Netherlands NIS2 Energy Compliance: Why RDI (Not ACM) Now Oversees TenneT and Gasunie
If you searched for the Dutch NIS2 energy authority and landed on ACM (Autoriteit Consument & Markt), you found last year’s answer. Since 1 January 2026, the Rijksinspectie Digitale Infrastructuur (RDI) supervises Dutch energy-sector cybersecurity under both the Cyberbeveiligingswet (CBW) — the Netherlands’ NIS2 transposition — and the EU Network Code on Cybersecurity (NCCS), the electricity-specific rulebook that used to sit with ACM. That handoff matters more than it sounds: it means TenneT, Gasunie, and every other essential or important energy entity in the Netherlands now answers to one supervisor for two overlapping-but-distinct compliance regimes, each with its own scope, trigger, and deadline.
This guide maps exactly how that works: who regulates what, how TenneT’s and Gasunie’s cross-border infrastructure is actually supervised (it’s simpler — and stricter — than the “shared grid, shared jurisdiction” assumption most guides repeat), which energy sub-sectors fall under the CBW’s 15 August 2026 deadline, and what a compliance officer or OT security lead needs in place before then.
Who Regulates Dutch Energy Cybersecurity? RDI, Not ACM
In short: RDI is the supervisor. ACM held a piece of this territory until January 2026; it no longer does. RDI’s mandate under the Cyberbeveiligingswet covers essential and important organisations across several sectors, including energy, digital infrastructure, space, research, and government. Within energy, RDI’s scope spans four sub-sectors, each carrying its own mix of essential entities:
| Energy sub-sector | Typical entities | Essential-entity threshold |
|---|---|---|
| Electricity | Transmission and distribution system operators, generation and supply undertakings, market operators | 250+ staff or >€50M turnover / €43M balance sheet |
| Natural gas | Transmission, distribution, storage and LNG terminal operators | Same threshold logic |
| Oil | Transmission, storage and refining operators | Same threshold logic |
| District heating and cooling | Heat network operators | Same threshold logic |
RDI is one of six Dutch sector supervisors created under the CBW — we’ve mapped all six, including the healthcare, finance and transport regulators, in our full competent-authority breakdown. Energy is RDI’s territory specifically because the ministry responsible for CBW implementation assigned it there by sector, not because ACM was ever the general NIS2 regulator for energy — ACM’s actual role was narrower and, as the next section explains, has now moved.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
The ACM-to-RDI Handoff: Why NCCS and NIS2 Aren’t the Same Law
NCCS and CBW/NIS2 look similar from the outside — both regulate electricity cybersecurity — but they’re separate EU instruments, and being designated under one doesn’t automatically put you in scope for the other. As of this year, RDI enforces both, which is new.
The Network Code on Cybersecurity is an EU Commission Delegated Regulation, not a national law — it entered into force on 13 June 2024, and member states had to appoint a competent authority by 13 December 2024. The Netherlands initially named ACM. NCCS applies only to “high-impact” and “critical-impact” electricity entities, selected using ENTSO-E and the EU DSO Entity’s European Cybersecurity Impact Index — a narrower, technically-driven designation process than the CBW’s sector-and-size test. Covered entity types include transmission and distribution system operators, large electricity producers, aggregators, nominated electricity market operators, balance responsible parties, and charge point operators.
Then, effective 1 January 2026, RDI took over NCCS enforcement from ACM as part of the new Energiewet. NCSC-NL is explicit that the two regimes stay distinct even under one supervisor: an NCCS designation does not automatically mean an entity falls under the CBW, and vice versa. In practice, a Dutch TSO or large generator can be in scope for one, both, or — for smaller market participants — neither. The table below is the comparison no generic NIS2 guide runs, because it requires knowing both regimes’ current Dutch status:
| Cyberbeveiligingswet (NIS2) | Network Code on Cybersecurity (NCCS) | |
|---|---|---|
| Legal basis | Dutch transposition of Directive (EU) 2022/2555 | EU Commission Delegated Regulation, in force since 13 Jun 2024 |
| Scope | All CBW sectors, incl. electricity, gas, oil, district heating | Electricity only — high/critical-impact entities |
| Dutch supervisor | RDI | RDI (took over from ACM on 1 Jan 2026) |
| Designation trigger | Sector membership + size threshold | Separate ECII impact-based designation |
| Key deadline | CBW enters into force 15 August 2026 | Phased 2025–2026 designation and compliance rollout |
| Does one imply the other? | No — designation under NCCS is not automatic CBW scope | No — and vice versa |
TenneT and Gasunie: How Cross-Border Grid Operators Actually Comply
TenneT operates the high-voltage grid in both the Netherlands and a large part of Germany. It’s tempting to assume that creates one shared NIS2 jurisdiction — it doesn’t, and the reason is worth understanding because it changes what “compliance” actually requires.
