Knowledge base

September 23, 2026

One Month of the Cybersecurity Act: A Review—and the Date Almost No One Notices

On September 15, the Cybersecurity Act had been in effect for exactly one month. Time to take stock. Not in terms of news headlines—since there were hardly any—but in terms of real-world experience: what happened, what didn’t happen, and what that means for those who supply products and services to major clients.

The report on the first week can be found in the blog post about the first week. This blog post looks at the entire month, at the regulator that has documented its working methods, and at a second piece of legislation with a date that almost no one has on their radar: the AI Act, on December 2.

The lesson from Month One can be summed up in one sentence: the law enforces itself through contracts, not through inspectors. And contracts are more patient than news headlines, but less patient than you might think.

What Happened

Three things, all out of sight of the doorbell.

The entity registry opened, and at the start, the number of registered entities was less than half of the estimated eight to ten thousand organizations required to register. Registration does not prove compliance. It proves that you know you are subject to the law, and that is the first question a regulator and a major client will ask.

The “My Cyber-Resilient Business” grant portal reopened in early September, with a requirement that aligns perfectly with this law: assess the situation yourself first, then apply for a measure. Anyone who wants to have a measure reimbursed must specify on the invoice which measure it is, as required by RVO.

And in our own scans, two out of three domains fail to meet the “Good” threshold—four assessments in a row. The most commonly missed component is also the cheapest to fix. The figures and methodology are detailed in the blog post about the assessment.

What Didn’t Happen

Fines, raids, panic. That’s never how the first month of a law goes. We didn’t find a single enforcement report in the first month, and we say this with due humility: not finding something isn’t proof that nothing happened. What is there is more important than a report about a fine.

Supervision in phases is no supervision at all

The RDI, the regulatory authority for most sectors covered by this law, has outlined how it operates. Essential organizations are subject to proactive oversight, even in the absence of an incident. Important organizations are primarily subject to retrospective oversight, for example, following a report. And organizations with robust security measures are less likely to come under scrutiny.

That’s not a delay—it’s a sequence. First, the sectors where disruptions hit hardest; then the rest. It’s exactly the order in which a major customer evaluates its suppliers. The companies that are building now will be ready soon, and the rest will be in a hurry later. We’ve already seen that play out with the GDPR.

The lists are getting smarter

A supply chain questionnaire gets smarter with each round because the person who creates it learns. The first version asks yes or no questions. Do you have MFA? Yes. The second version asks: Show which rule applies, and for whom. The third version asks for the date of your last recovery test, along with the result. Not because the creator distrusts you, but because he himself must demonstrate that his suppliers operate safely, and a “yes” without a source doesn’t help with that.

The blog on the supply chain questionnaire explains how to tackle such a list without a compliance team. The blog on the basic file explains which four documents cover the majority of the requirements. And the blog on the internal process explains how to convert “MFA is enabled” into a dated entry. Waiting won’t make the problem any smaller. It will only make the backlog bigger.

The Other Law: December 2

The AI Act has a date that almost no one has on their radar: December 2, 2026. Starting then, even generative AI systems that were already on the market before August 2 will be required to mark their output as machine-readable. For new systems, this requirement has been in effect since August 2. The transition period is specified in the Digital Omnibus, the amending regulation that took effect on July 27.

Machine-readable marking, in plain language: you’re already familiar with visible marking—the “made with AI” label on an image. Machine-readable means that software can also detect it—a watermark or metadata embedded in the file itself—so that platforms and tools can automatically recognize AI-generated content.

The responsibility lies with the tool provider, not with you as the user. But one thing remains your responsibility: if you publish a photorealistic image of a person or event created by AI, you must disclose that fact. So for you, the question is simple: which AI tools does your organization use, and what are they already doing on their own? That is exactly what an AI registry is for. For more details on what does and does not apply to small and medium-sized businesses, see the blog post about the AI Act.

The construction phase has begun

In July, every conversation was about the law itself. What does it mean? Does it apply to me? What if I don’t do anything? By September, almost none of the conversations are about the law itself anymore. They’re about documents, questionnaires, and deadlines. That’s a good thing. Laws are supposed to fade into the background as part of everyday work.

And the question we’re asked most often remains the same: Where do I actually stand?

Two things you can do in ten minutes

Checking your appearance. The Security Check only assesses what is visible to the public—it doesn’t cover your surroundings or safety measures—but it does assess, in thirty seconds, what your client can already see for themselves.

Documenting Your AI Tools. The AI Register does not make any legal judgments and is not a substitute for a legal advisor. However, in just ten minutes, you’ll receive an overview of your tools, their risk class, and the transparency texts you need—all in three documents sent to your email—based on the statutory text, including the July amendments.

How ALTA-ICT helps

To answer the question “Where do I stand?”, there’s the check-in: six themes, one conversation. Policy, access, devices, continuity, supply chain, awareness. For each theme, the same question: Is it documented, and is it still accurate? You won’t get a 40-page report, but rather a single A4 page summarizing what’s in place, what’s missing, and what needs to be addressed first. Usually, the list is shorter than feared. Afterward, we tackle the remaining work—whether as management tasks or specific assignments—with before-and-after documentation that you keep on file. We operate in accordance with ISO 27001:2023, ISO 9001:2015, and NEN 7510:2024.

Frequently Asked Questions

Nothing has happened for a month. Does that mean the law is just a paper tiger?

No. The law operates through contracts and phased oversight. The RDI starts with essential organizations; the request to the rest comes through the major client, who is already making it.

What will change on December 2?

Starting then, generative AI systems that were on the market before August 2 must also mark their output as machine-readable. This responsibility falls on the tool provider. Your job: know which tools you’re using and disclose it yourself if you publish a photorealistic image of a person generated by AI.

Do I still need to register if I didn’t do so in August?

Yes, if you are subject to the law. This requirement has been in effect since August 15 and has no end date. If you’re unsure, take the RDI self-assessment.

Can I receive a grant for these measures?

The “My Cyber-Resilient Business” portal is open again. To qualify, you must first conduct your own assessment; after that, you can have the costs of the measures reimbursed. Be sure to specify which measure it is on the invoice.

If I could do only one thing, what should I do first?

Know where you stand. A check-in—or, more quickly, the Security Check for the outside and the three questions for your administrator regarding the inside. After that, every follow-up question is just a formality.

Conclusion

One month into the law: no fines, no raids, but a registry that has opened, a regulator that has laid out its priorities, lists that are getting smarter, and scans that show the work is inexpensive yet still remains undone. The panic phase is over. The work phase has begun. And on December 2, the next deadline arrives—from a different law.

Not sure where you stand? Schedule a check-in with ALTA-ICT. Six topics, one conversation, one A4 page.

Want to know more?

Get in touch
Hero bij de balans na een maand Cyberbeveiligingswet: een kaart met drie punten, register open, toezicht in fasen en werkfase begonnen.