On 15 August 2026 — thirty days after this article publishes — the Cyberbeveiligingswet takes effect in the Netherlands. It is the Dutch implementation of NIS2, it covers more than 8,000 organizations across 18 sectors, and it arrives with no grace period for its three core duties: the zorgplicht (duty of care), the meldplicht (incident notification), and the registratieplicht (registration). The register is already open at mijn.ncsc.nl.
Buried in the supervisor's guidance is a detail that should be circled in red by every deal team: once registered, an entity has two weeks to report changes to its registration — and the RDI's own example of such a change is a merger. A deal doesn't just transfer shares. Under the Cbw, it starts a regulatory clock.
That's the argument of this article, part three of a series on what technical due diligence keeps missing: when you buy a company in scope, you don't buy its EBITDA and its order book with a punch-list attached. You buy its compliance state, live — and your own board now holds the accountability for it. The only question is whether that was priced.
The law changed what a target is
NIS2 — Directive (EU) 2022/2555 — pulls sectors into scope that deal teams historically treated as unregulated: alongside energy, transport and health, Annex II covers manufacturing of machinery, motor vehicles, electronics, electrical equipment and medical devices, plus chemicals and food production. In the Netherlands the Cbw makes that concrete on 15 August, together with its implementing decree, the Cyberbeveiligingsbesluit.
The RDI (Rijksinspectie Digitale Infrastructuur, the Dutch digital-infrastructure regulator) supervises the largest cluster of sectors — including all of Annex II manufacturing — alongside sectoral regulators in a ten-supervisor structure. The model differs by classification in a way that matters for deal risk: essential entities face proactive supervision — audits and checks without any incident having occurred — while important entities are supervised reactively. If your target is essential, the supervisor doesn't wait for something to go wrong before looking.
Who is personally liable under NIS2 and the Cbw?
The clause deal teams should read twice is Article 20(1) of NIS2, implemented in the Netherlands as Article 24 Cbw: the management body must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for the entity's infringements. This breaks from the familiar corporate-fine-only regime: the people who approve the risk framework can personally answer for its failure.
The Dutch enforcement toolkit makes it concrete. The RDI can impose orders and administrative fines — and per its own guidance, a fine or order subject to penalty payments can be directed at an individual board member. Executive board members carry a personal training obligation (to be met within two years of the law entering into force). And for essential entities, NIS2's Article 32(5) holds the sharpest instrument in the drawer: where earlier enforcement measures have failed, the supervisor can request the temporary suspension of a certification or authorization — or a temporary ban on a person at CEO or legal-representative level from exercising managerial functions in that entity. The corporate fines scale to the classification: member states must provide for fines reaching at least €10 million or 2% of worldwide turnover (whichever is higher) for essential entities — that's a floor on the maximum, not a ceiling — and at least €7 million or 1.4% for important ones.
For an acquirer, the transfer mechanism is the same one regulators established for data security — the Marriott precedent from part one of this series: a £18.4 million ICO fine for a breach that began in Starwood's systems two years before Marriott bought it, and a penalty notice stating that due diligence on acquired operations is "not time-limited or a 'one-off' requirement." Dutch law firm Loyens & Loeff spelled out the NIS2 version more than a year before the Cbw passed: acquiring a target that was previously out of scope "may trigger full NIS2 compliance post-acquisition, especially if IT systems are integrated," and the cost of bringing a non-compliant target up to standard "can materially affect deal valuation and integration planning." Note the trap inside that sentence: even a target that is out of scope today can be pulled into scope by your own integration.
The bill is quantifiable — so quantify it
"The target isn't NIS2-compliant" is a sentence I won't accept from a diligence team — it's not a finding you can price. A number is. Three anchors make the remediation bill estimable during diligence:
- The European Commission's impact assessment estimates that entities newly brought into scope face an increase of up to 22% of their ICT security spend in the first years (around 12% for those already covered under NIS1).
- ENISA's NIS Investments 2025 report (a survey of 1,080 professionals across EU organizations) puts median cybersecurity spend at €1.5 million, or about 9% of IT budgets — and names the hardest NIS2 requirements to implement: patching (50% of organizations), business continuity and disaster recovery (49%), supply-chain risk management (37%).
- Readiness is worse than sellers suggest. In a nine-country 2026 survey, only 16% of business leaders were confident they are fully compliant — and 11% of in-scope leaders weren't sure what NIS2 is. Aon's client assessments across EMEA average a 58% readiness score, with supply chain the weakest area at 37%.
Put the base rates together and the prior is obvious: the target you're diligencing is probably not compliant. The question the data room must answer is how far off it is, in euros and months.
Deals already reprice for this
The mechanism has precedent — the same Verizon–Yahoo repricing I cited in part two: $350 million off, pre-close, over breach disclosures. A compliance state, repriced. And the Forescout survey from part one applies with full force here: 53% of 2,779 IT and business decision-makers had encountered a critical cybersecurity issue during a deal that put it in jeopardy. What NIS2 changes is that the repricing logic now has a statute, a supervisor, and a personal-liability clause behind it.
