This is analysis for marketing and technology leaders, not legal or security advice. Confirm your own scope and obligations with qualified counsel.
The first few times I heard the advertisements on BNR, I assumed the government had started a public information campaign. They turned out to be cybersecurity vendors selling NIS2 readiness scans before breakfast. The timing makes sense. The Cyberbeveiligingswet, the Dutch implementation of the European NIS2 directive, takes effect on 15 August 2026.
So what does marketing actually need to do?
Start with the customer systems you already run. How much data can one account reach? Who can export it? Would anyone notice unusual behaviour, and does the team know who to call that day? Tooling may be useful later, once those ownership questions have answers.
Who does the Dutch law apply to?
The Cyberbeveiligingswet applies in the Netherlands. Around 8,000 organisations are expected to fall within its direct scope, mainly medium-sized and large entities across eighteen designated sectors, among them energy, transport, banking, health, drinking water, digital infrastructure and government. A few categories are covered whatever their size, including providers of public electronic communications networks and services, trust service providers, DNS and domain registration services, and government bodies.
Scope is assessed at the level of the legal entity, based on the type of organisation, its sector and its size. Marketing is therefore never classified on its own. In an international group that distinction does more work than it looks like: a Dutch entity can be regulated while the same CRM and marketing stack serves half a dozen countries. The NCTV publishes the criteria, and the entity-level question is where the conversation should start.
What changes on 15 August
The Cyberbeveiligingswet arrives alongside a separate resilience law for critical entities, which is the one that matters far less for marketing and MarTech. For organisations inside its scope, four things become law at once.
A duty of care. Run a risk analysis, then take appropriate and proportionate technical and organisational measures. The duty explicitly includes risks in the supply chain.
A registration duty. Register in the national entity register maintained by the NCSC.
A reporting duty, in three steps. An early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month of that notification.
Governance duties for the board. Management approves the cybersecurity measures, and board members carry statutory knowledge and training obligations. They have two years to meet the formal training requirement; everything else applies from 15 August.
Supervision is split by sector, so a bank answers to DNB, a hospital to the IGJ, a telecoms or digital infrastructure business to the RDI. Maximum fines reach 10 million euro or 2% of worldwide turnover for essential entities, and 7 million or 1.4% for important ones.
Read that list from a marketing seat and most of it turns out to be about ownership, decision rights and evidence rather than about technology choices.
Directly regulated, indirectly reached
The legal duty stays with the regulated entity. The requirements travel through procurement. A regulated organisation cannot outsource its duty of care, so it passes the expectation outward instead, through contract clauses, security questionnaires, access reviews, audit rights, incident notification terms and evidence requests.
For marketing that usually pulls CRM and marketing automation platforms, CDPs, agencies, implementation partners, data vendors, integrations, managed services and increasingly AI providers into the review. An agency or MarTech supplier can also be directly in scope in its own right, depending on what it delivers, since managed service providers can qualify.
If your customers are regulated, you are already in that conversation.
What this looks like from the inside
The uncomfortable part of an access review is how ordinary the findings are.
Someone leaves, loses their work email, and keeps a working Marketo login, because that account was created with an email and password instead of through single sign-on and offboarding never saw it. An intern has admin, because the role that matches the actual work does not exist. The web development agency hired to update landing page templates has admin too, because the web designer role stops just short of what the job needs. And a handful of API keys nobody can attribute to a system anyone still uses.
Nobody decided that any of this was acceptable. It survives because no one reviews it on a schedule, nothing alerts when it is used oddly, and no one owns the problem.
I once made that concrete for a client by using those rights rather than describing them, with a single recipient and the explicit purpose of closing the finding. An intern with far too much access sent his own manager an internal email carrying a 70% discount code. It reached that one manager and nobody else, and it landed as a joke, but it looked completely genuine because technically it was: the same platform, the same template, the same sending domain. The same account could have reached the full database.
A Dutch date inside a European operating model
15 August is a Dutch implementation date. The European deadline was October 2024, and on 8 July 2026, five weeks before the Dutch law took effect, the Commission referred the Netherlands to the Court of Justice, alongside Ireland, Spain and France, for failing to transpose NIS2 in time.
One directive therefore produces several national realities: different registers, different supervisors, different scope interpretations, around one centrally operated technology stack. The tracking pixel rules had the same shape, where a European principle met national execution and Marketing Operations was left to translate the difference into configuration.
The management question is whether there is one group-wide baseline with controlled national additions, or twelve local answers nobody has compared.
Odido: what customer-platform owners should learn
Odido is the obvious Dutch warning, and its own account is more useful than the reporting around it.
Odido says attackers contacted its customer service team on 5 and 6 February 2026, posing as internal IT staff, in what it calls voice phishing. Approximately 6.39 million people were affected, active and inactive customers of Odido and Ben. Odido has not named the platform. Public reporting has linked the incident to Salesforce, while the company's own account describes voice phishing and access to its customer contact system. The lesson for platform owners sits in the combination of people, permissions, process and a very large concentration of customer data.
I wrote about it in March as a governance story rather than a security one, and five months of follow-up has not changed that reading. The regulators have since split the file in a way that should interest every CMO. The RDI is examining the security of the customer system, the ACM whether the telecom duty of care was met, and the Autoriteit Persoonsgegevens is looking specifically at how long customer data was retained. Retention has become a supervisory question. The same structural pattern appeared in the Adobe breach earlier this year.
