---
title: "Dutch Cybersecurity Act (NIS2): access management explained"
description: "The Dutch NIS2 law and your access policy: what article 15 of the Cybersecurity Decree requires, where MFA comes in and what your sector regulation adds."
image: https://www.fuselogic.nl/hubfs/Blog/cyberbeveiligingswet-toegangsbeheer/cyberbeveiligingswet-toegangsbeheer-og-en.png
---

[![FuseLogic](https://www.fuselogic.nl/hubfs/Assets/Logo/fuselogic-logo.svg "Back to home")](https://www.fuselogic.nl/en/) [![FuseLogic](https://www.fuselogic.nl/hubfs/Assets/Logo/fuselogic-logo-white.svg "Back to home")](https://www.fuselogic.nl/en/)

 Challenges

[Organizational dynamics Organizational dynamics leads to security risks](https://www.fuselogic.nl/en/organizational-dynamics) [Brake on digital transformation Traditional IAM approaches don't meet the needs of modern, agile organizations](https://www.fuselogic.nl/en/digital-transformation) [Poor first day experience Without access to IT resources, a new employee can't get productive from day one](https://www.fuselogic.nl/en/blog-news/first-day-experience)

[Control over cloud identities Keep control over who has access to an ever-growing number of apps and data in the cloud](https://www.fuselogic.nl/en/identity-management-cloud) [Keeping access under control How do you maintain oversight of who has access to which applications and data?](https://www.fuselogic.nl/en/secure-access-applications) [Identity management adoption Getting buy-in requires showing concrete results quickly](https://www.fuselogic.nl/en/identity-management-adoption)

 Get started

 Ready for an efficient and fast approach?

[Schedule a call](https://www.fuselogic.nl/en/contact) ![Design icon](https://www.fuselogic.nl/hubfs/Assets/Icons/design-element-3.svg)

 Solutions

[Identity & Access Management Quickly gain control over access to applications and data](https://www.fuselogic.nl/en/identity-access-management) [Identity Governance & Administration Efficiently set up and maintain Identity Governance](https://www.fuselogic.nl/en/identity-governance-administration) [Customer Identity & Access Management Improve the digital experience of your customers with CIAM](https://www.fuselogic.nl/en/customer-identity-access-management) [Identity Management integration Fast integration in your IT landscape, with minimal impact](https://www.fuselogic.nl/en/identity-management-integration)

[Okta implementation Take your digital experience to the next level with Okta](https://www.fuselogic.nl/en/okta-implementation) [Passwordless login Passwordless login is faster, easier and just as secure](https://www.fuselogic.nl/en/passwordless-login) [SSO and MFA Better protected with SSO and MFA, without compromising on ease of use](https://www.fuselogic.nl/en/sso-mfa)

 Get started

 Ready for an efficient and fast approach?

[Schedule a call](https://www.fuselogic.nl/en/contact) ![Design icon](https://www.fuselogic.nl/hubfs/Assets/Icons/design-element-3.svg)

[Case studies](https://www.fuselogic.nl/en/case-studies)

[About FuseLogic](https://www.fuselogic.nl/en/about-us)

[Who is FuseLogic? We deliver Identity Management solutions at the speed of business](https://www.fuselogic.nl/en/about-us) [Our approach Our unique *at the speed of business*- approach for Identity Management and Identity Governance](https://www.fuselogic.nl/en/blog-news/speedofbusiness) [How does it work? How does Identity Management *at the speed of business?* work?](https://www.fuselogic.nl/en/blog-news/how-identity-management-works)

[Careers at FuseLogic We are always looking for colleagues with IAM experience and a cloud mindset to strengthen our team](https://www.fuselogic.nl/en/careers-at-fuselogic)

 Choose speed

 Ready to get started?

