Skip to main content
Authority

Rijksinspectie Digitale Infrastructuur (RDI)

The RDI is the Dutch supervisor for digital infrastructure, trust services, telecom and radio equipment, and one of the supervisors under the Cyberbeveiligingswet, the Dutch implementation of NIS2, in force since 15 August 2026. Most licensed financial institutions are not supervised by the RDI: DORA takes precedence, and banking and financial market infrastructure sit with DNB and the AFM.

Checked by Remmert
5 min read

What is the RDI responsible for?

The RDI is the inspectorate for the Netherlands' digital infrastructure, operating under the Ministry of Economic Affairs. It supervises digital infrastructure providers, qualified trust service providers under eIDAS, telecom operators and radio equipment, and is the Dutch notifying authority under the Cyber Resilience Act. It was renamed from Agentschap Telecom in 2023. Its head office is in Groningen, with a second office in Amersfoort. Inspector-General Angeline van Dijk left on 30 June 2026, and no successor had been publicly announced when this page was written.

Last updated: 17 August 2026, two days after the Cyberbeveiligingswet entered into force. This page moves faster than the rest of the family: it runs on a 30-day review cycle rather than the usual quarter.

Key facts

Why does the Cyberbeveiligingswet mostly not apply to licensed financial institutions?

Because DORA is the more specific regime. The Dutch government states that DORA's provisions take precedence over both the Cyberbeveiligingswet and the Critical Entities Resilience Act for financial entities. In the Cyberbeveiligingswet's own table of sectors and supervisors, banking and credit sits with DNB and financial market infrastructure with the AFM, not the RDI.

A financial institution re-enters the RDI's scope only where it does something else as well: acting as a qualified trust service provider under eIDAS, or operating digital infrastructure such as DNS, cloud or a TLD registry. If a group contains such an entity, it registers and reports separately, under a different law, to a different supervisor.

When did the Dutch NIS2 law actually take effect?

15 August 2026, two days before this page was written, and roughly 22 months after the EU transposition deadline of 17 October 2024. The delay matters commercially: organisations that built compliance programmes to the EU deadline spent almost two years in a regime that had not yet started.

Registration is running behind. As at 13 August 2026, two days before entry into force, 2,942 organisations had registered with the NCSC, against an expected 8,000 to 10,000 in scope: under half.

Which rules does the RDI enforce?

RegulationThe RDI's roleStatus as at 17 Aug 2026

What does the RDI publish, and how often?

Guidance and sector assessments, a NIS2 self-assessment tool, state-of-digital-infrastructure reporting and consultations. The volume is far lower than the financial supervisors': the RDI is an inspectorate, not a rule-writer, and its output clusters around implementation moments rather than a fixed calendar. The self-assessment tool is the most-used artefact, and the one most often cited by Dutch organisations working out whether they are in scope.

Which deadlines does the RDI own?

Incident notification under the Cyberbeveiligingswet follows the NIS2 pattern: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month.

2026

  1. 15 August 2026Passed

    Cyberbeveiligingswet in force; duty of care and registration obligations begin

  2. 11 September 2026Upcoming

    Cyber Resilience Act incident-reporting duties start

2027

  1. 11 December 2027Upcoming

    Cyber Resilience Act fully applicable

What does enforcement look like?

The Cyberbeveiligingswet gives supervisors instruction, binding-order and fining powers, with ceilings set in the act. We have not observed a published enforcement measure yet: the law is two days old. What can be said with confidence is what the supervisors have said themselves: the first phase is registration and duty-of-care compliance, and the registration gap above (2,942 against 8,000 to 10,000 expected) is the number to watch, because it defines where the first supervisory attention will go.

What changes for a mid-sized institution?

Probably nothing directly, and that is the useful answer. An institution holding a DNB or AFM licence has its cyber and ICT-risk obligations run through DORA, with incident reports going to its financial supervisor. Two exceptions are worth checking in a group structure: an entity that provides trust services under eIDAS, and an entity that provides cloud, DNS or data-centre services to third parties. Either pulls that entity, not the whole group, into the Cyberbeveiligingswet and into a separate registration with the NCSC.

What we do with this

We track both regimes because the boundary between them is exactly where scoping mistakes happen: a group can be entirely out of NIS2 on its licensed entities and squarely in it on one subsidiary. Our model works from the legal entity and its activities, not from the group name, which is why the answer differs per entity and carries the article it comes from.

Regulations

  • Cyber Resilience Act (CRA)

    The Cyber Resilience Act is Regulation (EU) 2024/2847. Its reporting obligations under Article 14 apply from 11 September 2026, to every product with digital elements on the Union market, including products placed there before the Regulation's main obligations start on 11 December 2027. Actively exploited vulnerabilities must be reported within 24 hours.

    NextArticle 14 reporting obligations apply: actively exploited vulnerabilities and severe incidents

    Checked

  • EU Artificial Intelligence Act (EU AI Act)

    The EU AI Act is Regulation (EU) 2024/1689. On 2 August 2026 its transparency rules and enforcement machinery took effect, but the high-risk regime for credit scoring and life and health insurance pricing did not: Regulation (EU) 2026/1744 moved it to 2 December 2027. Prohibitions have applied since February 2025.

    NextNew Art. 5 prohibitions; Art. 50(2) marking deadline for pre-existing generative systems

    Checked

  • electronic Identification, Authentication and Trust Services (eIDAS2)

    eIDAS2 is Regulation (EU) 2024/1183, which amends Regulation (EU) No 910/2014. It contains no calendar deadline: wallet availability runs 24 months from the entry into force of five implementing acts, and private relying-party acceptance 36 months. Those acts entered into force on 24 December 2024, giving end-2026 and end-2027.

    NextMember States to provide at least one wallet (Art. 5a(1))

    Checked

  • Digital Operational Resilience Act (DORA)

    DORA is Regulation (EU) 2022/2554. It has applied since 17 January 2025 to 20 categories of licensed financial entity, from banks to crypto-asset service providers. It requires an ICT risk management framework, major incident reporting within 4 hours of classification, an annual register of ICT contracts, and threat-led penetration testing every three years.

    NextNext register of information cycle, reference date expected 31 December 2026

    Checked

  • Cyberbeveiligingswet (Dutch NIS2)

    The Cyberbeveiligingswet is the Dutch implementation of NIS2, Directive (EU) 2022/2555. It entered into force on 15 August 2026 and covers more than 8,000 organisations. Registration, the duty of care and the 24-hour and 72-hour reporting duties applied from day one. Banks are largely displaced to DORA by Articles 22 and 31, but their IT suppliers are not.

    NextArticle 40 NIS2 review of sectors, size criteria and entity types; every 36 months thereafter

    Checked