NIS2 Netherlands Digital Infrastructure: Why RDI, Not NCSC-NL, Supervises AMS-IX, DNS, and IXP Operators From 15 August 2026
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
AMS-IX moves more than 15 terabits of internet traffic a second through Amsterdam, connecting over 900 networks and reachable from more than 3,000 data centres worldwide [8]. Ask most compliance guides which Dutch authority audits an operator that size under NIS2, and you’ll get the wrong answer: NCSC-NL. It isn’t. The Rijksinspectie Digitale Infrastructuur (RDI) supervises Dutch digital-infrastructure entities — NCSC-NL runs the national entity register and CSIRT, not sector enforcement [5][6][7]. That distinction decides who runs your conformity assessment, who receives your escalated incident reports, and who can fine you once the Cyberbeveiligingswet (CBW) enters into force on 15 August 2026 [5][6]. It gets more specific still, because “digital infrastructure” under NIS2 is not one rulebook. A Dutch DNS resolver, a data centre, and an internet exchange point sit in the same Annex I sector, but only some of them face the 150-plus binding controls of Commission Implementing Regulation (EU) 2024/2690. This guide separates the two, names the actual regulator, and uses AMS-IX — one of the world’s largest internet exchanges — to make the distinction concrete.
Does the Cyberbeveiligingswet’s Digital Infrastructure Sector Cover You?
Digital infrastructure is one of the 11 sectors of high criticality under NIS2 Annex I, and the Dutch CBW carries that sector forward unchanged. Nine entity types fall inside it — and three of them are essential entities regardless of headcount or revenue [1][2].
| Entity type | In the digital infrastructure sector? | Essential regardless of size? |
|---|---|---|
| Internet exchange point (IXP) operators | Yes | No — standard size thresholds apply |
| DNS service providers (excl. root name servers) | Yes | Yes |
| Top-level domain (TLD) name registries | Yes | Yes |
| Cloud computing service providers | Yes | No |
| Data centre service providers | Yes | No |
| Content delivery network (CDN) providers | Yes | No |
| Trust service providers (qualified, Reg. 910/2014) | Yes (separate Annex I point) | Yes |
| Public electronic communications network providers | Yes | No |
| Publicly available electronic communications services | Yes | No |
The “regardless of size” column matters because it changes the test you run. For DNS providers, TLD registries, and qualified trust service providers, providing the service at all is enough — Article 3(1)(b) makes them essential entities with no size test attached [1]. Everyone else on this list, including IXPs, only becomes an essential entity by clearing the general Annex I size thresholds, or an important entity below that line [1]. Our companion guide to Dutch CBW registration walks through the exact essential-versus-important headcount and turnover figures and the mijn.ncsc.nl registration mechanics in full — this guide focuses on what changes once you know which of the nine categories above you are.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
Two Different Rulebooks: Why an IXP and a Data Centre Don’t Face the Same Audit
All nine entity types above answer to Article 21(2)’s ten baseline security measures — risk analysis, incident handling, business continuity, supply chain security, secure system acquisition and maintenance, effectiveness assessment, cyber hygiene, cryptography, HR/access control, and multi-factor authentication [3]. But Commission Implementing Regulation (EU) 2024/2690 adds a second, far more prescriptive layer on top of that baseline — and it does not apply evenly across the sector.
| Entity type | CIR 2024/2690 in scope? | What that means in practice |
|---|---|---|
| DNS service providers | Yes | 150+ documented controls across 13 Annex sections |
| TLD name registries | Yes | Same 13-section Annex |
| Cloud computing providers | Yes | Same 13-section Annex |
| Data centre providers | Yes | Same 13-section Annex |
| CDN providers | Yes | Same 13-section Annex |
| Trust service providers | Yes | Same 13-section Annex |
| Internet exchange points | No | Article 21(2)(a)-(j) baseline only, built on the entity’s own technical judgement |
CIR 2024/2690 names its entity list explicitly: DNS service providers, TLD registries, cloud computing providers, data centre providers, CDN providers, managed service providers, managed security service providers, providers of online marketplaces, online search engines and social networking platforms, and trust service providers [9]. Internet exchange points are not on that list. A Dutch IXP is still an essential entity once it clears the size threshold, and it still owes its regulator documented evidence against all ten Article 21(2) measures [3] — but it builds that evidence against its own risk assessment rather than a pre-set 13-section Annex. For a compliance team covering more than one entity type, that is the difference between an audit built from a checklist and one built from scratch.