Article 26 of the NIS2 Directive sets jurisdiction by place of establishment as the default rule. There’s a well-known exception — a “main establishment” test that lets an entity operating across several member states be supervised from a single one — but that exception applies only to a specific list: DNS providers, TLD registries, domain registration services, cloud and data-centre operators, CDNs, managed service and security providers, and online marketplaces, search engines and social platforms. Energy entities, including TSOs, are not on that list. For Annex I sectors like energy, the default rule is the only rule.
That’s consistent with how TenneT is actually structured: not one cross-border entity, but a Dutch state-owned holding company (100% owned via the Ministry of Finance) with separate national subsidiaries — TenneT TSO B.V. in the Netherlands and TenneT TSO GmbH in Germany, together running over 25,000 km of transmission lines and roughly 485 substations serving more than 43 million end-users. TenneT TSO B.V. answers to RDI under the CBW. TenneT TSO GmbH answers to Germany’s BSI under its own NIS2 transposition. The group can — and in practice should — run one harmonised ISMS internally, but there is no shared regulatory filing: each legal entity registers, reports, and gets audited separately.
Gasunie follows the same logic. It’s 100% Dutch state-owned and operates over 12,000 km of gas transmission pipeline in the Netherlands, plus roughly 3,100 km of network in Germany. The Dutch pipeline network falls under RDI/CBW supervision as a gas-sector essential entity; the German assets fall under Germany’s own regime. For a Dutch energy compliance officer, the actionable takeaway is: don’t assume a group’s German compliance status covers the Dutch legal entity, or the reverse — CBW registration and Article 21 documentation have to exist independently for the Dutch entity, even inside a fully cross-border group.
Does This Apply to Your Organisation? Dutch Energy Sub-Sector Scope
Use this sequence rather than assuming your organisation is either obviously in or obviously out:
- Step 1 — Sector check. Do you operate in electricity, natural gas, oil, or district heating/cooling within the Netherlands? If not, CBW’s energy rules don’t apply to you directly — check the broader CBW scope criteria for other sectors.
- Step 2 — Size check. Do you exceed roughly 250 staff or €50M turnover / €43M balance sheet? Above that line, you’re generally an essential entity facing proactive RDI supervision and the full Article 21(2) measure set.
- Step 3 — Below-threshold check. Smaller but still market-relevant energy entities may still qualify as important entities under reactive supervision — the exact criteria are in our essential vs. important breakdown.
- Step 4 — NCCS check. Are you a TSO, DSO, large generator, aggregator, or another entity type that could meet a “high” or “critical” ECII impact rating? If so, expect a separate NCCS designation letter from RDI — CBW compliance does not cover it, and NCCS compliance does not cover your CBW obligations either.
Your Compliance Timeline Before 15 August 2026
What you need to do next depends on your role, not just your entity type:
- Compliance officers and SME owners: plan to complete entity registration once the CBW takes effect, and confirm — don’t assume — whether an NCCS designation letter has arrived from RDI separately from your CBW obligations.
- CISOs and OT security leads: map your Article 21(2) measures against existing OT/SCADA controls first. If you’re NCCS-designated, cross-check its distinct technical requirements separately — satisfying one framework’s controls doesn’t automatically satisfy the other’s.
- Boards: budget for two possible audit tracks, not one — RDI’s CBW supervisory powers alongside a separate NCCS technical assessment where applicable.
Non-compliance exposure under the CBW follows the same penalty structure as other essential entities in the Netherlands — see our full Dutch NIS2 penalty breakdown for the fine tiers and enforcement gap.
Frequently Asked Questions
Is ACM still involved in Dutch energy cybersecurity at all?
Not for cybersecurity supervision as of 1 January 2026 — RDI now enforces both the CBW and NCCS for Dutch energy entities. ACM remains the Netherlands’ general energy market regulator for non-cybersecurity matters such as tariffs and grid codes.
Does an NCCS designation automatically make me a NIS2 essential entity?
No. NCSC-NL is explicit that the two designations are independent — one does not trigger the other.
If TenneT’s German entity is NIS2-compliant, does that cover the Dutch entity?
No. TenneT TSO B.V. (Netherlands) and TenneT TSO GmbH (Germany) are separate legal entities under separate national regimes (RDI/CBW and BSI/Germany’s NIS2 law, respectively) — each must comply independently.
When does the Cyberbeveiligingswet actually take effect?
15 August 2026, replacing the previous Wbni.
Sources
- NIS2 Directive, Article 3 — Essential and important entities: nis-2-directive.com
- Directive (EU) 2022/2555 (NIS2), consolidated text: EUR-Lex
- NIS2 Directive, Article 26 — Jurisdiction (nis2resources.eu, linked in-article)
- Cyberbeveiligingswet overview (RDI, linked in-article)
- Netcode voor Cybersecurity — ACM-to-RDI transition (RDI, linked in-article)
- Toezicht digitale weerbaarheid in de energiesector in 2026: RDI
- Network Code on Cybersecurity (NCCS) overview (NCSC-NL, linked in-article)
- Cybersecurity network code for electricity (ACER, linked in-article)
- TenneT corporate and ownership structure: Wikipedia
- Gasunie corporate and network structure: Wikipedia
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