[Schedule a call](https://www.fuselogic.nl/en/contact) ![Design icon](https://www.fuselogic.nl/hubfs/Assets/Icons/design-element-3.svg)

[Blog](https://www.fuselogic.nl/en/blog-news)

[Contact](https://www.fuselogic.nl/en/contact)

[NL](https://www.fuselogic.nl/blog-nieuws/cyberbeveiligingswet-toegangsbeheer) | EN 

[Schedule a call](https://www.fuselogic.nl/en/contact)

[![FuseLogic](https://www.fuselogic.nl/hubfs/Assets/Logo/fuselogic-logo.svg "Back to home")](https://www.fuselogic.nl/en/) [![FuseLogic](https://www.fuselogic.nl/hubfs/Assets/Logo/fuselogic-logo-white.svg "Back to home")](https://www.fuselogic.nl/en/)

 Challenges

[Organizational dynamics Organizational dynamics leads to security risks](https://www.fuselogic.nl/en/organizational-dynamics) [Brake on digital transformation Traditional IAM approaches don't meet the needs of modern, agile organizations](https://www.fuselogic.nl/en/digital-transformation) [Poor first day experience Without access to IT resources, a new employee can't get productive from day one](https://www.fuselogic.nl/en/blog-news/first-day-experience)

[Control over cloud identities Keep control over who has access to an ever-growing number of apps and data in the cloud](https://www.fuselogic.nl/en/identity-management-cloud) [Keeping access under control How do you maintain oversight of who has access to which applications and data?](https://www.fuselogic.nl/en/secure-access-applications) [Identity management adoption Getting buy-in requires showing concrete results quickly](https://www.fuselogic.nl/en/identity-management-adoption)

 Get started

 Ready for an efficient and fast approach?

[Schedule a call](https://www.fuselogic.nl/en/contact) ![Design icon](https://www.fuselogic.nl/hubfs/Assets/Icons/design-element-3.svg)

 Solutions

[Identity & Access Management Quickly gain control over access to applications and data](https://www.fuselogic.nl/en/identity-access-management) [Identity Governance & Administration Efficiently set up and maintain Identity Governance](https://www.fuselogic.nl/en/identity-governance-administration) [Customer Identity & Access Management Improve the digital experience of your customers with CIAM](https://www.fuselogic.nl/en/customer-identity-access-management) [Identity Management integration Fast integration in your IT landscape, with minimal impact](https://www.fuselogic.nl/en/identity-management-integration)

[Okta implementation Take your digital experience to the next level with Okta](https://www.fuselogic.nl/en/okta-implementation) [Passwordless login Passwordless login is faster, easier and just as secure](https://www.fuselogic.nl/en/passwordless-login) [SSO and MFA Better protected with SSO and MFA, without compromising on ease of use](https://www.fuselogic.nl/en/sso-mfa)

 Get started

 Ready for an efficient and fast approach?

[Schedule a call](https://www.fuselogic.nl/en/contact) ![Design icon](https://www.fuselogic.nl/hubfs/Assets/Icons/design-element-3.svg)

[Case studies](https://www.fuselogic.nl/en/case-studies)

[About FuseLogic](https://www.fuselogic.nl/en/about-us)

[Who is FuseLogic? We deliver Identity Management solutions at the speed of business](https://www.fuselogic.nl/en/about-us) [Our approach Our unique *at the speed of business*- approach for Identity Management and Identity Governance](https://www.fuselogic.nl/en/blog-news/speedofbusiness) [How does it work? How does Identity Management *at the speed of business?* work?](https://www.fuselogic.nl/en/blog-news/how-identity-management-works)

[Careers at FuseLogic We are always looking for colleagues with IAM experience and a cloud mindset to strengthen our team](https://www.fuselogic.nl/en/careers-at-fuselogic)

 Choose speed

 Ready to get started?

[Schedule a call](https://www.fuselogic.nl/en/contact) ![Design icon](https://www.fuselogic.nl/hubfs/Assets/Icons/design-element-3.svg)

[Blog](https://www.fuselogic.nl/en/blog-news)

[Contact](https://www.fuselogic.nl/en/contact)

[NL](https://www.fuselogic.nl/blog-nieuws/cyberbeveiligingswet-toegangsbeheer) | EN 

[Schedule a call](https://www.fuselogic.nl/en/contact)

[![logo](https://www.fuselogic.nl/hubfs/Assets/Logo/fuselogic-logo.svg)](https://www.fuselogic.nl/en/)

[Schedule a call](https://www.fuselogic.nl/en/contact)

[![logo](https://www.fuselogic.nl/hubfs/Assets/Logo/fuselogic-logo.svg)](https://www.fuselogic.nl/en/)

