
July 20, 2026 - It took a little while, but on August 15, 2026, the NIS2 legislation, also known as the Cyber Security Act (Cbw), will finally take effect. These European rules for security and privacy will apply to all organizations in critical sectors in the Netherlands, such as hospitals and grid operators. Fortunately, complying with all the requirements is relatively simple. Follow our step-by-step plan and we will ensure you are compliant in no time.
Anyone falling under the Cbw is legally required to register in the entity register. If you are unsure whether this law applies to your organization, the NCSC has a handy self-assessment.
The NCSC looks at 10 measures to assess whether your security and privacy are in order. These are:
| Perform a risk analysis | Map out what risks could exist for your organization. Consider which interests and assets absolutely must be protected. |
| Set up incident response | There is always a chance things will go wrong. An Incident Response Plan (IRP) outlines how to act properly to limit as much damage as possible.
|
| Prepare for outages | It can happen that your systems experience prolonged outages due to an attack. How do you handle this? At Alcadis, we always advise, for example, having a backup 5G connection alongside your Wi-Fi connection, such as a RUTM50 from Teltonika. |
| Secure your supply chain as well | Map out your suppliers and determine whether they also have their security and privacy properly in order. |
| Get your cyber hygiene in order | Ensure your employees are well-informed on how to use your systems properly. Consider desk and screen policies, recognizing phishing, and performing updates. |
| Secure network systems | Make sure your network security is properly in order by utilizing built-in security tools from your network vendor, such as Cloudpath by RUCKUS. Alcatel-Lucent Enterprise (ALE) also has their network security properly in order. Planning to renew your network soon? Choose one of these two to be immediately compliant with NIS2. |
| Ensure personnel, access, and asset management | Segment network activities so guests and employees do not have access to the same data. This limits the impact of an attack. Both ALE and RUCKUS offer this capability within their Wi-Fi solution. |
| Use passkeys | We all know a password is a sensible tool for securing something, but did you know there are other methods nowadays? For example, ALE and RUCKUS both fully commit to Zero Trust. This means various things are looked at (IP address, language, etc.) to determine whether someone is allowed access to the network. |
| Establish a cryptography policy | By using encryption, you limit who can view data if they manage to gain access to the network. |
| Assess effectiveness | To measure is to know. Thoroughly test whether all these measures work. |
In addition to a registration and duty of care, organizations also have a reporting duty. Incidents can be submitted via mijn.ncsc.
Our advice is to start by realizing a good network on which all your systems and devices run. Do you already have a RUCKUS or Alcatel-Lucent Enterprise network? Then carefully check first whether all devices are outdated. If you still have a Wi-Fi 5 network – often installed before 2021 – it is wise, for example, to invest in Wi-Fi 7. Doing this with RUCKUS or ALE means you immediately comply with 70% of the Cbw requirements.
Curious about more information on how to become compliant for NIS2? Check out the Alcatel-Lucent Enterprise Best Practices PDF document or the slightly more comprehensive online brochure.
If you have a network other than RUCKUS or ALE, but it has been recently updated, there are also smart ways to get your network compliant nonetheless. Consider adding a SonicWall firewall or a backup 5G connection from Teltonika. Contact us to discuss the possibilities via sales@alcadis.nl or 030 – 65 85 125. We are also happy to think along with you, entirely without obligation, about the best course of action.