Summary
- The Dutch Cybersecurity Act implementing NIS2 entered into force on 15 August.
- Data centre services sit within NIS2's digital-infrastructure scope alongside cloud, DNS, and other critical services.
- Covered organisations now face risk-management, significant-incident reporting, and supervisory obligations rather than voluntary resilience guidance alone.
The Netherlands Enterprise Agency has confirmed that the country’s Cybersecurity Act implementing the EU’s NIS2 regime entered into force on 15 August, bringing new cybersecurity duties into effect across critical sectors including digital infrastructure.
Data centre service providers fall explicitly within the NIS2 framework. The EU definition covers services based on structures dedicated to the centralised accommodation, interconnection, and operation of IT and network equipment, together with the power-distribution and environmental-control infrastructure supporting those systems.
For covered Dutch organisations, the new regime introduces a duty of care, mandatory reporting of significant cybersecurity incidents, and regulatory supervision. Medium and large organisations operating in covered sectors are generally brought into scope according to the employee and financial thresholds set by the legislation, while certain smaller entities can also be designated where their services are considered particularly critical.
The duty of care requires organisations to assess cybersecurity risks and implement proportionate measures intended to protect networks and information systems, maintain services, and limit the effect of incidents. The regime therefore reaches beyond conventional perimeter security into business continuity, incident handling, supply-chain security, access control, vulnerability management, backup, disaster recovery, and governance.
That breadth is particularly relevant to data centres because their operational risk crosses physical and digital systems. A compromised management interface, network device, building-management platform, remote maintenance account, or supplier connection can affect the same availability objective as a failure in power or cooling.
NIS2 also changes the escalation timetable. The Netherlands Enterprise Agency says significant incidents must be reported to the relevant Computer Security Incident Response Team and competent authority, with an initial notification required within the statutory timetable. Under the NIS2 framework, early warning can be required within 24 hours, followed by further reporting as the incident is assessed.
Operators therefore need reporting processes capable of moving faster than a traditional post-incident review. Security teams, facility operations, senior management, legal functions, and suppliers need agreed thresholds for escalation before an outage or compromise occurs.
The technical baseline is also more prescriptive than a broad instruction to take reasonable cybersecurity measures. EU implementing rules covering data centre providers and other digital infrastructure entities set methodological requirements around risk analysis, incident handling, business continuity, crisis management, supply-chain security, vulnerability handling, cryptography, access control, asset management, and authentication.
The result is a closer connection between cybersecurity compliance and routine facility governance. Controls have to be documented, responsibilities assigned, supplier relationships understood, and evidence retained in a form that can withstand supervision.
The Dutch implementation arrives alongside the country’s Critical Entities Resilience framework, which also took effect on 15 August and addresses physical resilience for designated critical organisations. Digital infrastructure appears within both regimes, bringing cyber and physical continuity closer together at regulatory level.
That overlap fits the operating reality of data centres. Loss of a substation, fire, flood, sabotage, cooling failure, ransomware incident, or compromised control system can all produce the same outcome for customers: unavailable infrastructure. Separate engineering and cybersecurity teams increasingly have to demonstrate that their resilience assumptions join up.
The Dutch law has now moved those requirements from preparation into compliance. Operators within scope will need to establish not just that security controls exist, but that risk assessments, reporting routes, continuity arrangements, management oversight, and supplier controls are working as part of the site’s normal operating model.

