Technology & Cyber regulatory updates from Netherlands.
We track 13 Technology & Cyber updates from Netherlands regulators, published by AFM. The archive covers 10 news items, 2 speeches and 1 enforcement. Most recent update: September 2026.
"As Europeans, we all are in the same boat, and therefore we should act in unison," zei Hanzo van Beusekom op de tiende Annual European Compliance and Legal Conference. "Not just because ‘we all breath the same air and we are all mortal’, as President John. F Kennedy once said. But also because we are all part of a…
Why this matters
This is a speech by AFM leadership at a compliance conference emphasizing the importance of unified European action on financial market regulation. The content references three themes—Resilience, AI, and Europe—and five conditions for centralized supervision, but provides no specific rules, guidance, or enforcement...
The financial sector has made major progress since the introduction of the Digital Operational Resilience Act (DORA). At the same time, as a result of its supervision and requests for information, the Dutch Authority for the Financial Markets (AFM) has identified areas requiring further action from financial…
Why this matters
AFM regulatory update on DORA compliance progress and implementation gaps. Informational content summarizing sector-wide developments, compliance improvements (94% register approval), and areas requiring attention (incident reporting, policy documentation, threshold calculations).
Businesses procuring IT services should join forces more often, as this is key to strengthening their digital autonomy. Public authorities and businesses should make digital autonomy a core consideration in their procurement decisions, helping to drive the development of European digital services.
Why this matters
Dutch supervisory authorities' joint press release on digital autonomy and reducing IT service provider dependencies. Addresses operational resilience through supply chain risk management and cybersecurity considerations aligned with DORA and NIS2 Directive implementation.
Het Financieel Stabiliteitscomité (FSC) constateert tijdens zijn vergadering van 26 juni 2026 dat geavanceerde AI-modellen het cyberdreigingslandschap ingrijpend veranderen. Het FSC benadrukt dat financiële instellingen hun cyberweerbaarheid hierop moeten aanpassen en pleit voor sterkere coördinatie en betere…
Why this matters
FSC press release discussing AI-driven cybersecurity threats to financial stability, private credit growth monitoring, and resilience requirements. Informational statement from regulatory committee addressing systemic risks and coordination needs across financial sector.
Veel pensioenuitvoerders gebruiken online tools voor keuzebegeleiding. Een aantal van die tools hebben we grondig geanalyseerd. In te veel gevallen stuitten we daarbij op fouten.
Why this matters
AFM guidance on testing online pension choice guidance tools for errors. Addresses consumer protection risks from faulty calculations and the need for proper testing procedures involving multiple expertise areas. Informational bulletin preceding a full investigation report.
De Autoriteit Financiële Markten (AFM) is een professionele en doelmatige toezichthouder die haar wettelijke taken doeltreffend uitvoert en aantoonbare resultaten boekt. Dat blijkt uit de onafhankelijke evaluatie van het functioneren van de AFM als zelfstandig bestuursorgaan (zbo) over de periode 2021–2025. In het…
Why this matters
This is an informational news article announcing the AFM's five-year regulatory evaluation results (2021-2025). The evaluation covers the AFM's supervisory effectiveness across multiple domains including crypto, cybersecurity, and sustainability. It is a positive assessment with recommendations for improvement.
Per 19 juni treedt de herziene Distance Marketing of Financial Services Directive (DMFSD) in werking. De DMFSD bevat regels ter bescherming van consumenten bij het online sluiten van overeenkomsten voor financiële diensten. De regels gaan over precontractuele informatie, een ontbindingsrecht voor consumenten en…
Why this matters
AFM regulatory guidance on DMFSD implementation (effective 19 June 2024) regarding consumer protection in online financial services. Addresses dark patterns and manipulative design in digital customer journeys across multiple financial sectors.
In its SREP Market Overview 2025, the AFM notes that many firms have their foundations in order, but that implementation is lagging behind. Internal control and IT risks, in particular, require improvement. The message is clear: ensure that policies are not merely in place, but that they demonstrably work in practice.
Why this matters
AFM's SREP Market Overview 2025 provides regulatory guidance on implementation gaps in internal controls, IT risk management, and governance. This is informational content highlighting supervisory expectations rather than announcing new rules.