[Schedule a call](https://www.fuselogic.nl/en/contact)

[![logo](https://www.fuselogic.nl/hubfs/Assets/Logo/fuselogic-logo.svg)](https://www.fuselogic.nl/en/)

[Schedule a call](https://www.fuselogic.nl/en/contact)

 Challenges

[Organizational dynamics](https://www.fuselogic.nl/en/organizational-dynamics) [Digital transformation](https://www.fuselogic.nl/en/digital-transformation) [First day experience](https://www.fuselogic.nl/en/blog-news/first-day-experience) [Identity Management in the cloud](https://www.fuselogic.nl/en/identity-management-cloud) [Access under control](https://www.fuselogic.nl/en/secure-access-applications) [Identity management adoption](https://www.fuselogic.nl/en/identity-management-adoption)

 Solutions

[Identity & Access Management](https://www.fuselogic.nl/en/identity-access-management) [Identity Governance & Administration](https://www.fuselogic.nl/en/identity-governance-administration) [Customer Identity & Access Management](https://www.fuselogic.nl/en/customer-identity-access-management) [Identity Management integration Fast integration in your IT landscape, with minimal impact](https://www.fuselogic.nl/en/identity-management-integration) [Okta implementation](https://www.fuselogic.nl/en/okta-implementation) [Passwordless login](https://www.fuselogic.nl/en/passwordless-login) [SSO & MFA](https://www.fuselogic.nl/en/sso-mfa)

[Case studies](https://www.fuselogic.nl/case-studies)

 About FuseLogic

[Who is FuseLogic?](https://www.fuselogic.nl/en/about-us) [Careers at FuseLogic](https://www.fuselogic.nl/en/careers-at-fuselogic) [Our approach](https://www.fuselogic.nl/en/blog-news/speedofbusiness) [How does it work?](https://www.fuselogic.nl/en/blog-news/how-identity-management-works)

[Blog](https://www.fuselogic.nl/en/blog-news)

[Contact](https://www.fuselogic.nl/en/contact) 

[Schedule a call](https://www.fuselogic.nl/en/contact)

[Back](https://www.fuselogic.nl/en/blog-news)

[Blog](https://www.fuselogic.nl/en/blog-news/tag/blog) [Identity Management](https://www.fuselogic.nl/en/blog-news/tag/identity-management) Reading time 11 min

# The Dutch Cybersecurity Act explained: what it means for access management

On 15 August 2026, new cybersecurity legislation came into force: [the Cyberbeveiligingswet](https://wetten.overheid.nl/BWBR0052872/2026-08-15), the Dutch Cybersecurity Act. With it, the Netherlands implements the European NIS2 Directive. The Act is meant to ensure that organisations providing essential or important services have their digital security in order and are prepared for risks that could interrupt those services.

![FuseLogic](https://www.fuselogic.nl/hubfs/Assets/Template%20images/hero-team-picture.jpg)

**FuseLogic**

![Cybersecurity Decree article 15: access policy](https://www.fuselogic.nl/hs-fs/hubfs/Blog/cyberbeveiligingswet-toegangsbeheer/cyberbeveiligingswet-toegangsbeheer-hero-en.png?width=1200) ![](https://www.fuselogic.nl/hubfs/Assets/Icons/design-element-white-square.svg) ![](https://www.fuselogic.nl/hubfs/Assets/Icons/design-element-3.svg)

15 Aug 2026

Dutch Cybersecurity Act in force

Over 8,000

organisations with new obligations

18

sectors

On this page

1. [What is the Dutch Cybersecurity Act and does it apply to you?](https://www.fuselogic.nl/en/blog-news/dutch-cybersecurity-act-access-management#what-is-the-act)
2. [What does the Act ask of your access policy, and where does it mention MFA?](https://www.fuselogic.nl/en/blog-news/dutch-cybersecurity-act-access-management#access-policy-and-mfa)
3. [Do you currently meet the requirement to make access management demonstrable?](https://www.fuselogic.nl/en/blog-news/dutch-cybersecurity-act-access-management#demonstrable)
4. [What does your sector regulation say about admin accounts?](https://www.fuselogic.nl/en/blog-news/dutch-cybersecurity-act-access-management#sector-regulation)
5. [Frequently asked questions](https://www.fuselogic.nl/en/blog-news/dutch-cybersecurity-act-access-management#faq)

[Discuss your access policy](https://www.fuselogic.nl/en/contact)

According to the Dutch government, [more than 8,000 organisations in the Netherlands](https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht) now face new cybersecurity obligations, spread across 18 sectors such as energy, drinking water, healthcare and transport. If your organisation is in scope, you must register with the Dutch NCSC and report significant incidents. The board is ultimately responsible for cyber risk.

