Abstract glowing network interconnection nodes representing digital infrastructure cybersecurity

NIS2 Netherlands Digital Infrastructure: Why RDI, Not NCSC-NL, Supervises AMS-IX, DNS, and IXP Operators From 15 August 2026

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

AMS-IX moves more than 15 terabits of internet traffic a second through Amsterdam, connecting over 900 networks and reachable from more than 3,000 data centres worldwide [8]. Ask most compliance guides which Dutch authority audits an operator that size under NIS2, and you’ll get the wrong answer: NCSC-NL. It isn’t. The Rijksinspectie Digitale Infrastructuur (RDI) supervises Dutch digital-infrastructure entities — NCSC-NL runs the national entity register and CSIRT, not sector enforcement [5][6][7]. That distinction decides who runs your conformity assessment, who receives your escalated incident reports, and who can fine you once the Cyberbeveiligingswet (CBW) enters into force on 15 August 2026 [5][6]. It gets more specific still, because “digital infrastructure” under NIS2 is not one rulebook. A Dutch DNS resolver, a data centre, and an internet exchange point sit in the same Annex I sector, but only some of them face the 150-plus binding controls of Commission Implementing Regulation (EU) 2024/2690. This guide separates the two, names the actual regulator, and uses AMS-IX — one of the world’s largest internet exchanges — to make the distinction concrete.

Does the Cyberbeveiligingswet’s Digital Infrastructure Sector Cover You?

Digital infrastructure is one of the 11 sectors of high criticality under NIS2 Annex I, and the Dutch CBW carries that sector forward unchanged. Nine entity types fall inside it — and three of them are essential entities regardless of headcount or revenue [1][2].

Entity type In the digital infrastructure sector? Essential regardless of size?
Internet exchange point (IXP) operators Yes No — standard size thresholds apply
DNS service providers (excl. root name servers) Yes Yes
Top-level domain (TLD) name registries Yes Yes
Cloud computing service providers Yes No
Data centre service providers Yes No
Content delivery network (CDN) providers Yes No
Trust service providers (qualified, Reg. 910/2014) Yes (separate Annex I point) Yes
Public electronic communications network providers Yes No
Publicly available electronic communications services Yes No

The “regardless of size” column matters because it changes the test you run. For DNS providers, TLD registries, and qualified trust service providers, providing the service at all is enough — Article 3(1)(b) makes them essential entities with no size test attached [1]. Everyone else on this list, including IXPs, only becomes an essential entity by clearing the general Annex I size thresholds, or an important entity below that line [1]. Our companion guide to Dutch CBW registration walks through the exact essential-versus-important headcount and turnover figures and the mijn.ncsc.nl registration mechanics in full — this guide focuses on what changes once you know which of the nine categories above you are.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Two Different Rulebooks: Why an IXP and a Data Centre Don’t Face the Same Audit

All nine entity types above answer to Article 21(2)’s ten baseline security measures — risk analysis, incident handling, business continuity, supply chain security, secure system acquisition and maintenance, effectiveness assessment, cyber hygiene, cryptography, HR/access control, and multi-factor authentication [3]. But Commission Implementing Regulation (EU) 2024/2690 adds a second, far more prescriptive layer on top of that baseline — and it does not apply evenly across the sector.

Entity type CIR 2024/2690 in scope? What that means in practice
DNS service providers Yes 150+ documented controls across 13 Annex sections
TLD name registries Yes Same 13-section Annex
Cloud computing providers Yes Same 13-section Annex
Data centre providers Yes Same 13-section Annex
CDN providers Yes Same 13-section Annex
Trust service providers Yes Same 13-section Annex
Internet exchange points No Article 21(2)(a)-(j) baseline only, built on the entity’s own technical judgement

CIR 2024/2690 names its entity list explicitly: DNS service providers, TLD registries, cloud computing providers, data centre providers, CDN providers, managed service providers, managed security service providers, providers of online marketplaces, online search engines and social networking platforms, and trust service providers [9]. Internet exchange points are not on that list. A Dutch IXP is still an essential entity once it clears the size threshold, and it still owes its regulator documented evidence against all ten Article 21(2) measures [3] — but it builds that evidence against its own risk assessment rather than a pre-set 13-section Annex. For a compliance team covering more than one entity type, that is the difference between an audit built from a checklist and one built from scratch.

The 13-section Annex itself is worth understanding in full if your organisation falls on the CIR side of that split — our complete guide to CIR 2024/2690 breaks down all 13 sections, and our digital infrastructure compliance checklist turns them into an audit-evidence list for DNS, cloud, data centre, and CDN operators specifically. For the EU-wide view of how the sector’s 150+ controls map to Article 21, see our digital infrastructure compliance guide — this Netherlands guide layers the RDI/NCSC-NL supervisory split and the AMS-IX example on top of that baseline.

Who Actually Supervises You: RDI, Not NCSC-NL

Registering with NCSC-NL is not the same as being supervised by NCSC-NL — a distinction that gets flattened in most CBW overviews.

