Cybersecurity Act on the Threshold: From Compliance to Chain Management

Jul 6, 2026

Readtime: 2 min

Cybersecurity Act: from compliance to governance

Op 6 en 7 juli 2026 behandelt de Eerste Kamer de Cyberbeveiligingswet (Cbw),
de Nederlandse implementatie van de Europese NIS2-richtlijn. Op 7 juli vindt de stemming plaats.
Bij goedkeuring treedt de wet naar verwachting medio augustus 2026 in werking.

For many organizations, this marks not a new IT project, but a structural change in how cybersecurity is managed, procured, and safeguarded within the chain.

What changes specifically?

De Cyberbeveiligingswet legt verplichtingen op aan naar schatting meer dan 8.000 organisaties in Nederland.
Deze verplichtingen gaan verder dan technische maatregelen en raken direct aan governance,
leveranciersmanagement en samenwerking.

  • Duty of care: organizations must demonstrably manage cyber risks.
  • Obligation to report: serious incidents must be reported in a timely manner.
  • Supply chain responsibility: risks at suppliers must be actively managed.
  • Executive involvement: boards of directors bear explicit responsibility.

This means that cybersecurity can no longer be organized in isolation within IT, but becomes part of contracts, sourcing choices, and supplier management.

The role of IT sourcing and contract management

The greatest impact arises precisely at the intersection of IT sourcing and governance. Many organizations depend on complex supply chains, in which risks are often located outside the direct view.

Effective implementation of the law therefore requires:

  • Clear contractual agreements regarding security, monitoring, and incident response.
  • Transparency in the supply chain, including insight into subcontractors.
  • Measurable performance indicators regarding cybersecurity.
  • Active supplier management aimed at continuous improvement.

Binnen een SIAM-model (Service Integration and Management) biedt dit een duidelijke kans:
integrale regie op zowel servicekwaliteit als security.

Want to know more?

Discover our services in the field of:

From obligation to strategic opportunity

Hoewel de Cyberbeveiligingswet vaak wordt gezien als een compliance-vraagstuk, biedt deze juist kansen
om structurele verbeteringen door te voeren:

  • Professionalisering van governance.
  • Better collaboration with suppliers.
  • Increased transparency regarding performance and risks.
  • Stronger position vis-à-vis customers and regulators.

Organisaties die vroeg investeren in deze volwassenheid creëren een duurzaam voordeel.
Niet doordat zij simpelweg voldoen aan wetgeving, maar doordat zij grip hebben op hun
digitale ecosysteem.

Practical first steps

  1. Map out whether and where the organization falls under the law.
  2. Inventory critical suppliers and dependencies.
  3. Update contracts regarding security requirements.
  4. Establish governance with clear roles and responsibilities.
  5. Integrate cybersecurity into existing ITSM and sourcing processes.

The role of SourceMinds

Bij SourceMinds ondersteunen wij organisaties bij het vertalen van wet- en regelgeving naar
werkbare oplossingen binnen IT-sourcing, contractmanagement en governance.

Niet als compliance-check, maar als structurele verbetering van regie, samenwerking en prestaties
binnen de keten.

Become NIS2 compliant?

Wilt u weten wat de Cyberbeveiligingswet betekent voor uw organisatie en hoe u regie houdt
over leveranciers, contracten en cybersecurity?

Contact us for a no-obligation consultation.

#sourceminds #itcontracting #itsourcing #itstrategy #contractlifecyclemanagement #itsm #siam #it aanbesteding #berkelenrodenrijs #rotterdamregio #denhaagregio

Get in contact

Reach out to us for any questions

Noordeindseweg 88, 2651CX Berkel en Rodenrijs

010 - 203 66 40