You also have to take measures to secure your systems. That's called the duty of care, and access policy is one of those measures. In practice, it means you record who may access which systems and can demonstrate that this is how it actually works. And that you regularly check whether it's still right, for example when a colleague has changed roles but kept their old rights, or when someone has left the company but still has an active account (article 15 of the Cybersecurity Decree). For some organisations, a sector regulation comes on top of that.

## What is the Dutch Cybersecurity Act and does it apply to you?

### What it is

The Cyberbeveiligingswet is the Dutch implementation of the European NIS2 Directive. The EU adopts the directive and the Netherlands turns it into obligations that apply here. The Cyberbeveiligingswet is the Act itself and [the Cyberbeveiligingsbesluit](https://wetten.overheid.nl/BWBR0052875/2026-08-15), the Cybersecurity Decree, works it out in detail. The part about access is [identity and access management](https://www.fuselogic.nl/en/identity-access-management): who may access which system and who keeps track of that.

### Since when

Since 15 August 2026. The Act itself is in the Bulletin of Acts and Decrees, [Staatsblad 2026, 187](https://zoek.officielebekendmakingen.nl/stb-2026-187.html). The decree that sets that date is in [Staatsblad 2026, 189](https://zoek.officielebekendmakingen.nl/stb-2026-189.html). Different timelines apply to directors and to designated higher education institutions (article 24 and article 97).

### Who it applies to

The Act has two categories: essential entities and important entities. Both carry the same basic obligations. Whether the Act applies to you usually depends on your sector and size. Use [the NCSC's steps](https://www.ncsc.nl/cyberbeveiligingswet-nis2/valt-mijn-organisatie-onder-de-cyberbeveiligingswet-nis2) to work out whether you're in scope and whether you're essential or important. The [referral tree](https://www.ncsc.nl/api/media/sites/default/files/Doorverwijsboom%20Cyberbeveiligingswet%202026_0.pdf) shows which supervisory authority belongs to your sector. If you fall under a European sector law such as DORA, the consequences are set out [by the NCSC](https://www.ncsc.nl/cyberbeveiligingswet-nis2/meldplicht); that route isn't a full exemption from the Dutch Cybersecurity Act.

### One exception to article 15

For eleven types of digital service providers, from cloud services to online marketplaces, European rules apply instead of the Dutch implementation. The full list is in the FAQ at the bottom.

## What does the Act ask of your access policy, and where does it mention MFA?

The measures must be appropriate and proportionate (article 21), and what's appropriate depends on the risks you face, the state of the art, the cost and the size of your organisation. That weighing does have a floor. The Decree lists a set of measures you must take in all cases (article 5), and access policy is one of them (article 15).

Article 15 then asks three things of you.

1. 1
   
   ### Record it
   
   An established policy on logical and physical access to your network and information systems, set down in writing and demonstrably applied (paragraph 1). A policy that only exists in people's heads doesn't meet the first requirement, and a policy that's on paper but isn't visibly carried out doesn't meet the second.
2. 2
   
   ### What it covers at a minimum
   
   The policy covers "at least" the issuing, monitoring, use, modification and revocation of identities and authorisations, and the management of all of that (paragraph 2; quotations from Dutch legislation are our translation). That's a floor, not an exhaustive list. The Decree doesn't put it this way, but this is mainly about setting up the [joiner-mover-leaver process (JML)](https://www.fuselogic.nl/en/identity-management-integration) correctly.
3. 3
   
   ### Keep it up to date
   
   You periodically check identities, authentication means and authorisations for necessity, accuracy and currency. Where something isn't right, you make the changes (paragraph 3).

