What Changed for Dutch IT Buyers on 15 August 2026
The Netherlands was among the last EU member states to transpose the NIS2 Directive. The Cyberbeveiligingswet (Cbw) was adopted by the Eerste Kamer on 7 July 2026, published as Staatsblad 2026, 187, and entered into force on 15 August 2026 alongside the Cyberbeveiligingsbesluit, the decree covering management body training, certification and incident notification. The companion Wet weerbaarheid kritieke entiteiten, implementing the EU Critical Entities Resilience Directive, started the same day.
Three features of that transition matter directly to how you select an IT provider:
There is no transition period. The duty of care and the duty to report applied from day one. The supervisor's mandate existed from 15 August. Nobody expects an inspection immediately, but "we'll start after the summer" stopped being a defensible position three weeks ago.
Scope expanded roughly eightfold. Under the old Wbni framework of 2018, around 1,000 Dutch organisations were in scope. Under the Cbw that number rises to approximately 8,000 and many are discovering their status for the first time. If you have not run a scoping assessment, that is the first thing to do, at mijn.ncsc.nl.
The supply chain pulls in far more than 8,000. Cbw Article 24 requires essential and important entities to assess the cybersecurity of their direct suppliers and service providers, with documented evidence retained at contract execution and on a recurring risk-based cycle. In practice that draws tens of thousands of Dutch suppliers into the requirements indirectly, through their customers' contracts. Your MSP sits squarely in that chain and so, if you supply a regulated customer, do you.
Supervision is deliberately split. The Ministry of Justice and Security and NCSC-NL share the competent authority and CSIRT functions, with sectoral regulators layered on top, and the Rijksinspectie Digitale Infrastructuur overseeing the availability and reliability of Dutch digital infrastructure. There is no single Dutch cyber regulator, so sector-matched experience in a provider is worth more here than a generic security claim.
What to Require From a Dutch Managed Service Provider
The obligations above translate into concrete contract requirements. Use this as your procurement baseline.
| Obligation under Dutch law |
What to require from your MSP |
| Cbw duty of care |
Documented risk-management measures mapped to Cbw articles, not a generic security policy |
| Cbw duty to report |
A defined detection-to-notification path that meets the incident reporting clock, with named escalation contacts |
| Cbw Art. 24 supply chain |
Signed security clauses, audit rights, sub-contracting limits, termination triggers, and evidence of recognised standards |
| Cbw registration |
Confirmation of whether the provider is itself in scope and registered via mijn.ncsc.nl |
| Cyberbeveiligingsbesluit |
Support for management body training obligations your board, not just your IT team, must be trained |
| AVG (GDPR) |
A verwerkersovereenkomst, a current sub-processor list, and a documented datalek notification route |
| Fiscal bewaarplicht (AWR art. 52) |
Backup and archive retention of at least seven years, ten for immovable property records |
A note on retention, because it is where Dutch and other European markets differ. The Belastingdienst requires seven years of retention for core administrative records longer than most EU neighbours and this sits in direct tension with the AVG's storage-limitation principle. The Autoriteit Persoonsgegevens has confirmed the fiscal retention obligation is a valid legal basis for holding that data for the statutory term, meaning a customer cannot force deletion of invoice data while the bewaarplicht runs. The practical resolution is to retain financial documents intact while removing or pseudonymising the surrounding personal data that has no fiscal relevance. That is a data-lifecycle design question, and it belongs in your MSP's scope, not in a filing cabinet.
Note also what Dutch law does not require: unlike some EU jurisdictions, there is no blanket statutory mandate that backups be held inside the EU or EEA. Residency is still worth specifying contractually for AVG and sovereignty reasons but do not assume a provider has addressed it because the law forced them to.
For the independent certifications worth demanding as evidence, see our MSP certifications checklist. ISO 27001 remains the strongest baseline signal in the Dutch market, with NEN 7510 effectively mandatory in healthcare.
The Dutch MSP Market
The Netherlands has one of the densest digital infrastructure footprints in Europe. Amsterdam hosts AMS-IX, one of the world's largest internet exchanges, and the surrounding datacentre cluster gives Dutch providers access to low-latency hosting and colocation that providers in comparable-sized markets simply do not have. That shapes the service mix: hosting, private cloud and connectivity feature more heavily in Dutch MSP portfolios than in most European markets.
Comparing providers on hosting and cloud capability specifically? Our cloud MSP database and Microsoft partner list filter by platform. For security-led providers, see the cybersecurity MSP database.