The insurance market is moving the same direction. Warranty & indemnity underwriters are being told by their own trade body — the IUA, in a report published this month — to move "beyond passive reliance on standard cyber policies toward active interrogation" of cyber exposure in transactions. And insurance counsel at DAC Beachcroft expect exactly this regulation to reshape underwriting: NIS2's sanctions "can be severe and include fines and temporary disqualification from managerial roles," and underwriters may "reassess the questions asked on proposal forms." The W&I logic every dealmaker knows applies: gaps in diligence become gaps in coverage. An unexamined NIS2 posture is exposure nobody will insure on decent terms.
The three-step exposure sketch (week one of diligence)
This is the triage I'd run in the first week of any deal touching the 18 sectors — the companion to the five OT questions and the three AI questions from earlier in this series.
Step 1 — Scope determination, including the indirect routes. Is the target essential, important, or out of scope — and does that hold post-close? Check the Annex II manufacturing categories against the target's actual activities, check whether it's pulled into scope indirectly as a supplier to in-scope customers (Article 21(2)(d) makes supply-chain security the customer's regulated problem — and therefore the supplier's commercial one), and check whether your own integration changes the answer. Wrong scope determination is the cheapest severe error in this space. The falsifiable ask: request the target's mijn.ncsc.nl registration confirmation and its filing date (mandatory from 15 August) — or, before that date, ask who owns getting it filed. Either answer tells you whether scope has ever actually been determined.
One more asset most scope reviews miss: the asset-management duty doesn't stop at servers and PLCs. If the target runs copilots or AI agents with standing access to production or customer data, that access sits inside the Cbw's asset inventory too — whether the target's compliance team has noticed or not.
Step 2 — Gap headline against the Cbw Control Framework. Don't buy a generic maturity scan. The Auditdienst Rijk (ADR — the Dutch government's central audit service) and NOREA, the Dutch professional association of IT auditors, publish a free Cbw Control Framework — acknowledged by the NCSC and the Cbw supervisors, available in Dutch and English — which is as close as it gets to the control set an auditor or supervisor will reference. Running the target's evidence against it during diligence produces a defensible gap list in the auditor's own vocabulary, not a consultant's rainbow chart.
Step 3 — Convert the gap into a deal lever. Cost the gap list as a range using the anchors above (the 22% uplift, the 9%-of-IT-budget benchmark), then place it where it belongs: a price adjustment, an escrow or specific indemnity, a W&I carve-out negotiation, or a funded 100-day remediation plan. And put the regulatory clocks on the closing checklist itself: the two-week register update, and meldplicht readiness — 24 hours for the early warning, 72 hours for the notification, one month for the final report. If the target's incident-response plan can't hit those timelines on day one, that's an integration workstream you now own.
I don't take "NIS2-ready" on a seller's deck at face value, and neither should you. The register, the control framework, and your board's personal exposure all say the same thing: verify it, price it, or own it.
If there's a target in one of the 18 sectors on your desk — or you're the seller and would rather find the gap before the buyer does — that's a conversation, not a pitch.
Next in this series: converting technical findings into the deal model — why technical debt belongs in the purchase price, not the report appendix.
Sources & further reading
- Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf 15 augustus 2026 van kracht — Rijksoverheid, July 2026
- Registratieplicht (two-week change notification, merger example) — Rijksinspectie Digitale Infrastructuur, 2026
- Bestuurlijke verantwoordelijkheid en governance — RDI, 2026
- Toezicht en handhaving Cyberbeveiligingswet — NCTV, 2026
- NIS2 Directive, Article 20 (governance and liability of management bodies) — Directive (EU) 2022/2555 full text, 2022
- NIS2 Directive, Article 32 (supervision of essential entities, incl. temporary management ban) — Directive (EU) 2022/2555, 2022
- NIS2 Directive, Article 34 (administrative fines) — Directive (EU) 2022/2555, 2022
- Marriott International Penalty Notice — UK Information Commissioner's Office, October 2020
- Trends in Life Sciences M&A: Cybersecurity and AI take center stage — Loyens & Loeff, June 2025
- NIS Investments 2025 — ENISA, December 2025
- Navigating cybersecurity investments in the time of NIS 2 — ENISA, November 2024
- NIS2: Europe revamps its cybersecurity framework (EC impact-assessment cost estimates) — Clifford Chance, 2022
- NIS2 Research 2026 (16% confident fully compliant) — CyberSmart, April 2026
- Bridging the NIS2 Cyber Security Gap (58% average readiness) — Aon, August 2025
- Verizon–Yahoo amended agreement ($350M reduction) — SEC EDGAR, February 2017
- The Role of Cybersecurity in M&A Diligence — Forescout / GlobeNewswire, June 2019
- IUA report flags cyber coverage gap in W&I insurance — Insurance Business UK, July 2026
- NIS2 and DORA: cybersecurity regulation moves centre stage for insurers — DAC Beachcroft, December 2025
- Cbw (NIS2) Control Framework — ADR / NOREA, 2025