### Multi-factor authentication is a different matter

Access policy is a measure you must take in all cases; MFA is a judgement call. The word doesn't appear in the articles of the Decree, so it isn't in article 15 either. It's in the Act, in [article 21(3)(j)](https://wetten.overheid.nl/BWBR0052872/2026-08-15), and that provision opens with "where appropriate". The access policy in article 15 carries no such qualification. Where SSO and MFA fit into that picture is on our page about [single sign-on and multi-factor authentication](https://www.fuselogic.nl/en/sso-mfa).

## Do you currently meet the requirement to make access management demonstrable?

One test to start with: can you show today who has access to which system, without someone spending a week on it? "Demonstrable" (aantoonbaar) is the Decree's own word, not a term we've added. Paragraph 1 requires you to apply the policy demonstrably, and what isn't recorded anywhere can't be demonstrated. This is how we go about it.

- ### Record the policy
  
  A document with an owner and a date of last review, not an intranet page that nobody maintains.
- ### Document issuing and revocation
  
  Process documentation of the JML process, plus logging that shows who got which access when and when it was removed again.
- ### Separate requesting from approving
  
  Segregation of duties, so the person who requests a right isn't also the person who approves it.
- ### Record the access reviews themselves
  
  Who approved what, and what was revoked as a result. Without that record, you can't trace the previous round.

This is our approach, not a list from the Decree. The Decree leaves the details open and puts the burden of demonstrating it on the entity. If you'd rather build up that evidence automatically than reconstruct it afterwards, you end up with [identity governance and access certifications](https://www.fuselogic.nl/en/identity-governance-administration).

## What does your sector regulation say about admin accounts?

Ministers may set further rules for their own sector on the measures the Act requires (article 19), and for a number of sectors they have. Four of those regulations carry their own provision on admin accounts, where article 15 is silent on them.

What those four regulations add is strong identification, authentication and authorisation procedures for those accounts, and admin rights that are granted "individualised and restricted as far as possible" and used only for system administration. "As far as possible" is a best-efforts obligation, not an absolute requirement. The explanatory notes to the regulation of the Ministry of Agriculture, Fisheries, Food Security and Nature (LVVN) also state that the requirement to set up specific system administration accounts has been dropped, and that the article therefore allows privileges to be raised temporarily, for example through Privileged Identity Management.

For public administration and healthcare, it runs through standards instead of this article, and for public administration that doesn't mean less. [The BIO2 version 1.3](https://www.bio-overheid.nl/media/dr4inbhc/20260109-baseline-informatiebeveiliging-overheid-2-bio2-v13-def.pdf) does set intervals. Special privileges are reviewed at least every quarter (measure 8.02.01), all issued access rights at least once a year (5.18.02). So where the Decree only says "periodically", the BIO2 has numbers. The public administration regulation does allow those measures to be replaced by another framework of standards that offers at least an equivalent level of security, provided you can demonstrate both the need for it and that equivalence. The quarter is a standard with a way out, not a legal deadline.

| Regulation by | Where to find it | What it says about admin accounts |
| --- | --- | --- |
| Infrastructure and Water Management | [Staatscourant 2026, 24093, article 13](https://zoek.officielebekendmakingen.nl/stcrt-2026-24093.html) | The policy from article 15(1) also covers privileged accounts and system administration accounts |
| Energy | [Staatscourant 2026, 22078, article 45](https://zoek.officielebekendmakingen.nl/stcrt-2026-22078.html) | The same provision |
| Economic Affairs and Climate Policy | [Staatscourant 2026, 25627, article 6](https://zoek.officielebekendmakingen.nl/stcrt-2026-25627.html) | The same provision |
| Agriculture, Fisheries, Food Security and Nature | [Staatscourant 2026, 25478, article 6](https://zoek.officielebekendmakingen.nl/stcrt-2026-25478.html) | The same provision |
| Public administration | [Staatscourant 2026, 27679, article 5](https://zoek.officielebekendmakingen.nl/stcrt-2026-27679.html) | Doesn't carry that provision, but makes ISO 27002 and the BIO2 version 1.3 binding, with a quarterly review. Applies to essential entities in the public administration sector except water authorities; for water authorities, the Infrastructure and Water Management regulation makes the same standards binding |
| Healthcare, plus manufacture of medical devices | [Staatscourant 2026, 28763, article 2.1](https://zoek.officielebekendmakingen.nl/stcrt-2026-28763.html) | A choice between NEN 7510, ISO 27001 with ISO 27002 or a demonstrably equivalent level of protection |

The left-hand column names the regulation, not your sector. Which sectors and subsectors it covers is set out in the regulation's own scope provision, and that can be narrower than you'd expect. The Infrastructure and Water Management regulation, for example, only applies this section to entities that aren't government organisations.

