Martin Maas CISO
4 August 2026

NIS2 Cybersecurity Directive: what does it mean for CIOs in financial services and central government?

The Cybersecurity Directive makes the NIS2 directive legally binding in the Netherlands. The legislation touches governance, IT infrastructure and executive accountability, including personal liability for board members, fines of up to € 10 million and proactive supervision by national authorities. 

The stakes are highest for CIOs at banks, insurers, and central government organisations. This article explains what the law entails, which organisations fall within its scope, what the consequences of non-compliance are, and what preparation looks like for the sectors facing the greatest pressure. 

What is the NIS2 Cybersecurity Directive?

The Cybersecurity Directive is the Dutch implementation of the European NIS2 directive. It significantly extends regulatory oversight and imposes binding duty-of-care obligations on medium-sized and large organisations across digital infrastructure, financial services, healthcare, government and IT services. 

IT services encompass providers of infrastructure services, platform services, workplace environments, identity and access management (IAM) services and network services. Board members carry explicit responsibility for compliance, oversight and decision-making. 

The Senate approved the Cybersecurity Act (Cbw) and the Critical Entities Resilience Act (Wwke) on 7 July 2026. These laws will enter into force on 15 August 2026. Organisations that are not yet structurally prepared, are already at risk. They may need to revisit their planning cycles and budget rounds in order to achieve and demonstrably maintain compliance. 

"Essential entities fall under proactive supervision. Regulators enforce actively, even in the absence of an incident."

Which organisations fall under NIS2?

The law distinguishes between two categories of entity. That distinction determines the supervisory regime and the level of sanctions. 

Essential entities are organisations in sectors with the highest societal impact: 

  • Central government and public bodies 
  • Banks and financial market infrastructure 
  • Providers of digital infrastructure, including data centres and DNS services 
  • Energy, drinking water and transport 
  • Hospitals and healthcare institutions 

Essential entities fall under proactive supervision. Regulators enforce actively, even in the absence of an incident. Sanctions can reach € 10 million or 2% of global annual turnover, whichever is higher. 

Important entities include postal services, waste management and parts of the manufacturing sector. They fall under reactive supervision: enforcement takes place primarily in response to incidents. The maximum fine here is € 7 million or 1.4% of global annual turnover. 

For a CIO at a bank, insurer or government body, the conclusion is straightforward: the organisation is likely to fall into the most demanding category, with the most far-reaching obligations and the most rigorous oversight.

"The question is not whether the organisation needs to be compliant, but how much it costs if it is not."

Sanctions: the boardroom argument

Cybersecurity takes on a different weight when legislation ties fines to executive failings. For essential entities, the Cybersecurity Directive provides for the following sanctions: 

  • Fines of up to € 10 million or 2% of global annual turnover 
  • Temporary suspension of board members in cases of serious negligence 
  • Public disclosure of violations 
  • Mandatory external audits at the organisation’s expense

For a CIO who needs internal budget and mandate to invest in compliance, these figures are the strongest argument to put before the board. The question is not whether the organisation needs to be compliant, but how much it costs if it is not. 

Personal executive liability

One of the most significant elements of the Cybersecurity Directive is the personal liability of board members. This goes beyond organisational accountability: individual executives are personally liable when insufficient measures have been taken or when oversight of IT security is demonstrably inadequate. 

In practice, this means: 

  • Board members are required to be informed of the organisation’s cybersecurity risks 
  • Training and knowledge development are a legal obligation for both board members and supervisory directors 
  • Serious negligence can result in temporary exclusion from executive roles 

This is new and far-reaching. For a long time, cybersecurity was a technical domain with its own chain of responsibility. The Cybersecurity Directive makes it a core executive responsibility, with personal consequences when things go wrong. A board member who claims to have been unaware of IT risks is already in breach of the legal standard. 

An illustrative scenario: a mid-sized Dutch bank suffers a data breach through an outdated identity management system. The vulnerability had been flagged internally by the security team eight months earlier but never escalated to the board. During the supervisory meeting with DNB, the CIO states that he was unaware of the issue. 

Under the Cybersecurity Directive, that is not a defence, it is precisely the problem. The law requires board members not only to take appropriate measures, but also to actively stay informed of the organisation’s cybersecurity risks. A board member who was unaware of a known vulnerability has failed in their supervisory duty. The result: personal liability, a fine for the organisation and possible temporary exclusion from executive roles, even if the board member had no direct involvement in managing the system. 

Formal supervision and competent authorities

Once the Cybersecurity Directive enters into force, formal supervision by national authorities begins. Technical decisions around IT architecture, outsourcing and management will carry direct legal and governance consequences.

The law requires, among other things:

  • Risk management measures for digital infrastructure
  • Defined timeframes for incident reporting
  • Assessment of suppliers within the IT chain
  • Executive liability in cases of non-compliance

The supervisory framework is still being developed. The same applies to the further elaboration of the obligations arising from the NIS2 directive, on which decisions are still pending.

Relationship with the Baseline Information Security for Government (BIO)

The relationship with the Baseline Information Security for Government (BIO) deserves attention here. The BIO provides an existing security framework for government organisations, but does not fully cover the NIS2 obligations. For instance, the BIO does not prescribe explicit incident reporting deadlines, lacks a requirement for personal executive training and addresses chain responsibility less concretely than the Cybersecurity Directive demands. Government organisations seeking to comply with both frameworks will therefore need to supplement their existing BIO baseline. 