The reach of all this showed up in the business pages last week. The CFO of VodafoneZiggo, a competitor, spent a good part of an interview in Het Financieele Dagblad answering questions about the Odido breach, and turned down the suggestion that he should advertise on cyber safety. Flaunting how safe you are, he said, invites somebody to prove otherwise, and a hack at a competitor is good for nobody, not for them and not for the sector.
The Cyberbeveiligingswet would not have guaranteed prevention. Its effect is to raise the standard for risk assessment, access management, detection, retention and escalation. Several of those decisions are shared across marketing, service, platform owners and security.
One incident can start two clocks
One incident can trigger two reporting regimes.
Where it hits a system holding personal data, the Cyberbeveiligingswet wants an early warning within 24 hours, a fuller notification at 72 hours and a final report one month after that notification. The GDPR wants a personal data breach that meets the notification threshold reported to the Autoriteit Persoonsgegevens within 72 hours. Both clocks run from awareness rather than certainty, and the thresholds are not identical.
Legal and security teams decide which duties apply. Marketing Operations still has to escalate quickly, because a suspected sync problem that spends two days in the normal support backlog can already miss the first reporting deadline.
Six answers a CMO should be able to get within a day
1. Where is our largest concentration of customer data? Which CRM, CDP, marketing automation and service platforms hold the volume, and does anyone maintain that list?
2. Who genuinely has access? Including agencies, implementation partners, freelancers, integration accounts, API users, and people who left last year.
3. What can one compromised account do? View single records, or run bulk exports, download segments, create API tokens, change permissions and add integrations?
4. Would we notice unusual behaviour? An unusually large export, access at an odd hour, a new integration, a sudden full sync, a login from somewhere new.
5. Does Marketing Operations know what to escalate, and to whom, today? Twenty-four hours is not long to discover that nobody was sure who to call.
6. Can we explain why the data is still there? Data minimisation is usually filed under privacy. It is also one of the simplest ways to reduce the blast radius of a breach, and the Odido investigations show retention becoming a supervisory question in its own right.
What a vendor can and cannot sell you
The slightly awkward conclusion is that some of the vendors on the radio may be useful. Monitoring, controls and specialist expertise all add value, and buying them from people who do it for a living is sensible.
A vendor cannot decide who owns the platform, why ten years of data is still there, who genuinely needs bulk export rights, or who gets called in the first hour. Those choices belong inside the operating model.
MarTech has been governed for a decade as a performance environment, measured on reach, activation and conversion. The Cyberbeveiligingswet asks regulated organisations to treat it as an operational dependency instead. In Value Gravity™ terms this work belongs in the governed foundation: ownership, access, retention, integrations and supplier dependencies.
Cybersecurity expertise is worth buying. The operating model around it still has to be organised inside the business.
Frequently asked questions
What is the Cyberbeveiligingswet and when does it take effect?
The Cyberbeveiligingswet is the Dutch implementation of the European NIS2 directive. It applies from 15 August 2026 and covers roughly 8,000 organisations providing essential or important services across eighteen sectors in the Netherlands. It introduces a duty of care including supply chain risk, registration in the NCSC entity register, a three-step incident reporting duty, and governance and training obligations for management. Supervision is split by sector, and maximum fines reach 10 million euro or 2% of worldwide turnover for essential entities and 7 million or 1.4% for important entities.
Who falls within the scope of the Dutch law?
Scope is assessed at the level of the legal entity, based on the type of organisation, its sector and its size. Around 8,000 organisations are expected to fall within direct scope, mainly medium-sized and large entities across eighteen designated sectors, among them energy, transport, banking, health, drinking water, digital infrastructure and government. Some categories are covered whatever their size, including providers of public electronic communications networks and services, trust service providers, DNS and domain registration services, and government bodies. A marketing department is never classified separately, but its systems, data and suppliers can sit squarely inside the organisation's obligations.
Does the Cyberbeveiligingswet apply to marketing departments and agencies?
Marketing is assessed as part of its legal entity rather than on its own. An agency or MarTech provider can be directly in scope depending on what it delivers, since managed service providers can qualify. Most marketing suppliers will meet the law indirectly instead, through regulated customers passing requirements down via contracts, security questionnaires, access reviews and incident notification terms. The legal duty stays with the regulated entity. The requirements travel through procurement.
What are the 24-hour and 72-hour reporting deadlines?
An entity in scope sends an early warning to its CSIRT and supervisor within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month of that 72-hour notification rather than one month from awareness. If the incident is still running at that point, a progress report is filed instead.
How does this differ from GDPR breach reporting?
They are separate duties with different thresholds that the same incident can trigger. The Cyberbeveiligingswet concerns significant incidents affecting network and information systems and reports to the CSIRT and sectoral supervisor. The GDPR concerns personal data breaches that pose a risk to the rights and freedoms of individuals, and reports to the Autoriteit Persoonsgegevens within 72 hours. Both clocks run from awareness rather than from certainty, and the cyber deadline arrives first.
What should a CMO or Marketing Operations team do now?
Establish who can answer six things within a day: where the largest concentration of customer data sits, who genuinely has access including agencies and integration accounts, what a single compromised account can do, whether unusual behaviour would be noticed, what gets escalated to whom on the day it looks wrong, and why the data is still being retained. These are ownership questions inside the marketing operating model rather than security engineering questions, and answering them first determines what tooling is worth buying at all.