If your sector is one of those four, admin access is no longer something you fill in yourself but a written requirement. What that requirement means in your own environment is yours to work out, and that work falls under [identity governance and administration](https://www.fuselogic.nl/en/identity-governance-administration).

If you get stuck, we're happy to take a look at the access part with you: what's in place, what's missing and what the first step is.

[Let us take a look](https://www.fuselogic.nl/en/contact) ![](https://www.fuselogic.nl/hubfs/Assets/Icons/design-element-3.svg)

## Frequently asked questions

### What does the Act require of access policy, and is MFA mandatory?

Two different things. Article 15 of the Cybersecurity Decree requires an access policy that's set down in writing and demonstrably applied, with periodic review, and it has no "where appropriate". MFA isn't mandatory in every case, but the Act does name it: article 21(3)(j) speaks of "multi-factor authentication or continuous authentication solutions", preceded by "where appropriate". Whether it's appropriate for you is something you weigh against the risks you face. A complex password isn't an alternative the Act mentions, because it's one factor. Four ministerial regulations currently add a requirement on privileged accounts on top of that; searching can't rule out that a fifth exists. For public administration and healthcare, the regulations run through the BIO2, NEN 7510 or ISO 27001, and for public administration that includes a quarterly review of special privileges, with the option to use another framework if you can demonstrate need and equivalence.

### Who does article 15 not apply to?

Article 4 of the Decree declares articles 6 to 18 inapplicable to eleven categories of entities. If you fall into one of them, you measure yourself against [Implementing Regulation (EU) 2024/2690](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R2690) and not against article 15:

- DNS service providers
- TLD name registries
- cloud computing service providers
- data centre service providers
- content delivery network providers
- managed service providers
- managed security service providers
- providers of online marketplaces
- providers of online search engines
- providers of social networking services platforms
- trust service providers

That isn't an exemption. The heading of article 4 reads "relationship to Implementing Regulation (EU) 2024/2690": for these eleven, that European regulation sets the requirements, not the Dutch implementation. It prescribes access control in more detail than article 15, with need-to-know, least privilege, segregation of duties and a separate policy section for privileged accounts and system administration accounts. MFA is in there too with "where appropriate", but anyone relying on that has to document their reasoning in a comprehensible way (article 2(2)), and strong authentication for privileged accounts is in there without the "where appropriate" qualification. The regulation does place a general proportionality standard above this, in article 2(2).

Article 21 of the Act can also be disapplied under article 22 and article 23. That's general exemption law and not an access question; have your lawyer look at it.

### Can FuseLogic make us NIS2 compliant?

No, not for the whole Act. We're IAM specialists and work on the access part, one of the obligations the Act imposes.

Article 15 of the Cybersecurity Decree requires an access policy that's set down in writing and demonstrably applied, covering the issuing and revocation of identities and authorisations, with periodic review. That applies if the article applies to your organisation. That's where we focus our work: the JML process, the access reviews, segregation of duties and the logging that records who got which access when and when it was removed again.

The legal side, from sector classification to the reporting process and supervision, is for your lawyer or compliance adviser.

#### Subscribe to FuseLogic news and updates

![Design icon](https://www.fuselogic.nl/hubfs/Assets/Icons/design-element-3.svg)

 Share 

<https://www.linkedin.com/shareArticle?url=https://www.fuselogic.nl/en/blog-news/dutch-cybersecurity-act-access-management> <https://twitter.com/intent/tweet?text=https://www.fuselogic.nl/en/blog-news/dutch-cybersecurity-act-access-management> [mailto:info@example.com?&subject=&body=https://www.fuselogic.nl/en/blog-news/dutch-cybersecurity-act-access-management](mailto:info@example.com?&subject=&body=https://www.fuselogic.nl/en/blog-news/dutch-cybersecurity-act-access-management) <https://wa.me/?text=https://www.fuselogic.nl/en/blog-news/dutch-cybersecurity-act-access-management>

![FuseLogic](https://www.fuselogic.nl/hubfs/Assets/Template%20images/hero-team-picture.jpg)

**FuseLogic,**

 Based on more than 18 years of experience, we have developed best practices to accelerate Identity Management projects. We deliver Identity Management solutions. But faster, easier and cheaper. As a result, you are quickly 'in control' and Identity Management follows the speed of the business, rather than the other way around.

