
Knowledge base
September 18, 2026
The First Week of the Cybersecurity Act: No Inspector, But the Supply Chain, and Why “No Evidence” Is Often the Case
The Cybersecurity Act has been in effect since Saturday, August 15, 2026. No raid. No fine. No inspector showing up at the door. That’s not how this law works—and you probably already knew that. What happened at our place that weekend: nothing. No questions, no checklist, no phone call. That was exactly what we expected. Procurement departments operate on a quarterly basis, and they were just hanging out in the backyard that weekend, too.
What we *did* see the week before, in our own scan log: someone scanned their domain, made a change twenty minutes later, and scanned it again. Score went up. No consultant, no quote, no project. That’s usually how it goes as soon as people see what’s broken.
This is the report on that first week: what didn’t happen, what did get started, and the one distinction that will shape the entire fall. The blog post on supply chain pressure explains why a small organization has to deal with this law at all.
What Didn’t Happen
No wave of fines. No enforcement notice. No panic among the major clients we speak with; their procurement processes operate on a quarterly basis, not daily. That is neither a coincidence nor a delay. The regulator, the RDI, has itself outlined how it operates: essential organizations receive proactive oversight, even in the absence of an incident; important organizations are primarily subject to retrospective oversight, for example, following a report. First come the sectors where disruptions would have the most severe impact, then the rest.
So, can you just sit back and relax? The questionnaires that were drafted in August will land on your desk in September and October. The procurement process that began that first week will soon require your documents. The law isn’t a deadline you either meet or miss. It’s a minimum standard that will evolve with every contract round from now on.
What Did Happen
Three things, all out of sight of the doorbell.
The entity registry has opened. Organizations subject to the law have been required to register with the NCSC since August 15. At the start, fewer than half of the estimated 8,000 to 10,000 organizations required to do so had registered. Registration does not prove compliance; it proves that you are aware you are subject to the law, and that is the first question a regulator and a major client will ask.
Procurement began conducting assessments. Contracts now include security addenda, audits require supporting documentation, and supply chain partners are passing the questions on to their suppliers. Quiet on the streets, but busy in the supply chain. The blog post about the supply chain questionnaire explains how to tackle such a list when it lands on your desk.
And people came to watch. The scan from August 13—three scans of the same domain within twenty minutes, with scores increasing each time—is the smallest example of this. The bigger picture is evident in the September scan: two out of three scanned domains fail to meet the threshold, and the most commonly missed component is the cheapest to fix.
“Regular” is not proof
One question will define the entire fall: Can you prove it on paper? This is no longer just a thought experiment. The difference between “organized” and “verifiable” is the whole story.
MFA is set up. A screenshot of the enforced rule, including the date, is available as proof. Backup is running—this has been taken care of. A documented recovery test, including the date and result, is verifiable. Data processor agreements—“we have them”—this has been taken care of. A single folder containing all signed copies is verifiable. Clients aren’t buying reassurance. They’re buying proof.
That’s also why “that’s taken care of” is such a dangerous phrase during an intake. It’s a feeling. A list with a date on it is an answer. The blog post about the inner workings explains how to make that difference visible in your Microsoft 365 environment.
Things You Can Do in a Single Weekend
It doesn’t cost anything: have the four basic documents ready—they’ll help you answer most of the questions in the chain. The blog post about the basic dossier explains which four documents these are, what they should contain, and why they don’t have to be lengthy reports. If you have all four, you’ll be able to answer every supply chain question that comes up this fall. If you’re missing one or more: no shame in that, but it does mean you have a to-do list.
And check your online presence. That’s the part your client can look up on their own before they even ask you anything.
Know what your client sees
The Security Check doesn’t delve into your specific environment and says nothing about the duty-of-care measures required by law. It assesses the external aspects: email security, encryption, certificates, and security headers—exactly the parts your client sees as soon as they start evaluating you. Thirty seconds, no account required, a report sent to your email, and for every result, a single line of actionable advice: what it means and whether you need to take action.
How ALTA-ICT helps
We regularly verify compliance. It starts with a check-in: six topics—policy, access, equipment, continuity, the supply chain, and awareness—and the same question for each topic: Is it documented, and is it still accurate? You won’t receive a 40-page report, but rather a single A4 page summarizing what’s in place, what’s missing, and what needs to be addressed first. Usually, that list is shorter than feared. Then we tackle the remaining work—whether as management tasks or specific assignments—with before-and-after documentation that you can keep on file. We operate in accordance with ISO 27001:2023, ISO 9001:2015, and NEN 7510:2024.
Frequently Asked Questions
I haven’t noticed anything since August 15. Does that mean I’m not covered by the law?
That doesn’t mean anything. The law operates through contracts and phased oversight, not through a letter on the first day. Whether you’re subject to it is determined by the RDI’s self-assessment; whether you’re indirectly affected by it is determined by your largest client.
Do I need to register?
Only if your organization is subject to the law. In that case, registration in the NCSC’s entity registry has been mandatory since August 15, with no specific end date.
What is the difference between “regular” and “demonstrable”?
“Arranged” refers to a feeling or a verbal commitment. “Verifiable” refers to a document, screenshot, or report that includes a date and the name of the person responsible. An auditor always asks for the latter.
Does the Security Check provide any information about duty-of-care measures?
No. It only assesses the external aspects of your domain. The duty of care pertains to your organization, your risk analysis, and your measures; that’s what the check-in is for.
When will the first supply chain questions come up?
For the next tender, insurance renewal, annual financial statements, or contract renewal. The lists compiled in August will be finalized in September and October.
Conclusion
Week One of the Cybersecurity Act: no drama, but some movement. No inspector at the door, but a registry that opened, procurement departments that began conducting assessments, and people who started looking into things on their own. The lesson from that week is the lesson for the entire fall: being compliant is not proof of compliance. “Demonstrable” means a list with a date on it.
Start by checking your profile at check.alta-ict.nl. Then, have the four documents ready. And if you want to know where you stand, schedule a check-in with ALTA-ICT.
Want to know more?