Managed IT Services Offered by Dutch Providers
If the managed services model itself is new to you, our guide to what a managed service provider does covers the fundamentals. Across the Dutch market, expect these service lines:
- Managed werkplek — the Dutch market's characteristic packaging: a fully managed end-user workplace including device, identity, Microsoft 365 and support, priced per user
- Servicedesk and end-user support — Dutch-language first line, with English second line common given the size of the international workforce
- Monitoring, patching and RMM — proactive fault detection under a defined SLA
- Cloud and hosting — Azure and Microsoft 365 dominate, with local private cloud and colocation widely available
- Network and connectivity management — including SD-WAN and multi-site
- Managed security — EDR, email security, firewall management, awareness training
- Backup, disaster recovery and long-term archiving — must reconcile the seven-year bewaarplicht with AVG storage limitation
- Compliance support — Cbw scoping, gap assessment, evidence documentation
- vCIO and IT strategy — increasingly bundled as regulatory obligations move to board level
Where security requirements exceed what a general IT contract covers, the requirement shifts to an MSSP. Our explainer on the MSP versus MSSP distinction covers where that line falls; the MSSP list covers dedicated security providers.
Managed Service Providers by Dutch Region
Randstad Noord-Holland, Zuid-Holland, Utrecht. Amsterdam, Rotterdam, The Hague and Utrecht account for the bulk of Dutch corporate IT demand and the widest provider choice. Amsterdam skews toward financial services, tech and international businesses with English-language requirements; Rotterdam toward logistics, port and maritime; The Hague toward government, legal and international institutions.
Noord-Brabant and Limburg. The Brainport Eindhoven region is the Netherlands' high-tech manufacturing and semiconductor cluster. Providers here more often carry OT experience and work with engineering-heavy environments.
Gelderland, Overijssel and Utrecht east. Manufacturing, logistics and agri-business, with providers typically serving regional SMEs.
Groningen, Friesland, Drenthe and Flevoland. The northern provinces have a thinner provider field. Businesses here should confirm on-site response times specifically, since a Randstad-based provider is two to three hours away.
Zeeland. Concentrated around process industry, ports and cross-border Belgian operations.
For city-level searches in other markets, browse our MSP directory by city or the full verified provider directory.
Managed IT Services by Industry in the Netherlands
Logistics, ports and transport. Rotterdam is Europe's largest port and Schiphol a major cargo hub. Requirements centre on 24/7 uptime, EDI and customs system integration, and OT security across terminal equipment. Transport is a Cbw sector.
High-tech manufacturing and semiconductors. The Brainport cluster demands IP protection, engineering workstation performance, and OT/IT segmentation. Manufacturing falls within Cbw scope.
Agri-food and horticulture. The Netherlands is the world's second-largest agricultural exporter. Greenhouse horticulture around Westland runs heavily instrumented climate and irrigation control systems — an OT environment most generalist providers have never touched. Food is a Cbw sector.
Financial services and fintech. Amsterdam's financial cluster sits under DORA alongside the Cbw, with DNB supervision. Expect the highest documentation burden of any Dutch vertical.
Healthcare and care providers. NEN 7510 is the Dutch information security standard for healthcare and is effectively a procurement prerequisite. Health is a Cbw sector.
Public sector, gemeenten and waterschappen. Dutch municipalities and the water boards are a distinctive segment with their own procurement rules, BIO baseline requirements, and DigiD/eHerkenning integration needs. Water and waste water fall under Cbw scope, making the waterschappen directly regulated.
Energy and utilities. Grid operators and energy suppliers sit under sector-specific supervision in addition to the Cbw, with the North Sea offshore wind build-out driving remote-site infrastructure demand.
Chemicals and process industry. Concentrated around Rotterdam, Geleen and Terneuzen. Safety-critical OT, and a named Cbw sector.
Retail and e-commerce. The Netherlands has high e-commerce penetration. Priorities are payment infrastructure, PCI DSS, peak-season capacity and iDEAL integration.
Professional services legal, accounting, consultancy. Confidentiality and document management dominate. Accountancy firms carry a double obligation: their own seven-year bewaarplicht and their clients'.
Construction, engineering and architecture. BIM and CAD workloads, large file estates, and temporary site connectivity.
Education and research. Research is a Cbw sector. Identity management at scale, BYOD estates, and international collaboration constraints.
Media, creative and marketing. Amsterdam's creative sector needs high-throughput storage, colour-managed workflows and rights-controlled asset access.
Hospitality and tourism. Guest network segregation from PMS and payment systems, plus high seasonal staff turnover driving access-management workload.
Non-profits and foundations. Budget-constrained with volunteer turnover, which favours flat-rate managed services with strong documentation over hourly support.
