
Cyber Security Act (NIS2) finalised: will your organisation be compliant, or truly cyber resilient?






After months of preparation, the moment has arrived: the Dutch Parliament has passed the Cybersecurity Act. This means the Dutch implementation of the NIS2 Directive will come into effect on August 15, 2026 .
For thousands of Dutch organisations, the law brings new legal obligations. But the impact goes further. Many suppliers and supply chain partners will also face these new requirements, as customers increasingly demand demonstrable proof that their cybersecurity is in order.
That sounds like a compliance issue. But that is only half the story.
What should you do now?
August 15 is not the time to start thinking about the Cybersecurity Act. Organisations must meet the legal requirements by that date. That is why we advise organisations to take the following steps now:
1. Determine if your organisation falls under the Cybersecurity Act
It is not just organizsations in vital and important sectors that fall under the law. Many suppliers and supply chain partners will also be indirectly affected by the obligations of the Cybersecurity Act, as customers or partners increasingly demand demonstrable cybersecurity measures that apply to the entire chain.
2. Register your organisation with the NCSC
Organisations that fall under the Cybersecurity Act are required to register with the National Cyber Security Centre (NCSC). This allows them to receive important information about threats, vulnerabilities, and incidents.
3. Map out your current situation
Do you have insight into which applications are being used, who has access to which systems, and whether this access is sufficiently secured? This insight forms the foundation for further improvements.
4. Assess your Identity & Access Management (IAM)
Check whether strong authentication, MFA, access policies, and account management are not only set up but also actively enforced.
5. Set priorities and get started
Start with the measures that provide the greatest risk reduction. Not just to comply with the law, but primarily to prevent cyber incidents. For many organizations, this means first gaining insight into their digital access security, enforcing strong authentication, and protecting employees against phishing and password abuse.
Passing an audit is not the same as being secure
In the coming period, many organizations will invest in policies, processes, and security solutions. That is an important step. However, a document on paper or a solution that is barely used does not immediately reduce the risk of a cyberattack.
There are still many misconceptions about the Cybersecurity Act. For example, organizations often think the law does not apply to them, that there will be little enforcement, or that cybersecurity is solely the responsibility of the IT department. In practice, the exact opposite is true.
At MindYourPass, we often say:
"The auditor sees policy. An attacker sees reality."
The goal of the Cybersecurity Act is not to check a box, but to make organisations within the supply chain genuinely more resilient.
How does MindYourPass help?
The Cybersecurity Act sets requirements for, among other things:
- Risk analyses and appropriate security measures
- Identity & Access Management (IAM)
- Inventory and management of assets and applications
- Access policy
- Multi-Factor Authentication (MFA)
- Cyber hygiene and security awareness
- Phishing prevention
- Encryption
MindYourPass supports organisations specifically in these areas by:
- Provide insight into the security of digital access protection
- Gain visibility into applications in use, including shadow IT
- Automatically enforce access policies
- Enable strong authentication with secure passwords, passkeys, FIDO2, and MFA
- Protect employees against phishing and account misuse
- Provide real-time insight into policy compliance, the adoption of security measures, and the organisation's cyber resilience
This is how we help organisations not only prepare for an audit, but more importantly, structurally increase their digital resilience.
From compliance to cyber resilience
At MindYourPass, we believe that good security doesn't have to come at the expense of ease of use. By making secure working simple, adoption increases and risks are genuinely reduced.
The Cyber Security Act is therefore not an end goal, but an opportunity to structurally improve how cybersecurity is organised.
Compliance is proof that you have taken measures. Cyber resilience is proof that they actually work.
Are you unsure whether your organization falls under the Cyber Security Act, or would you like to know how to strengthen online access security within your organization? We would be happy to help you think it through.
Get in touch with us.
Let MindYourPass make your organization safe.

Log in securely with ease.
At home and at work.


Triple-i™ improvement method
Wachtwoordveiligheid meten om doelgericht te verbeteren
Elke verandering begint met het verkrijgen van volledig inzicht in de huidige situatie. Om vanuit daar met behulp van een concreet en praktisch plan toe te werken naar de gewenste situatie: het gebruik van kwetsbare wachtwoorden binnen jouw organisatie onmogelijk maken.





