Cybersecurity Act also affects the food chain
Ondernemers sociëteit voedingsindustrie
B2B Communications
Wallbrink Crossmedia
Check this out

Cyberse­cu­rity Act also affects the food chain

  • 16 July 2026

The Cybersecurity Act will enter into force on August 15, 2026. This gives the Netherlands a national implementation of the European NIS2 Directive. Organizations in essential and important sectors will face stricter requirements for information security, governance, and risk management. Companies that supply these organizations may also be affected.

National implementation of NIS2

The House of Representatives adopted the bill for the Cybersecurity Act on April 15, 2026. The Senate approved the law on July 7, 2026. This means the law will enter into force on August 15, 2026.

NIS2 stands for the Network and Information Security Directive. This European directive aims to strengthen the digital resilience of member states. Organizations in essential and important sectors will face stricter cybersecurity requirements. Whether an organization falls under the law depends on several factors. Sector, size, and activities all play a role. The government has developed a self-assessment tool. This allows organizations to check whether the law applies to them.

New obligations

Organizations that fall under NIS2 must be able to show they have taken appropriate measures. This applies to information security and business continuity management. Among other things, the law introduces management liability. It also includes an explicit duty of care. Serious cyber incidents with societal impact are subject to a reporting obligation. A training obligation also applies.

Requirements for suppliers

The law also affects organizations outside the direct target group. Companies that supply products or services to organizations under NIS2 may face supply chain responsibility.

Under NIS2, organizations must set appropriate requirements for suppliers. They must also monitor the correct implementation of measures. This is based on the risks within the services provided. This is relevant for supply chain parties in the food industry. The law calls for preparation in cybersecurity, governance, and risk management.

Dnv.nl

Source: DNV