insider risk resilience, and once the obligations under this legislation affect your organisation, we're ready to support you. We help organisations prevent, detect and mitigate threats from insiders, whether intentional, negligent, or driven by external influence. We offer:
NIS2 and CER don't just make insider risk management more important; they make it mandatory. The 15 August deadline is a milestone, not the finish line. The real challenge starts after that: oversight, incidents, audits, and maturing your processes.