NIS2 and Cybersecurity Obligations for SMEs: What You Need to Know
NIS2 may sound like a concern for large corporations and utilities, but for many SMEs and freelancers the reality is more nuanced. Through the Dutch Cybersecurity Act (CBW), expected to take effect on 15 August 2026, a significant number of businesses will face direct obligations. Everyone else will feel the pressure through their clients. Here is what it means in practice.
This article does not constitute legal advice: consult a qualified legal or compliance adviser for your specific situation.
What Is NIS2 and Who Is Directly Affected?
NIS2, the second EU directive on network and information security, replaces its predecessor and sets significantly stricter requirements. In the Netherlands it becomes the Cybersecurity Act (CBW), targeting organisations in critical sectors: banking, utilities, healthcare and Managed Service Providers (MSPs).
According to the CBW explanatory memorandum, direct obligations apply if your organisation operates in such a sector and exceeds certain thresholds (generally: more than 50 employees or more than €10 million turnover). Smaller businesses are formally exempt, but that is only half the story.
| Organisation type | Direct CBW obligation? | Indirect pressure via supply chain? |
|---|---|---|
| Bank / utility / MSP | Yes | Yes |
| SME supplier to NIS2-obligated client | No | Yes, via contractual requirements |
| Freelancer as IT supplier | No | Yes, client sets the terms |
| SME without critical-sector clients | No | Limited |
Supply Chain Responsibility: Why SMEs Are Still Affected
Suppose you work as an IT consultant providing managed services to a regional energy company. That energy company falls under the CBW and, under the CBW explanatory memorandum, has a statutory duty of care and incident reporting obligation, including requirements towards its suppliers. Your client can contractually require you to meet specific security standards: encryption, access management, incident reporting.
This is what experts call 'indirect NIS2 impact'. You are formally outside the law, but your client is not, and they will pass requirements downstream.
In practice this may mean:
- Contractual security clauses to sign before starting an engagement
- Mandatory documentation of your security measures
- Audits or questionnaires from your client
- Risk of contract loss if you cannot demonstrate secure working practices
For freelancers and small IT suppliers this is legally relevant grey territory. It is also worth reading about the Dutch DBA Act 2026, where your relationship with clients is equally critical.
What Should You Arrange Now?
August 2026 may seem distant, but preparation takes time, especially when clients ask for proof of adequate security. Practical steps:
1. Map your risks What data do you manage? Which systems are critical? Even a simple inventory is a strong starting point.
2. Review your contracts Check existing agreements for security clauses. More organisations are adding NIS2-related provisions to new contracts.
3. Get the basics right Strong passwords plus MFA, regular updates, restricted access rights and a basic incident process. These are the first things clients check.
4. Make compliance demonstrable NIS2-obligated clients want evidence, not promises. Document your security measures and your work processes. Accurate time tracking as a freelancer is part of the professional administration clients increasingly evaluate when selecting suppliers.
5. Consider additional certification ISO 27001 or NEN 7510 (healthcare) are not legally required for SMEs, but may strengthen your position with NIS2-obligated clients.
Try PrikKlokPlus for free and get your administration in order, so you have instant proof of your work processes at every audit.
What Does This Mean for Your Business Operations?
Compliance starts with visibility. NIS2, directly or indirectly, demands demonstrably responsible conduct. That reaches beyond your IT systems: your administrative processes will also be scrutinised.
Structured time registration supports:
- Transparency for clients about work delivered and system access
- Audit trails showing which team member worked on what and when
- Project management aligned with your client's security requirements
With tools like PrikKlokPlus you not only log hours, you also build the administrative foundation that professional clients expect. See also how sprint planning and backlog management contribute to structured project administration.
Wondering whether your current time tracking meets client expectations? Read whether time tracking is legally required in the Netherlands and what you should record as a minimum.
Conclusion
NIS2 affects Dutch SMEs in two ways: directly, if you operate in a critical sector, and indirectly, through your clients' supply chain obligations. With the CBW expected to arrive on 15 August 2026, now is the moment to strengthen both your security posture and your administrative processes. Do not wait until a client sends you a questionnaire.
Frequently Asked Questions about NIS2 and SMEs
Does NIS2 apply to me as a freelancer? Not directly. The Cybersecurity Act targets organisations above certain thresholds in critical sectors. However, if you supply a NIS2-obligated organisation, that client can contractually require specific security measures from you. Consult a qualified adviser for your specific situation.
What happens if I do not meet my client's requirements? It depends on your contract. In the worst case you risk losing the contract or being excluded from tenders. NIS2-obligated organisations are, under the directive, responsible for the security of their supply chain and may remove suppliers who cannot demonstrate adequate security.
When does the Dutch Cybersecurity Act take effect? The expected date is 15 August 2026, though you should verify this against the official publication in the Dutch Government Gazette (Staatsblad).
What is the difference between NIS2 and the Cybersecurity Act? NIS2 is the EU directive. The Cybersecurity Act (CBW) is the Dutch implementation in national law, adding specific Dutch enforcement mechanisms and procedural rules.
How can I as an SME demonstrate compliance with security requirements? Start with documentation: record which measures you take, who has access to which systems, and how you handle incidents. Structured project administration and time tracking provide supporting evidence.
Get Your Administration in Order Today
Demonstrating professionalism starts with structured processes. PrikKlokPlus helps you make hours, projects and access transparent, exactly what clients expect.