What the law assesses in your IT environment

The Cybersecurity Directive does not assess cloud usage in the abstract, it examines the design and governance of cloud infrastructure and underlying IT components. This includes:

  • Infrastructure as a Service (IaaS) for compute and storage
  • Platform services for application development
  • IAM for access control
  • Network segmentation and secure connectivity
  • Logging and monitoring for detection and reporting via a Security Information and Event Management (SIEM) system

Failure or compromise of these components is assigned a higher risk classification when it results in societal or economic impact.

"The crisis structure is not a document sitting in a drawer, it is a rehearsed process with named owners at board level."

Incident reporting and crisis structure

Serious cybersecurity incidents must be reported to the competent authority within strict timeframes: an initial notification within 24 hours, followed by a detailed report within 72 hours. This applies to incidents within infrastructure, platform services or identity systems.

This requires an established crisis structure with defined responsibilities, decision-making lines and communication arrangements at board level. Organisations that only start working out who does what during an incident are structurally too late. The crisis structure is not a document sitting in a drawer. It is a rehearsed process with named owners at board level.

An illustrative scenario: a ransomware attack takes down a bank’s payment infrastructure for 72 hours. Who reports to which authority, and when? And who is liable if the notification arrives late? Under the Cybersecurity Directive, the answer is clear: the affected organisation notifies the NCSC and DNB within 24 hours, followed by a detailed report within 72 hours. If the notification is late or missing, the board is personally liable. An organisation that has not worked through this scenario has no crisis structure and that is precisely what the law requires.

 

Demonstrable security and control

The law requires demonstrable effectiveness of security measures. Documentation and auditability carry as much weight as the technical measures themselves. This calls for established processes and technical controls such as:

  • Data encryption at rest and in transit
  • Centralised IAM with strong authentication
  • Separated environments for production and management
  • Continuous monitoring and logging via a SIEM
  • Periodic security testing
  • Defined reporting structures

Organisations that fall short here face not only technical risk but legal risk as well. The question a regulator will ask is not only whether a measure exists, but whether its effectiveness can be demonstrated.

Suppliers and chain responsibility

Outsourcing IT does not transfer ultimate accountability. The Cybersecurity Directive requires organisations to actively manage chain risks. This covers:

  • Selection and assessment of suppliers on security standards
  • Contractual arrangements covering security and audits
  • Transparency regarding sub-processors
  • Aligned procedures for incident handling

For organisations that have outsourced IT management, infrastructure or workplace environments to a Managed Service Provider (MSP), the following questions are directly relevant: what NIS2 compliance guarantees does the MSP provide? What audit rights are contractually established? And who notifies in the event of an incident?

NIS2 and DORA: the overlap CIOs cannot afford to miss

For CIOs at banks and insurers, the relationship between NIS2 and the Digital Operational Resilience Act (DORA) is the most complex part of the compliance puzzle.

For financial institutions, DORA serves as the primary regulatory framework. This means that the ICT risk requirements under DORA largely take precedence over the corresponding NIS2 obligations. The relevant supervisors here are De Nederlandsche Bank (DNB) and the Authority for the Financial Markets (AFM).

At the same time, financial institutions also fall under NIS2 for obligations that DORA does not fully cover, such as incident reporting to the NCSC and chain responsibility beyond direct financial services. The two regimes overlap but do not fully mirror each other.

In practice, this means the following for a CIO in the financial sector:

  • A security gap assessment comparing current IT measures against the requirements of both DORA and NIS2 is the logical first step
  • Reporting and notification obligations run through different channels: DNB and AFM for DORA, NCSC and CSIRT-DSP for NIS2
  • Chain responsibility applies under both regimes, but with different supervisory logic

A CIO at a bank or insurer who focuses exclusively on DORA will miss a portion of the obligations enforced under NIS2.

In summary: preparing for the Cybersecurity Directive

Preparation requires structural decisions made now, including:

  • An inventory of IT services and data flows
  • Classification of data based on societal and operational impact
  • A documented methodology for risk analysis
  • Alignment between IT, security, legal and executive leadership
  • Alignment with frameworks such as ISO 27001

In an earlier article on the delay to NIS2, we outlined actions organisations can take immediately.

These steps reduce legal and operational risk once the Cybersecurity Directive comes into force.

From preparation to a measurable security posture

Knowing which steps to take is one thing. Knowing where you stand right now is another. That insight is precisely what many organisations lack: security measures are in place, but demonstrability and prioritisation fall short.

A security gap assessment based on the CIS Controls (Center for Internet Security Controls) provides a structured starting point. This international framework maps the current security posture and reveals which measures are missing or insufficiently implemented, ordered by impact and urgency. That also makes it useful as input for board-level conversations: not a technical inventory, but a prioritised risk map.

It is also worth noting that annual penetration tests are no longer sufficient. The Cybersecurity Directive expects continuous insight into vulnerabilities, in the form of ongoing tests and scans that match the pace at which threats and IT environments evolve.

The combination of a gap assessment and continuous testing produces a prevention roadmap that structures measures across four levels: code, applications, infrastructure and organisation. The result is a methodology that is not only technically comprehensive but also aligned with the requirements of NIS2 and sector-specific regulation such as DORA and the BIO. Solvinity offers this approach through its subsidiary Securify, purpose-built for organisations that treat demonstrable compliance as their starting point.

Find out more

Would you like to know how the Cybersecurity Act applies to your organisation, what the overlap is with DORA or the BIO, or how Solvinity (and Securify) as a Managed Service Provider contributes to a demonstrably compliant IT environment? Contact Tim Kooij, Commercial Director at Solvinity, or visit our contact page.

Also read

More