KPMG Netherlands urges clients to move from NIS2 interpretation to action
KPMG Netherlands says NIS2 work has moved past interpretation. Clients now need scoped controls, supplier oversight, incident reporting, and evidence that can stand up to scrutiny.

The Dutch Senate approved the Cyberbeveiligingswet on July 7, 2026, and it is set to take effect on August 15. For KPMG Netherlands and its clients, the task is no longer treating NIS2 as a legal reading exercise. The focus has shifted to turning policy into controls, ownership, reporting lines, and proof that will survive supervisory review.
From directive to delivery
NIS2 has been moving toward implementation for years, but the pressure point has changed. The EU directive entered into force on January 16, 2023, and member states were supposed to transpose it by October 17, 2024. The European Commission then published its implementing regulation on October 17, 2024, setting technical and methodological requirements for relevant entities, while ENISA followed with its Technical Implementation Guidance on June 26, 2025, built around practical advice, evidence examples, and mappings of security requirements.
The early work was about reading the directive and deciding who fell inside scope. The current work is about proving readiness, one control, one workflow, and one documented responsibility at a time. For KPMG cyber, risk, and technology teams, that means demand is moving toward implementation support rather than broad policy interpretation.
The questions clients now have to answer
The same issues keep surfacing when organizations try to operationalize NIS2. The first is scope: firms need a defensible view of which entities, systems, and business lines are covered, and where a group structure creates overlap or blind spots. That is especially important in large multinational organizations, where one country’s compliance decision can trigger work across legal, IT, procurement, and resilience teams.
The second issue is supply-chain dependency. NIS2 does not stay inside the four walls of the firm, and that is where many compliance programs get stuck. Companies now have to translate supplier risk into contract language, escalation triggers, third-party controls, and evidence that key vendors are monitored rather than merely acknowledged.
The third issue is accountability. Accountability depends on someone owning the policy, reviewing it, and explaining it to management or a regulator. In practice, that means clearer reporting lines, a named control owner, and board-level visibility over the risks that NIS2 is designed to surface.
The fourth issue is incident reporting. Organizations cannot just say they have a response plan; they need operating procedures that tell teams when an event becomes reportable, who decides, what timestamps are captured, and how the record is preserved. The fifth is evidence. Supervisory scrutiny will not be satisfied by a slide deck or a policy PDF; firms will need logs, test results, meeting records, training completion data, and remediation trackers that show the control worked, not just that it was written down.
A practical NIS2 response now has to include:
- a scoped inventory of covered entities, services, and systems
- named owners for incident response, supplier oversight, and board reporting
- tested playbooks for escalation and regulatory notification
- evidence packs that show controls were designed, operated, and reviewed
- governance routines that keep remediation open items from drifting
What this means for KPMG teams
Inside KPMG, the shift from interpretation to execution changes the shape of the work. Cyber advisory cannot run this as a standalone legal translation project. Clients need legal, IT, procurement, resilience, and management functions in the same room, because NIS2 is really an operating-model issue. That makes the work more cross-functional, more document-heavy, and more demanding on the people who can connect technical controls to board reporting.
The strongest proposals will not just explain the rule set; they will lay out a remediation roadmap. That means showing how a client will build a control framework, test it, document it, and keep it current. It also means talking in practical terms about supplier risk, incident escalation, evidence packs, and whether a control is actually effective instead of merely described in a policy.
The professionals who can bridge regulation, technology, and governance are the ones who become useful on these accounts quickly. In a Big 4 environment, that often means more responsibility earlier, but it also means more pressure to translate abstract requirements into deliverables that stand up in an audit trail.
Why the Dutch timetable raises the stakes
Official government materials put the number of affected organizations at more than 8,000 in the Netherlands, and the law will replace the current Wbni framework, so the compliance population is broad enough to create real delivery volume across industries.
NIS2 covers sectors including energy, transport, banking, healthcare, drinking and wastewater, food, and digital infrastructure. It also distinguishes between essential and important entities, with stricter supervision for essential entities. That distinction will affect how companies prioritize their remediation work, how they prepare for supervision, and how much board attention the program gets.
The law will be implemented through the main bill, a Cyberbeveiligingsbesluit, and sector-specific ministerial rules. Those secondary rules will sharpen duties such as the care duty, registration duty, and the training duty for directors.
This article was produced by Prism’s automated news system from verified source data, official records, and press releases, then run through automated quality and moderation checks before publishing. The system is built and supervised by the people who set the standards it runs under. Read our full AI policy.
Did this article answer your question?