Advanced AI models can speed up the process of identifying and combining vulnerabilities. As a result, organisations have less time to address vulnerabilities and mitigate incidents. Small and medium-sized enterprises in particular, with less advanced security or older systems, may be relatively more vulnerable. The…
Why this matters
AFM speech addressing AI-driven cyber threats and resilience requirements. Applies broadly across financial services sectors with emphasis on vulnerability management, patch management, and incident response. Classified as informational/advisory content rather than binding regulation, hence null urgency.
The escalation of the Middle East conflict leaves the global economy in a clearly worse state than previously expected. Higher inflation expectations, lower growth and heightened uncertainty are also affecting the financial sector, according to the annual Financial Stability Report from the Dutch Authority for the…
Tijdens de verenigingsdag van het Verbond van Verzekeraars stond Hanzo van Beusekom (AFM) stil bij de impact van data en digitalisering op de verzekeringssector. In zijn speech schetste hij hoe technologische ontwikkelingen het mogelijk maken om premies steeds persoonlijker te maken. Dat biedt kansen, zoals beter…
Why this matters
AFM speech addressing balance between data-driven personalization and insurance solidarity principles. Focuses on conduct expectations for insurers regarding algorithmic pricing and risk of consumer exclusion. Informational/guidance content rather than binding regulation, hence null urgency.
De Autoriteit Financiële Markten (AFM) waarschuwt voor telefoontjes van mogelijke oplichters die uit naam van de AFM bellen en zo proberen u gevoelige informatie te laten delen.
Why this matters
AFM consumer warning about phone spoofing fraud targeting financial sector customers. Alerts about identity theft, credential harvesting, and unauthorized access attempts. Applies broadly across financial services as threat affects all regulated entities and their customers.
Financial institutions are working to make their digital services accessible. This is important, because it ensures that people with disabilities can manage their finances independently. To provide further guidance to the sector, the Autoriteit Financiële Markten (AFM) shares expectations and points of attention in…
AI Analysis
AFM’s third EAA update makes clear that Dutch financial institutions must not only fix accessibility gaps, but also **assign clear internal accountability**, **embed accessibility compliance in governance and monitoring**, and **submit more specific non-compliance notifications**. AFM also announced a **sector-wide compliance review in the coming months**, with a focus on whether websites meet WCAG criteria, especially **level A** requirements, so compliance teams should treat this as an active supervisory campaign rather than routine guidance.
Key dates
28 June 2025
- The European Accessibility Act came into force, and Dutch national measures began applying to covered new products and services
Coming months (TBD, est. late 2026) Deadline
- AFM will conduct an accessibility compliance review of the sector, focusing on WCAG compliance, especially level A criteria
23 April 2026 Deadline
- AFM published its third EAA update and announced a forthcoming sector compliance review
Suggested considerations
Firms should map all consumer-facing digital services and identify which websites, apps, and digital documents fall within EAA/WCAG scope.
Firms should assign a named internal owner for accessibility compliance, monitoring, remediation tracking, and regulatory notifications.
Firms should document accessibility risks and remediation plans for each in-scope digital service, including the precise pages, functions, or documents affected.
Firms should embed accessibility checks into design, development, testing, and change-management processes so compliance is monitored continuously.
Firms should review EAA non-compliance notifications and make them more specific, including the exact accessibility issues, affected locations, and remediation status.
What changed
- AFM expects financial institutions to identify accessibility risks in their digital services and implement improvements that meet the required WCAG criteria.
AFM expects firms to embed and monitor accessibility through internal processes, rather than treating accessibility as a one-off remediation project.
AFM is emphasizing clear accountability for safeguarding digital accessibility, which means firms should be able to show who owns accessibility compliance, monitoring, and remediation internally.
AFM says EAA notifications of non-compliance must be more specific, because current submissions often do not describe the exact accessibility issues or where they are located.
AFM has published further instructions on how to answer certain questions in the EAA notification form, indicating a stronger supervisory focus on the quality of regulatory reporting.
Compliance impact
The compliance risk is material because AFM is moving from guidance to active review and may directly challenge firms with shortcomings. In practice, poor documentation, vague notifications, or weak governance can expose firms to supervisory intervention, remediation orders, and escalating scrutiny over the accessibility of consumer-facing channels.