## Related posts

### [![Cybersecurity Decree article 15: access policy](https://www.fuselogic.nl/hubfs/Blog/cyberbeveiligingswet-toegangsbeheer/cyberbeveiligingswet-toegangsbeheer-og-en.png) ![Design icon](https://www.fuselogic.nl/hubfs/Assets/Icons/design-element-3.svg) Blog Identity Management The Dutch Cybersecurity Act explained: what it means for access management Read more](https://www.fuselogic.nl/en/blog-news/dutch-cybersecurity-act-access-management)

### [![Joost Koiter van FuseLogic spreekt op het podium tijdens de Okta AI Identity Summit](https://www.fuselogic.nl/hubfs/Events/2026-okta-ai-event/okta-ai-summit-joost-koiter-hero.jpg) ![Design icon](https://www.fuselogic.nl/hubfs/Assets/Icons/design-element-3.svg) Blog Okta Giving AI agents access to five kinds of systems, one approach Read more](https://www.fuselogic.nl/en/blog-news/ai-agent-access-five-systems)

### [![FuseLogic collega's bij een klant op kantoor](https://www.fuselogic.nl/hubfs/social-suggested-images/www.fuselogic.nlhubfsHero%20images%20882x720fuselogic-sfeerfoto-1998%20(Aangepast)-2.jpg) ![Design icon](https://www.fuselogic.nl/hubfs/Assets/Icons/design-element-3.svg) Blog What you can learn from the Odido breach Read more](https://www.fuselogic.nl/en/blog-news/odido-breach-phishing-resistant-mfa)

![FuseLogic](https://www.fuselogic.nl/hubfs/Assets/Icons/design-element-4.svg)

###### SOLUTION PAPER

### Identity Management *at the speed of business*

FuseLogic delivers Identity Management *at the speed of business*: faster and simpler, without compromising on security or ease of use. Download our free solution paper and discover how your organization can achieve this too.

[Download your solution paper](https://www.fuselogic.nl/en/solutionpaper-identity-management-speed-business)

[![FuseLogic](https://www.fuselogic.nl/hubfs/Assets/Logo/fuselogic-logo.svg)](https://www.fuselogic.nl/en/)

The leading Okta partner with over 18 years of experience

### Office

Olympia 2D  
 1213 NT Hilversum  
 Netherlands

[035 - 20 40 043](tel:+31352040043)  
[Info@fuselogic.nl](mailto:info@fuselogic.nl)

### Challenges

[Organizational dynamics](https://www.fuselogic.nl/en/organizational-dynamics) [Digital transformation roadblocks](https://www.fuselogic.nl/en/digital-transformation) [First day experience](https://www.fuselogic.nl/en/blog-news/first-day-experience) [IAM in the cloud](https://www.fuselogic.nl/en/identity-management-cloud) [Keeping access under control](https://www.fuselogic.nl/en/secure-access-applications) [Identity Management integration](https://www.fuselogic.nl/en/identity-management-integration)

### Solutions

[Identity Management](https://www.fuselogic.nl/en/identity-access-management) [Identity Governance](https://www.fuselogic.nl/en/identity-governance-administration) [Customer IAM](https://www.fuselogic.nl/en/customer-identity-access-management) [Okta implementation](https://www.fuselogic.nl/en/okta-implementation) [Passwordless](https://www.fuselogic.nl/en/passwordless-login) [SSO and MFA](https://www.fuselogic.nl/en/sso-mfa)

