All articles
ComplianceCybersecurityGovernance

Which supervisor regulates your organization under the Dutch NIS2 law?

Germany has the BSI. Belgium has the CCB. The Netherlands has seven authorities, and which one you get depends on what you do.

Ilke Tosunoğlu
Ilke Tosunoğlu6 min readUpdated
The seven supervisory authorities under the Dutch Cyberbeveiligingswet, mapped across the sectors.

The Dutch Cyberbeveiligingswet has no single regulator. Seven authorities share supervision by sector: the RDI, ILT, DNB, AFM, NVWA, ANVS and IGJ. Which one looks at your organization (and how closely) depends on your sector and on whether you are an essential or an important entity.

Last verified: 16 August 2026.

Which supervisor applies to my sector?

Sector Annex Supervisor Supervision style Where to look
Digital infrastructure 1 RDI Proactive (essential) rdi.nl
Energy: electricity, district heating and cooling, gas, oil, hydrogen 1 RDI Proactive (essential) rdi.nl
ICT service management: MSPs and MSSPs 1 RDI Proactive (essential) rdi.nl
Government: ministries, agencies, provinces, municipalities 1 RDI Proactive (essential) rdi.nl
Space: ground infrastructure 1 RDI Proactive (essential) rdi.nl
Postal and courier services 2 RDI Reactive (important) rdi.nl
Manufacturing: non-medical 2 RDI Reactive (important) rdi.nl
Digital providers: marketplaces, search engines, social networks 2 RDI Reactive (important) rdi.nl
Research 2 RDI Reactive (important) rdi.nl
Transport: air, rail, water, road 1 ILT By entity class ilent.nl
Drinking water 1 ILT By entity class ilent.nl
Wastewater 1 ILT By entity class ilent.nl
Water management 1 ILT By entity class ilent.nl
Chemicals 2 ILT Reactive (important) ilent.nl
Waste management 2 ILT Reactive (important) ilent.nl
Meteorology ILT By entity class ilent.nl
Banking 1 DNB By entity class dnb.nl
Financial market infrastructure 1 AFM By entity class afm.nl
Food 2 NVWA Reactive (important) nvwa.nl
Nuclear ANVS By entity class anvs.nl
Healthcare 1 IGJ By entity class igj.nl
Manufacturing of medical devices 2 IGJ Reactive (important) igj.nl

Sources: NCSC: supervision, RDI: sectors under supervision, ILT, NCSC brochure (PDF). Last verified 16 August 2026.

Two caveats we would rather state than paper over:

  • The essential/important labels are published by the supervisor itself only for the RDI sectors. For the others we infer the column from the annex in which the sector sits. That is a strong indication, not an official classification by that authority.
  • Water boards (waterschappen) fall under ILT on our reading. RDI lists them there, and the government-sector regulation explicitly excludes them. Note a common confusion: CERT-WM is the water boards' CSIRT, which is a different role from supervisor. A CSIRT receives reports and assists; a supervisor enforces.

Registration runs through the same portal for everyone: Mijn.NCSC.nl, with eHerkenning at level 3. The supervisor differs; the register does not.

Why is supervision split across seven authorities?

Because the Netherlands chose to place cyber supervision with the authorities that already know each sector, rather than with one new agency.

That is a genuine policy choice and not the only one available: Germany routes almost everything through the BSI, Belgium through the CCB. The Dutch model produces supervisors who understand the sector, but it also means a group active in two sectors deals with two regulators, each with its own emphasis, questionnaires and timetable.

What is the difference between proactive and reactive supervision?

Essential entities can be visited without an incident; important entities are generally looked at only after something has happened.

The RDI is explicit: "Voor essentiële entiteiten geldt proactief toezicht. De RDI kan bijvoorbeeld om informatie vragen of bij u langskomen." (proactive supervision applies to essential entities, and the RDI may request information or visit). For important entities, supervision "vindt … voornamelijk achteraf plaats", largely after the fact (RDI).

The Act mirrors the split: enforcement against essential entities sits in §15.2 (art. 70–80), against important entities in §15.3 (art. 81–87), with a separate paragraph for domain name registration service providers (§15.4).

What does that mean in practice for essential entities?

That your evidence has to be presentable at any moment, not only after an incident.

Under reactive supervision you get a trigger and some time. Under proactive supervision the request itself is the trigger. The difference is not in what you need (the duty of care is identical) but in how quickly you can show it. Organizations that reconstruct their evidence once a year for the auditor feel this most.

What if we operate in two sectors?

You may face two supervisors, and each activity is governed by its sector's regime.

A hospital that also manufactures medical devices sits with IGJ twice, in two different classes. An energy company running its own data center service sits with RDI twice. It gets harder across authorities: a transport operator (ILT) with an in-house MSP arm (RDI), for instance. In practice the heaviest classification and the strictest supervision style set your pace.

If you are designated a critical entity under the Wwke, article 8 of the Cbw makes you an essential entity by operation of law, whatever the sector table suggests.

Where Soveryne fits

Two supervisors rarely means twice the security work, but it does mean twice the evidencing work. Soveryne Command maps controls once to assets and to the requirements of NIS2, ISO 27001 and DORA, so the same evidence answers more than one questionnaire. That is precisely the problem split supervision creates.

Frequently asked questions

What if my organization is active in two sectors? Each activity follows its sector's regime, so you may deal with more than one supervisor. In practice the heaviest classification sets your pace.

What does the RDI do proactively versus reactively? Proactively for essential entities: information requests and visits, with no incident required. For important entities it generally acts after an incident or signal.

Who supervises MSPs and MSSPs? The RDI. ICT service management sits in Annex 1 and the RDI classifies the sector as essential, so a managed service provider can expect proactive supervision even without an incident.

Does my supervisor change if we grow? No. Your supervisor follows your sector. What can change is your classification: growth can move you from important to essential, and so from reactive to proactive supervision. Changes to registered details must be reported within two weeks.

Sources

Further reading