Identify the services, processes and information that matter most, and how much disruption the organisation can genuinely absorb.
Outside the Act? Resilience still matters.
The Dutch Cybersecurity Act takes effect on 15 August 2026. It applies to specific sectors and organisations — not to every business. Legal scope determines which duties apply; business risk determines the resilience that is structurally required.
Start with the right context
The Act is targeted. Digital risk reaches much further.
Whether the Act applies directly starts with the type of organisation and its sector. Size criteria will then usually matter. As an initial indication, the NCSC refers to 50 or more employees, or annual turnover or a balance-sheet total above €10 million. Specific exceptions exist, and complex organisational structures may require a different assessment. Use the official NCSC guidance and the RDI NIS2 Self-Assessment to establish your position.
What if your organisation is outside scope?
If your organisation is not in one of the designated sectors or organisation types, the Act does not apply to it. Its systems and operations still face digital risks. Strengthening security, continuity and recovery capability therefore remains a sound business decision.
The Digital Resilience Check looks only at that practical situation and is useful to every organisation.
NorthBridge does not start with a legal checklist or an isolated security product. We connect business and IT, provide independent risk judgement, and turn critical processes, cloud and supply-chain dependencies, technology, ownership and recovery capability into one practical improvement route.
Where improvement adds value
Four practical areas for every organisation.
Assign decisions, resources and follow-through clearly so digital risk does not fall between leadership, delivery teams and suppliers.
Keep systems, access, vulnerabilities and safeguards demonstrably current and prioritise them by business impact.
Practise detection, escalation, communications and recovery before disruption affects day-to-day operations.
The NorthBridge route
From business risk to manageable improvement.
We start with what the organisation must be able to keep delivering. From there, we connect risk, architecture, suppliers, safeguards and operations — with clear choices and a route that remains practical.
Business context
Critical services, processes and business impact determine where improvement will add real value.
Independent judgement
We assess risks and choices in the organisation’s interest, without making a preselected product the starting point.
Architecture and dependencies
Cloud, data, suppliers, access, continuity and recovery are assessed as one connected business and IT challenge.
Priorities and delivery
Risk and impact become concrete measures, ownership, investment choices and an achievable roadmap.
Embedded governance
NorthBridge remains involved in delivery, operations, supplier governance, assurance and demonstrable follow-through.
Proportionate measures based on risk
Technology follows context, risk and the existing architecture.
Technical measures support discovery, prevention, detection and recovery. Their value depends on a clear scope, appropriate configuration, expert interpretation and demonstrable follow-through. NorthBridge connects that technical practice to business impact and ownership.
A defined, authorised assessment identifies relevant vulnerabilities and translates them into risk, business impact and concrete mitigating measures.
Digital resilience →Segmentation, firewall policy, strong authentication and managed access reduce the attack surface and help protect critical systems.
Network & Security →Monitoring and IDS/IPS help identify anomalies and known threat patterns. Pre-assigned ownership, escalation and response determine what happens next.
Detection and network security →Data location, jurisdiction, concentration risk, supplier arrangements and a viable exit belong in the risk picture for critical services.
Cloud & Infrastructure →Structurally stronger
Let business risk determine what you improve with purpose.
Digital resilience requires continuous attention to continuity, dependencies, ownership and recovery. That matters to every organisation — whether or not the Act applies directly.
Official source basis
The commencement date and scope explanation are based on current information from the Dutch Government, NCSC and RDI. Always use the official channels when assessing your own position.