Smaller organisations should read our managed IT for small business cost guide. Organisations with existing internal IT staff should consider co-managed IT rather than full outsourcing.
What Managed IT Services Cost in the Netherlands
Dutch providers quote a recurring monthly fee, typically per user (per werkplek) in euros under a service agreement, rather than an hourly rate. Full outsourcing is priced as a fixed monthly operating cost.
Published Dutch market benchmarks are scarce, so use international per-user pricing as a reference point and validate locally. The established international benchmark for full-scope managed IT runs roughly USD 100–400 per user per month, clustering between USD 120 and 220. Our MSP pricing breakdown explains what drives position within that range.
Dutch factors that move a quote:
- Wage levels and labour scarcity. Dutch technical salaries sit above the EU average and the IT labour market is tight, which pushes rates up.
- Cbw compliance scope. If you are in scope, gap assessment, evidence documentation and board training are real cost lines. Ask whether they are included or billed separately this is the single most common source of quote variance in the Dutch market right now.
- Hosting choice. Dutch datacentre density makes local private cloud competitive against hyperscale for some workloads.
- Retention depth. Seven-year archiving costs more than a standard 30-day backup retention tier. Confirm it is in the base price.
- Language coverage. Dutch-language first line is standard; guaranteed English coverage is sometimes an add-on.
The most useful question in any Dutch pricing conversation remains: wat zit er niet in?
How to Choose a Managed Service Provider in the Netherlands
Our 15-question MSP vetting checklist applies in any market. These are the Netherlands-specific additions:
- "Have you assessed whether you fall in scope of the Cbw, and are you registered at mijn.ncsc.nl?" A provider that has not checked has not read the law that took effect in August.
- "Will you sign Cbw Article 24 supplier clauses, including audit rights and sub-contracting limits?" If you are in scope, you are required to obtain these.
- "Can you evidence your own security posture to a standard we can show a supervisor?" ISO 27001 certification, or NEN 7510 for healthcare.
- "How do you support our seven-year bewaarplicht while meeting AVG storage limitation?" The answer should describe data lifecycle handling, not just backup retention settings.
- "Which supervisor covers our sector, and have you worked with them?" Dutch supervision is split across NCSC-NL, sectoral regulators and the RDI.
- "Can you support management body training under the Cyberbeveiligingsbesluit?" Board-level, not IT-level.
- "What is your guaranteed on-site response time to our address?" Relevant outside the Randstad.
- "Is first-line support in Dutch, English or both, and at what hours?"
- "Can you provide a verwerkersovereenkomst and a current sub-processor list?"
How This Netherlands MSP List Is Verified
Every provider listed above is independently verified against its own website, LinkedIn presence and registered Dutch address before publication. We record company name, address, province, contact details, employee band, revenue band, founding year, declared services and technology stack. No provider has paid for placement or position.
This list is not exhaustive — the Dutch market includes many small local operators. We add and re-verify on an ongoing cycle. Dutch MSPs can request a listing; buyers who need something not covered here can contact our team.
For other markets, see the MSP market data by country hub or the wider MSP data report.
Frequently Asked Questions
Does NIS2 apply to my Dutch business? It applies through the Cyberbeveiligingswet, in force since 15 August 2026. Around 8,000 Dutch organisations fall directly in scope, up from roughly 1,000 under the previous Wbni framework. Check your status at mijn.ncsc.nl. Even if you are out of scope directly, you may be pulled in contractually as a supplier to a regulated customer.
Is my MSP required to comply with the Cyberbeveiligingswet? Possibly directly, depending on its size and services and certainly indirectly, because Cbw Article 24 requires in-scope entities to assess their direct suppliers' cybersecurity and retain documented evidence of that assessment. Ask your provider for its own scoping conclusion in writing.
Was there a grace period when the Dutch law took effect? No. The Cyberbeveiligingswet applied from 15 August 2026 with no transition period. The duty of care, the duty to report and the registration requirement all began on the same date.
How long must a Dutch business retain its records? Seven years for core administrative records under the fiscal bewaarplicht, extending to ten years for records relating to immovable property. This is longer than many EU neighbours and should be reflected in your backup and archiving contract.
Do Dutch MSPs provide support in English? Many do, particularly in the Randstad where international workforces are common. Dutch is the default first line at most regional providers, so confirm guaranteed English coverage and its hours.
What certifications should a Dutch MSP hold? ISO 27001 is the baseline. NEN 7510 is effectively mandatory for anything touching healthcare data. Microsoft Solutions Partner designation matters given how Microsoft-centric the Dutch SME market is. For regulated buyers, ask for documented Cbw readiness rather than a general security statement.