Dutch companies must implement the NIS2 Directive from 15 August 2024, affecting approximately 8,000 organizations and mandating strict cybersecurity standards.
The perceived shortage of skilled cybersecurity professionals is symptomatic of organizational and strategic deficiencies, not primarily a personnel recruitment problem.
NIS2 obligates operators of critical infrastructures and essential services to comply with enhanced cybersecurity standards by 3 October 2026; non-compliance carries penalties of up to €10 million.