The 13-section Annex itself is worth understanding in full if your organisation falls on the CIR side of that split — our complete guide to CIR 2024/2690 breaks down all 13 sections, and our digital infrastructure compliance checklist turns them into an audit-evidence list for DNS, cloud, data centre, and CDN operators specifically. For the EU-wide view of how the sector’s 150+ controls map to Article 21, see our digital infrastructure compliance guide — this Netherlands guide layers the RDI/NCSC-NL supervisory split and the AMS-IX example on top of that baseline.
Who Actually Supervises You: RDI, Not NCSC-NL
Registering with NCSC-NL is not the same as being supervised by NCSC-NL — a distinction that gets flattened in most CBW overviews.
| Function | Who | What they do |
|---|---|---|
| National entity register | NCSC-NL (via mijn.ncsc.nl) | Receives Registratieplicht filings [7] |
| National CSIRT | NCSC-NL | Receives Meldplicht 24h/72h/1-month incident notifications, routes copies to your sector regulator [7] |
| Digital infrastructure sector supervisor | RDI (Rijksinspectie Digitale Infrastructuur) | Conformity assessments, enforcement, fines [5][6] |
RDI supervises five sectors under the Cyberbeveiligingswet: digital infrastructure, energy, space, research, and government [5][6]. For essential entities — AMS-IX among them — that supervision is proactive: RDI can request information or conduct a site visit without waiting for an incident, using regular risk-based inspections, thematic sector inspections, and incident-triggered investigations [6]. Important entities get mostly reactive, incident-triggered oversight instead [6]. Either way, RDI holds enforcement authority up to the Article 34 fine ceiling [4][5]. NCSC-NL’s role stops at registration and incident coordination; it is not the body auditing your Article 21(2) evidence. Confuse the two and a compliance team can end up building an evidence package addressed to the wrong authority. If your organisation spans multiple sectors, our guide to the Netherlands’ five CBW regulators covers where the other four — DNB, AFM, ILT, and IGJ — take over.
AMS-IX: What Essential-Entity Status Looks Like for the World’s Busiest IXP
AMS-IX is a useful stress test for the classification rules above, because it is unambiguous at every step. As an internet exchange point, it sits in NIS2 Annex I’s digital-infrastructure sector [2]. It does not qualify for the automatic, size-independent essential status that Article 3(1)(b) reserves for DNS providers, TLD registries, and qualified trust service providers [1] — an IXP earns essential status the ordinary way, by exceeding the large-enterprise thresholds under Article 3(1)(a) [1]. At AMS-IX’s scale — over 900 connected networks, peak traffic above 15 terabits per second, reach into 3,000-plus data centres [8] — that threshold is not in doubt.
What follows: AMS-IX owes RDI documented evidence across all ten Article 21(2) measures [3][5], under RDI’s proactive supervision model. What does not follow is a 150-plus-control CIR 2024/2690 audit. Because IXPs sit outside the CIR’s named entity list [9], AMS-IX builds its own risk-based control set instead of working through the Annex’s 13 mandatory sections that will bind a Dutch DNS resolver or data centre operator down the road. For a Dutch digital-infrastructure compliance team, the AMS-IX case is the clean version of a distinction that gets muddled fast in smaller organisations: sector membership decides who audits you; entity type decides how thick the rulebook is.