Function Who What they do
National entity register NCSC-NL (via mijn.ncsc.nl) Receives Registratieplicht filings [7]
National CSIRT NCSC-NL Receives Meldplicht 24h/72h/1-month incident notifications, routes copies to your sector regulator [7]
Digital infrastructure sector supervisor RDI (Rijksinspectie Digitale Infrastructuur) Conformity assessments, enforcement, fines [5][6]

RDI supervises five sectors under the Cyberbeveiligingswet: digital infrastructure, energy, space, research, and government [5][6]. For essential entities — AMS-IX among them — that supervision is proactive: RDI can request information or conduct a site visit without waiting for an incident, using regular risk-based inspections, thematic sector inspections, and incident-triggered investigations [6]. Important entities get mostly reactive, incident-triggered oversight instead [6]. Either way, RDI holds enforcement authority up to the Article 34 fine ceiling [4][5]. NCSC-NL’s role stops at registration and incident coordination; it is not the body auditing your Article 21(2) evidence. Confuse the two and a compliance team can end up building an evidence package addressed to the wrong authority. If your organisation spans multiple sectors, our guide to the Netherlands’ five CBW regulators covers where the other four — DNB, AFM, ILT, and IGJ — take over.

AMS-IX: What Essential-Entity Status Looks Like for the World’s Busiest IXP

AMS-IX is a useful stress test for the classification rules above, because it is unambiguous at every step. As an internet exchange point, it sits in NIS2 Annex I’s digital-infrastructure sector [2]. It does not qualify for the automatic, size-independent essential status that Article 3(1)(b) reserves for DNS providers, TLD registries, and qualified trust service providers [1] — an IXP earns essential status the ordinary way, by exceeding the large-enterprise thresholds under Article 3(1)(a) [1]. At AMS-IX’s scale — over 900 connected networks, peak traffic above 15 terabits per second, reach into 3,000-plus data centres [8] — that threshold is not in doubt.

What follows: AMS-IX owes RDI documented evidence across all ten Article 21(2) measures [3][5], under RDI’s proactive supervision model. What does not follow is a 150-plus-control CIR 2024/2690 audit. Because IXPs sit outside the CIR’s named entity list [9], AMS-IX builds its own risk-based control set instead of working through the Annex’s 13 mandatory sections that will bind a Dutch DNS resolver or data centre operator down the road. For a Dutch digital-infrastructure compliance team, the AMS-IX case is the clean version of a distinction that gets muddled fast in smaller organisations: sector membership decides who audits you; entity type decides how thick the rulebook is.

Registration Timeline: What to Do Before 15 August 2026

The Cyberbeveiligingswet enters into force on 15 August 2026 [5][6]. Voluntary registration at mijn.ncsc.nl has been open since October 2024; from the entry-into-force date, registration becomes mandatory for every in-scope entity, including digital-infrastructure operators supervised by RDI [7].

Step Action Owner
1 Confirm sector and entity classification against the tables above Compliance lead
2 Obtain eHerkenning EH2+ business authentication (apply early — processing takes time) IT / administration
3 Register at mijn.ncsc.nl Authorised signatory or delegated permissions administrator
4 Build Article 21(2) evidence, cross-referenced to the CIR Annex if in CIR scope CISO / IT security
5 Confirm incident-reporting routing (24h / 72h / 1-month) Compliance / legal

For the full step-by-step mijn.ncsc.nl walkthrough, including exact eHerkenning mechanics and the three CBW compliance pillars, see the companion guide linked above.

Penalties for Getting This Wrong

Entity tier Maximum fine Triggered by
Essential (e.g. DNS/TLD providers, and IXPs the size of AMS-IX) €10,000,000 or 2% of total worldwide annual turnover, whichever is higher Article 21 or 23 infringements [4]
Important €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher Article 21 or 23 infringements [4]

For the Dutch CBW’s additional tiered penalties and how enforcement actually reaches a supervisory board, see our dedicated guide to Netherlands NIS2 penalties.

Frequently Asked Questions

Is AMS-IX regulated under NIS2?
Yes. As an internet exchange point, AMS-IX sits in NIS2 Annex I’s digital-infrastructure sector [2], and given its scale it clears the large-enterprise threshold for essential-entity status [1].

Does CIR 2024/2690 apply to Dutch internet exchange points?
No. The regulation’s entity list covers DNS providers, TLD registries, cloud, data centre, CDN, MSP/MSSP, marketplace/search/social platforms, and trust service providers [9] — IXPs are not named and stay on the Article 21(2) baseline only [3].

Who do I register with, and who audits me?
You register the same way regardless of entity type — through NCSC-NL’s mijn.ncsc.nl portal [7]. Ongoing supervision and any conformity assessment or enforcement action comes from your sector regulator: RDI for digital infrastructure [5][6].

Does a small Dutch IXP get the same automatic essential status as AMS-IX?
No. Size matters for IXPs in a way it doesn’t for DNS or TLD providers. A small exchange that stays under the large-enterprise thresholds in Article 3(1)(a) may qualify only as an important entity, or fall outside CBW scope entirely [1] — confirm your classification with the RDI/NCSC-NL self-evaluation tool rather than assuming sector membership alone decides it.

The Bottom Line

Digital infrastructure is the one NIS2 sector where what you are changes the rulebook as much as how big you are. A Dutch DNS provider or TLD registry is essential regardless of size and faces CIR 2024/2690’s full 150-plus-control Annex. A Dutch IXP the size of AMS-IX earns essential status on scale alone and answers only to the ten-measure Article 21(2) baseline. Both report through the same portal — NCSC-NL’s mijn.ncsc.nl — but neither is supervised by NCSC-NL day to day; that job belongs to RDI. Get the entity-type and regulator distinctions right before 15 August 2026, and the rest of Dutch digital-infrastructure compliance is a documentation exercise, not a guessing game.

Sources

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: