ITER/NLNetherlands
What the record establishes for the Netherlands: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.
Recipients
| Reached under | Body | Channel | Source |
|---|---|---|---|
| Data protection authorityGDPR, article 33 | Autoriteit Persoonsgegevens reported | — | edpb members |
| CSIRT or competent authorityNIS2, article 23 | The sectoral CSIRT and the supervisory authority, both reached by one report reported | https://mijn.ncsc.nlchecked 2026-09-03 MijnNCSC, the central reporting point. One report reaches the sectoral CSIRT and the supervisory authority at once. Entry needs eHerkenning at level EH2+, or Single Sign On Rijk for a government body, which is a prerequisite to obtain before an incident rather than during one. | ncsc nl meldplicht · ncsc nl mijnncsc |
| Financial supervisorDORA, article 19 | De Nederlandsche Bank reported | — | eba competent authorities |
| Market authorityMAR, article 17 | Autoriteit Financiële Markten (AFM) reported | — | esma mar nca |
Transposition of NIS2 reported
| Act | Cyberbeveiligingswet |
|---|---|
| In force | 15 August 2026 |
| Recipient | The sectoral CSIRT and the supervisory authority, both reached by one report |
| Moves a term | No. None found. The three stages are the Directive's own, «Vroegtijdige waarschuwing binnen 24 uur», «Melding binnen 72 uur», «Eindverslag binnen 1 maand na je melding», and the page states the anchor plainly: «De termijnen tellen vanaf het moment dat je kennis krijgt van het incident». |
| Standing | This is the NCSC's guidance on the act, not the act. What it adds to the Directive is the channel and the fact that one report discharges the duty to two bodies. |
| Source | ncsc nl meldplicht |
An event in the Netherlands
The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.