Registration Timeline: What to Do Before 15 August 2026
The Cyberbeveiligingswet enters into force on 15 August 2026 [5][6]. Voluntary registration at mijn.ncsc.nl has been open since October 2024; from the entry-into-force date, registration becomes mandatory for every in-scope entity, including digital-infrastructure operators supervised by RDI [7].
| Step | Action | Owner |
|---|---|---|
| 1 | Confirm sector and entity classification against the tables above | Compliance lead |
| 2 | Obtain eHerkenning EH2+ business authentication (apply early — processing takes time) | IT / administration |
| 3 | Register at mijn.ncsc.nl | Authorised signatory or delegated permissions administrator |
| 4 | Build Article 21(2) evidence, cross-referenced to the CIR Annex if in CIR scope | CISO / IT security |
| 5 | Confirm incident-reporting routing (24h / 72h / 1-month) | Compliance / legal |
For the full step-by-step mijn.ncsc.nl walkthrough, including exact eHerkenning mechanics and the three CBW compliance pillars, see the companion guide linked above.
Penalties for Getting This Wrong
| Entity tier | Maximum fine | Triggered by |
|---|---|---|
| Essential (e.g. DNS/TLD providers, and IXPs the size of AMS-IX) | €10,000,000 or 2% of total worldwide annual turnover, whichever is higher | Article 21 or 23 infringements [4] |
| Important | €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher | Article 21 or 23 infringements [4] |
For the Dutch CBW’s additional tiered penalties and how enforcement actually reaches a supervisory board, see our dedicated guide to Netherlands NIS2 penalties.
Frequently Asked Questions
Is AMS-IX regulated under NIS2?
Yes. As an internet exchange point, AMS-IX sits in NIS2 Annex I’s digital-infrastructure sector [2], and given its scale it clears the large-enterprise threshold for essential-entity status [1].
Does CIR 2024/2690 apply to Dutch internet exchange points?
No. The regulation’s entity list covers DNS providers, TLD registries, cloud, data centre, CDN, MSP/MSSP, marketplace/search/social platforms, and trust service providers [9] — IXPs are not named and stay on the Article 21(2) baseline only [3].
Who do I register with, and who audits me?
You register the same way regardless of entity type — through NCSC-NL’s mijn.ncsc.nl portal [7]. Ongoing supervision and any conformity assessment or enforcement action comes from your sector regulator: RDI for digital infrastructure [5][6].
Does a small Dutch IXP get the same automatic essential status as AMS-IX?
No. Size matters for IXPs in a way it doesn’t for DNS or TLD providers. A small exchange that stays under the large-enterprise thresholds in Article 3(1)(a) may qualify only as an important entity, or fall outside CBW scope entirely [1] — confirm your classification with the RDI/NCSC-NL self-evaluation tool rather than assuming sector membership alone decides it.
The Bottom Line
Digital infrastructure is the one NIS2 sector where what you are changes the rulebook as much as how big you are. A Dutch DNS provider or TLD registry is essential regardless of size and faces CIR 2024/2690’s full 150-plus-control Annex. A Dutch IXP the size of AMS-IX earns essential status on scale alone and answers only to the ten-measure Article 21(2) baseline. Both report through the same portal — NCSC-NL’s mijn.ncsc.nl — but neither is supervised by NCSC-NL day to day; that job belongs to RDI. Get the entity-type and regulator distinctions right before 15 August 2026, and the rest of Dutch digital-infrastructure compliance is a documentation exercise, not a guessing game.
Sources
- [1] NIS2 Directive, Article 3 — Essential and Important Entities
- [2] NIS2 Directive, Article 6 — Definitions
- [3] NIS2 Directive, Article 21 — Cybersecurity Risk-Management Measures
- [4] NIS2 Directive, Article 34 — Penalties
- [5] Rijksinspectie Digitale Infrastructuur — Cyberbeveiligingswet
- [6] Rijksinspectie Digitale Infrastructuur — Toezicht RDI op de Cyberbeveiligingswet
- [7] NCSC-NL — Cyberbeveiligingswet (NIS2)
- [8] AMS-IX — Amsterdam Internet Exchange
- [9] Advisera — NIS2 CIR 2024/2690: Cybersecurity Requirements for EU Digital Infrastructure
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
