Signpost Six Blog

NIS2 & CER in the Netherlands: what changes from 15 August 2026, and how insider risk becomes a compliance requirement

Written by Signpost Six | Jul 23, 2026 2:33:17 PM

In our earlier blog post, we set out what the NIS2 Directive (cybersecurity) and the CER Directive (physical security of critical infrastructure) actually entail, and the goals Europe is pursuing with them. We're now at an important turning point: from 15 August 2026, both the Cybersecurity Act (Cyberbeveiligingswet, the Dutch implementation of NIS2) and the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten, the Dutch implementation of CER) enter into force. Together, they form a new foundation for national security, continuity and risk management in vital sectors.

For organisations in energy, transport, digital infrastructure, financial services, healthcare, drinking water, government, and various production and logistics chains, this means: more obligations, stricter oversight, and a broader scope of risk, including insider risk.

In short: NIS2 and CER require organisations to structurally address human behaviour, access and integrity as well. That is insider risk management.

This blog covers:

  • What exactly changes from 15 August 2026
  • Why insider risk management plays a key role in NIS2 and CER compliance
  • How organisations are preparing together with Signpost Six

What changes from 15 August 2026?

NIS2 – cybersecurity obligations for essential and important entities

On 15 August 2026, the Cybersecurity Act (Cbw), the Dutch implementation of NIS2, enters into force. From that point, organisations that fall under the Act must meet three core obligations:

Duty of care: organisations must carry out a risk assessment and take appropriate technical and organisational measures to safeguard continuity and information security. Think of monitoring, access management, encryption, incident response, supply chain security and awareness. Access management and monitoring relate directly to insider risk: who has access to which systems, and is misuse of that access flagged in time?

Duty to report: for a significant incident, a phased reporting timeline applies: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month. Cyber incidents must be reported to the CSIRT (NCSC-NL) and the relevant sector regulator. Factors such as impact, duration and financial damage determine whether an incident is reportable.

Supervision: sector regulators will actively check compliance. Penalties can run into the millions of euros.

The following organisations fall under the NIS2 Directive:

  • Organisations in sectors of high criticality and other critical sectors (Annex I and II of the Directive);
  • Medium-sized organisations (50 or more employees, or annual turnover/balance sheet total above €10 million);
  • Large organisations (250 or more employees, or annual turnover above €50 million combined with a balance sheet total above €43 million).

To help organisations determine whether they fall under the NIS2 Directive, the Dutch government has published the NIS2 self-assessment tool.

CER – physical security of critical infrastructure

The CER Directive, implemented nationally through the Critical Entities Resilience Act (Wwke), also enters into force on 15 August 2026. Where NIS2 focuses on digital risk, CER focuses on physical threats that can disrupt critical entities, such as sabotage, terrorism, supply chain disruptions, natural disasters and the failure of essential services. Organisations don't determine for themselves whether they are critical; this is decided by the responsible ministries based on risk assessments. Sabotage doesn't have to come from an external attack: an employee or contractor with legitimate access who deliberately disrupts a critical process also falls under the physical threats CER is designed to mitigate.

Organisations that fall under CER must:

  • Carry out risk analyses for physical threats
  • Draw up continuity plans
  • Implement security measures (access control, monitoring, physical hardening)
  • Report incidents
  • Cooperate with national authorities

CER and NIS2 overlap on key points: both call for structural attention to human factors, access rights, critical processes and incident response.

Insider risk as a key factor in NIS2 and CER compliance

Both NIS2 and CER name human factors as one of the biggest risks to critical infrastructure. That makes insider risk management not just sensible, but also a compliance matter.

Why insider risk is now central to both frameworks:

  • Insiders have legitimate access to systems, locations and processes.
  • NIS2 sets strict requirements for access management, monitoring and governance: all areas where insider risk plays a direct role.
  • CER focuses on physical sabotage and disruption, in which insiders often play a role.
  • Supply chain risk must be factored into the analysis: suppliers, contractors and temporary staff also fall under insider risk.
  • Incident response must be able to handle human incidents too, not just technical or physical ones.

Building resilience with Signpost Six

The implementation of NIS2 and CER makes one thing clear: organisations must not only strengthen their defences against external actors, but also structurally manage their insider risk. Signpost Six is already your partner in insider risk resilience, and once the obligations under this legislation affect your organisation, we're ready to support you. We help organisations prevent, detect and mitigate threats from insiders, whether intentional, negligent, or driven by external influence. We offer:

  • Insider risk asssessment, based on Signpost Six's holistic insider risk framework, measuring your insider risk maturity on 9 critical domains.
  • Design and implementation of an insider risk programme.
  • Training, awareness and behavioural change, through management training, awareness programmes, scenario exercises and workshops, focused on your organisation's threat landscape.
  • Support during insider incidents: from triage and investigation to remediation and reporting to regulators.

Conclusion

NIS2 and CER don't just make insider risk management more important; they make it mandatory. The 15 August deadline is a milestone, not the finish line. The real challenge starts after that: oversight, incidents, audits, and maturing your processes.