Alessandro AleddaInsider Threat and Risk

ITER/NLNetherlands

What the record establishes for the Netherlands: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.

Recipients
4 of 4
Reporting address
Recorded
NIS2
In force 15 August 2026
Terms moved
No
Sources cited
5
Last read
3 SEPTEMBER 2026

Recipients

Reached underBodyChannelSource
Data protection authorityGDPR, article 33Autoriteit Persoonsgegevens reportededpb members
CSIRT or competent authorityNIS2, article 23The sectoral CSIRT and the supervisory authority, both reached by one report reported

https://mijn.ncsc.nlchecked 2026-09-03

MijnNCSC, the central reporting point. One report reaches the sectoral CSIRT and the supervisory authority at once. Entry needs eHerkenning at level EH2+, or Single Sign On Rijk for a government body, which is a prerequisite to obtain before an incident rather than during one.

ncsc nl meldplicht · ncsc nl mijnncsc
Financial supervisorDORA, article 19De Nederlandsche Bank reportedeba competent authorities
Market authorityMAR, article 17Autoriteit Financiële Markten (AFM) reportedesma mar nca

Transposition of NIS2 reported

ActCyberbeveiligingswet
In force15 August 2026
RecipientThe sectoral CSIRT and the supervisory authority, both reached by one report
Moves a termNo. None found. The three stages are the Directive's own, «Vroegtijdige waarschuwing binnen 24 uur», «Melding binnen 72 uur», «Eindverslag binnen 1 maand na je melding», and the page states the anchor plainly: «De termijnen tellen vanaf het moment dat je kennis krijgt van het incident».
StandingThis is the NCSC's guidance on the act, not the act. What it adds to the Directive is the channel and the fact that one report discharges the duty to two bodies.
Sourcencsc nl meldplicht

An event in the Netherlands

The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.