The Cybersecurity Act and Admissibility of Evidence: What Will Change for File Sharing?

The Cybersecurity Act is the Dutch implementation of the European NIS2 Directive, while the Critical Entities Resilience Act governs the physical and operational resilience of critical sectors. Together, they entail mandatory security measures, incident reporting, oversight by designated authorities, and a registration requirement. Organizations subject to the law must strengthen, document, and demonstrate their digital and physical security processes.
The Cybersecurity Act and Admissibility of Evidence: What Will Change for File Sharing?

Cybersecurity Act and File Sharing

On July 7, 2026, the Senate definitively passed the Cybersecurity Act (Cbw) and the Critical Entities Resilience Act (Wwke). Both laws will take effect on August 15, 2026. For thousands of Dutch organizations, this is more than just a legal formality: from now on, security must not only be in order but also demonstrable. And that last word is exactly where things will get tricky for many organizations, especially when it comes to something seemingly as simple as sending a file.

What exactly has changed?

The Cybersecurity Act is the Dutch implementation of the European NIS2 Directive, while the Critical Entities Resilience Act governs the physical and operational resilience of critical sectors. Together, they entail mandatory security measures, incident reporting, oversight by designated authorities, and a registration requirement. Organizations subject to the law must strengthen, document, and demonstrate their digital and physical security processes.

Starting August 15, registration with the NCSC is mandatory for organizations subject to the law; registration is already available on a voluntary basis.

Do you qualify?

Whether the Cbw applies to your organization depends on two factors: sector and size. The law applies to approximately 8,000 organizations in eighteen (highly) critical sectors—such as energy, digital infrastructure, research, and government—and may also apply to larger companies in other sectors and to certain suppliers.

Specifically: Do you operate in one of those sectors and have 50 or more employees, or an annual revenue or total assets exceeding 10 million euros? If so, you likely fall under the law. A number of types of organizations are covered in any case, regardless of size—for example, providers of public communications networks, trust services, DNS service providers, and all government organizations.

Not sure? The quickest way to check is to take the RDI’s NIS2 Self-Assessment. It will help you determine in just a few minutes whether you’re subject to the law and whether you’re classified as “essential” or “important.”

The essence of the new requirement: demonstrability

If you are subject to the law, you are required to fulfill three obligations: registration, taking measures, and reporting incidents. A regulatory authority—which varies by sector—monitors compliance.

That last point is the crux of the matter. Compliance means that, at any given time, you must be able to demonstrate what you’ve done, when, and with what results. Not just “we send files securely,” but documentation that supports that claim. For most organizations, that burden of proof doesn’t lie in the large, visible systems—which are often already well-documented—but in the everyday, informal way employees share files: with customers, regulators, auditors, and supply chain partners. That’s exactly where the problem often lies, because this type of file sharing still regularly takes place via email attachments, personal WeTransfer links, or consumer cloud storage—channels that lack an audit trail.

What "verifiability" Means in Practice for File Sharing

In practice, verifiability in file sharing comes down to a few specific points:

  • A comprehensive audit trail. Who sent or downloaded what, when, and to whom—all recorded and cannot be changed afterward.
  • Verification of the recipient. Not only encrypt the connection, but also verify that the file has actually been received by the correct person—for example, through email and phone verification upon download.
  • Retention periods and exportable reports. This way, in the event of an audit or incident, you won’t have to manually reconstruct logs; instead, you can submit a report to a regulator or auditor with the push of a button.
  • Traceability in the event of an incident. When it comes to the reporting requirement, time is of the essence: the faster you can reconstruct what was shared and with whom, the faster you can substantiate your report.

This is the difference between “we sent it securely” and “we can prove that it was sent securely,” and with the Cbw, that difference becomes a legal requirement for the first time, rather than merely a quality goal.

How Msafe Fits Into This

Msafe is built around precisely that principle: file sharing that is not only secure but also verifiable for each transfer. Recipient verification, comprehensive logging of upload and download times, and reports that are immediately usable for a regulatory authority or internal audit are all built into how the platform works—not a separate report you have to create afterward.

This approach aligns with Msafe’s broader approach to demonstrating compliance: the platform is ISO/IEC 27001:2022-certified (audited by DEKRA), and a SOC 2 Type I report is expected shortly. While those certifications speak to the organization as a whole, the audit trail for each file transfer provides the evidence at the level that regulators and auditors actually require: the individual transaction.

Practical Step-by-Step Guide

  1. Check whether you are subject to the law using the RDI’s NIS2 Self-Assessment.
  2. Map out your file-sharing practices: with whom, through which channels, and how sensitive are those files?
  3. Ensure there is a verifiable audit trail for every transfer, even those that do not involve the major IT systems.
  4. Register your organization on the NCSC portal (mijn.ncsc.nl) by August 15, 2026.
  5. Test your incident reporting process, including the following question: Can we reconstruct what was shared within the specified timeframe?

Want to know more?

Would you like to hear about this step by step, including practical examples that go beyond the text of the law? Hennie Jansen will explain it during the keynote “Get a Handle on Secure and Verifiable File Sharing”at Cybersec Netherlands at Jaarbeurs Utrecht on September 9 and 10.

FAQ

On August 15, 2026, following final adoption by the Senate on July 7, 2026.

That depends on your sector (18 critical sectors) and your size (50 or more employees or annual revenue/total assets exceeding €10 million). Use the RDI’s NIS2 Self-Assessment for a quick check.

You must be able to show who sent and received what and when, including verification of the recipient and an exportable report for regulators or audits.

Yes, organizations subject to the law are required to register with the NCSC via mijn.ncsc.nl.

Share:

More Posts

SharePoint vs. Secure File Transfer
Blog

SharePoint vs. Secure File Transfer

SharePoint remains an excellent choice for internal collaboration. Once files leave the organization, that process requires a solution built specifically for that purpose, one that offers the same ease of use for the user, but with verifiable control for IT, security, and compliance.

Read More »
Msafe Pers bericht
Blog

Msafe Launches Version 2.3 of Secure File Transfer with Easy Download

Share files securely without an account? With the new Easy Download feature in Msafe Secure File Transfer version 2.3, external users receive a secure download link and, after a simple verification process, gain immediate access to the shared files. In this way, Msafe optimally combines ease of use with maximum security and complete control.

Read More »
alternative to GoAnywhere
Blog

Alternative to GoAnywhere

Secure file sharing and Managed File Transfer are often used interchangeably, but they address different issues. In this article, you’ll learn when to use Msafe Secure File Transfer, when MFT—such as GoAnywhere—makes more sense, and how both solutions can complement each other.

Read More »
Why Secure File Sharing Is Only Truly Secure with Security Awareness Training
Blog

Security awareness training ensures that secure file sharing is truly compliant

Files are still shared by people. And that’s exactly where the risk lies. An employee who clicks on a phishing email, shares a document with the wrong recipient, leaves permissions too broad, or works outside the secure channel because it seems faster can put even the best-secured environment under strain. That’s why secure file sharing, security awareness, and compliance training go hand in hand.

Read More »
Complexity Undermines Compliance
Blog

Complexity Undermines Compliance

Compliance rarely goes wrong because organizations lack policies. It goes wrong because policies become too complicated in practice. As soon as employees have to deal with cumbersome processes, extra steps, separate portals, and unclear exceptions, they look for a faster way. And that’s exactly where the problem begins. What seems safe and compliant on paper quickly turns into shadow IT, workarounds, and hidden risks in day-to-day operations.

Read More »