### FuseLogic

[Case studies](https://www.fuselogic.nl/en/case-studies) [Blog](https://www.fuselogic.nl/en/blog-news) [About FuseLogic](https://www.fuselogic.nl/en/about-us) [Our approach](https://www.fuselogic.nl/en/blog-news/speedofbusiness) [Contact](https://www.fuselogic.nl/en/contact) [Careers](https://www.fuselogic.nl/en/careers-at-fuselogic)

### Receive our tips & updates

 © 2026 FuseLogic

[Privacy statement](https://www.fuselogic.nl/en/privacy-statement)

[NL](https://www.fuselogic.nl/blog-nieuws/cyberbeveiligingswet-toegangsbeheer) | EN

<https://www.linkedin.com/company/fuselogic/>

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "FuseLogic",
    "url" : "https://www.fuselogic.nl/en/blog-news/author/fuselogic"
  },
  "datePublished" : "2026-10-06T09:13:01.000Z",
  "headline" : "Dutch Cybersecurity Act (NIS2): access management explained",
  "image" : [ "https://www.fuselogic.nl/hubfs/Blog/cyberbeveiligingswet-toegangsbeheer/cyberbeveiligingswet-toegangsbeheer-og-en.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.fuselogic.nl/en/blog-news/dutch-cybersecurity-act-access-management",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.fuselogic.nl/hubfs/Fuselogic%20logo.png"
    },
    "name" : "FuseLogic B.V."
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "<p>Two different things. Article 15 of the Cybersecurity Decree requires an access policy that's set down in writing and demonstrably applied, with periodic review, and it has no \"where appropriate\". MFA isn't mandatory in every case, but the Act does name it: article 21(3)(j) speaks of \"multi-factor authentication or continuous authentication solutions\", preceded by \"where appropriate\". Whether it's appropriate for you is something you weigh against the risks you face. A complex password isn't an alternative the Act mentions, because it's one factor. Four ministerial regulations currently add a requirement on privileged accounts on top of that; searching can't rule out that a fifth exists. For public administration and healthcare, the regulations run through the BIO2, NEN 7510 or ISO 27001, and for public administration that includes a quarterly review of special privileges, with the option to use another framework if you can demonstrate need and equivalence.</p>"
    },
    "name" : "What does the Act require of access policy, and is MFA mandatory?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "<p>Article 4 of the Decree declares articles 6 to 18 inapplicable to eleven categories of entities. If you fall into one of them, you measure yourself against <a href=\"https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R2690\" target=\"_blank\" rel=\"noopener\">Implementing Regulation (EU) 2024/2690</a> and not against article 15:</p>\n<ul><li>DNS service providers</li><li>TLD name registries</li><li>cloud computing service providers</li><li>data centre service providers</li><li>content delivery network providers</li><li>managed service providers</li><li>managed security service providers</li><li>providers of online marketplaces</li><li>providers of online search engines</li><li>providers of social networking services platforms</li><li>trust service providers</li></ul>\n<p>That isn't an exemption. The heading of article 4 reads \"relationship to Implementing Regulation (EU) 2024/2690\": for these eleven, that European regulation sets the requirements, not the Dutch implementation. It prescribes access control in more detail than article 15, with need-to-know, least privilege, segregation of duties and a separate policy section for privileged accounts and system administration accounts. MFA is in there too with \"where appropriate\", but anyone relying on that has to document their reasoning in a comprehensible way (article 2(2)), and strong authentication for privileged accounts is in there without the \"where appropriate\" qualification. The regulation does place a general proportionality standard above this, in article 2(2).</p>\n<p>Article 21 of the Act can also be disapplied under article 22 and article 23. That's general exemption law and not an access question; have your lawyer look at it.</p>"
    },
    "name" : "Who does article 15 not apply to?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "<p>No, not for the whole Act. We're IAM specialists and work on the access part, one of the obligations the Act imposes.</p>\n<p>Article 15 of the Cybersecurity Decree requires an access policy that's set down in writing and demonstrably applied, covering the issuing and revocation of identities and authorisations, with periodic review. That applies if the article applies to your organisation. That's where we focus our work: the JML process, the access reviews, segregation of duties and the logging that records who got which access when and when it was removed again.</p>\n<p>The legal side, from sector classification to the reporting process and supervision, is for your lawyer or compliance adviser.</p>"
    },
    "name" : "Can FuseLogic make us NIS2 compliant?"
  } ]
}
```