NIS2 is a directive, not a regulation, which means the version that binds you is not the one in Brussels. It is the one your national parliament passed — late, in the case of the Netherlands and Ireland, and with a supervisory structure the directive never described.
Both countries missed the 17 October 2024 transposition deadline by a wide margin. The Netherlands drew a reasoned opinion from the European Commission in May 2025 for the delay. Ireland was still moving its transposing bill through the Oireachtas well into 2026. For an in-scope firm operating in either market, that lateness is not an excuse to wait. It is the reason you have to read the national instrument rather than the directive, because the national instrument is where the competent authority, the sector cuts and the registration mechanics are actually decided — and the two countries decided them differently.
Two late transposers, two different machines
The directive gives you a baseline: risk-management measures under Article 21, incident reporting under Article 23 on a 24-hour early warning, 72-hour notification and one-month final-report cadence, management-body accountability, and registration on a national register. That baseline is real, but it is not what a supervisor inspects. A supervisor inspects the national law, and the national law names who they are, what threshold pulls you in, and how the reporting flows. Get the baseline right and the national mapping wrong, and you have built controls for a regulator who will never call — while the one who does call finds you unregistered.
Free · 4 minutes
Do you know where AI is already being used in your business — and what it can see?
Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.
The Netherlands: one law, a fan of supervisors
The Dutch transposition is the Cyberbeveiligingswet (Cbw). It was adopted on 7 July 2026 and, on the published timeline, entered into force in mid-August 2026 — confirm the exact commencement date against the official Staatsblad publication before you rely on it, because Dutch commencement dates move. Scope follows the directive’s size-cap logic: broadly, entities of 50 or more staff, or with turnover and balance-sheet totals above the medium-enterprise thresholds, operating in the listed sectors. That pulls in the order of several thousand Dutch organisations that had no cyber-specific supervisor before.
The technology-relevant point is not the duty of care — that is recognisable to anyone who has run an ISO 27001 programme. It is the supervision. The Netherlands did not create a single cyber regulator. Oversight is distributed across sector authorities: the Rijksinspectie Digitale Infrastructuur (RDI) for digital infrastructure and digital providers, De Nederlandsche Bank for financial entities, and a spread of ministry-appointed regulators across the remaining sectors. The government publishes a referral tree — the Doorverwijsboom — precisely because a firm cannot always tell from its own activity which authority owns it. The NCSC-NL sits at the centre as the national CSIRT and the destination for incident notifications, but it is not your line supervisor unless your sector lands there.
So the first Dutch task is not writing a policy. It is determining, in writing, which authority supervises you, registering with the NCSC-NL by the stated deadline, and wiring your incident process to the 24-hour early-warning clock. A firm that assumes “the NCSC handles it” and never identifies its sector regulator has a governance gap, not a technical one.
Ireland: a lead authority the directive never asked for
Ireland’s route is the National Cyber Security Bill 2024, built on a General Scheme published on 30 August 2024. Treat its provisions as provisional until the Act is signed and commenced: verify the final text and any commencement order rather than the general scheme or early commentary, because scope thresholds and reporting detail can shift between scheme and statute.
Ireland also chose a federated model — multiple competent authorities by sector rather than one — but layered something on top that the directive does not require. It designates the National Cyber Security Centre as both the single point of contact and a lead competent authority, a coordinating role adopted as a domestic policy choice after engagement with the sector regulators. Underneath sit the familiar Irish supervisors: the Commission for Regulation of Utilities for energy and water, ComReg for digital infrastructure and ICT service management, the Central Bank of Ireland for banking and financial-market infrastructure, the Irish Aviation Authority, the rail and road transport bodies, and health-sector authorities. The NCSC catches the sectors no one else owns.
The practical consequence is that an Irish firm can face a sector regulator it already knows for prudential or safety matters — the Central Bank, say — now also holding a cyber remit, while the NCSC coordinates across the whole. If you already track the Central Bank of Ireland’s operational resilience expectations, NIS2 does not replace that relationship; it adds a cyber-specific overlay administered partly by the same body and partly by the NCSC. The mapping matters most where a firm sits across sectors — a med-tech manufacturer running its own digital infrastructure, for instance, where the interaction between IT governance and sector-specific oversight is already delicate.
Where the local law diverges from the baseline
Three divergences do real work, and none of them is in the directive’s own text.
Self-identification is the entity’s job. Neither country hands you a letter confirming you are in scope. You register because you have determined you are caught. Get that determination wrong — too narrow — and you are unregistered when the regulator arrives, which under both regimes is itself a breach with turnover-linked penalties (broadly up to 2% of worldwide turnover for essential entities, 1.4% for important ones).
The competent-authority map is national, not deducible. In the Netherlands you may need the Doorverwijsboom to find your supervisor. In Ireland you may answer to a sector body and coordinate with the NCSC. Neither can be inferred from the directive; both have to be read off the national instrument and recorded.
The clock lives locally. The 24/72/one-month cadence is common, but the channel, the language of submission and the portal are national. An incident runbook that names “the CSIRT” generically will stall at 3 a.m. when someone has to file.
For a group operating in both, the temptation is to build two compliance stacks. The better move is one control set mapped to each jurisdiction’s supervisor and reporting channel — the approach I set out in building one control set that satisfies multiple member states. The controls are largely common; the routing is not.
Who this is for
- The CTO of a Dutch or Irish entity that has never had a cyber supervisor and is not certain which one it now has.
- The group security lead running one estate across both markets who needs the routing right without duplicating the controls.
- The compliance owner who has read the directive and assumed it applies as written. It does not; the national law does.
The directive is the easy part to read. The expensive mistake is assuming it is the part that binds you.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming