Blog / Cybersecurity Hiring in the Netherlands: Why It's So Hard Right Now

Cybersecurity Hiring in the Netherlands: Why It's So Hard Right Now

    New Dutch cybersecurity law is pushing thousands of companies to hire at once. Here's why cybersecurity hiring is harder than regular IT recruitment, and what actually works.

    Cybersecurity hiring in the Netherlands is stuck because demand outpaces supply by a wide margin. There are roughly 28,582 unfilled security roles against a workforce of just 72,910 people, according to a 2026 salary benchmark. New compliance law is now forcing thousands of companies to compete for the same small pool at the same time.


    You're a hiring manager. You need a security architect, or maybe a CISO. The job description is ready. Budget is approved. Then nothing happens for three months.


    Sound familiar? You're not doing anything wrong. You're just hiring in a market that changed faster than most recruitment processes can keep up with.


    New Dutch legislation, the Cyberbeveiligingswet, takes effect on August 15, 2026, and it's expected to affect more than 8,000 organizations according to a report on the law's rollout. That's 8,000 companies suddenly needing security governance, incident response capability, and board-level reporting, often at the same time. If you're one of them, you're competing with everyone else who read the same memo.

    Why this law is turning into a hiring problem

    The Cyberbeveiligingswet is the Dutch version of NIS2, the EU directive meant to raise digital resilience standards. It's really more of a talent story than a tech story. Every company that falls under it now needs people who can own risk management, incident reporting, and supplier oversight, and most of them need those people yesterday.


    The European Commission referred the Netherlands to the Court of Justice in July 2026 for not reporting full transposition of the NIS2 directive on time. That tells you something: even the government moved slower than planned. Companies don't have that luxury. Compliance deadlines don't wait for a slow hiring pipeline.


    So what happens? Everyone starts hiring at once. Salaries move up. Good candidates get five offers instead of one. And companies that don't already have a strong process end up losing candidates to whoever moves faster.


    That's the real cost of this wave of regulation, and it shows up in the hiring gap, not the fines.

    Which roles are hardest to fill

    Five roles are absorbing most of the pressure right now, and they're not interchangeable.


    CISO and Head of Security roles are in highest demand because companies need governance and board reporting fast. Senior CISOs in the Netherlands are commanding €140,000 to €180,000, with executive-level packages reaching €180,000 to €240,000, according to a hiring guide for Dutch cybersecurity companies.


    Cloud Security Engineers are just as scarce. Senior profiles sit at €102,000 to €138,000, with lead and head-level roles up to €172,000, per the same guide.


    DevSecOps Engineers cover a wide range, roughly €72,000 to €162,000, because the role varies so much between companies. Some want someone who bolts security onto an existing pipeline. Others want someone who redesigns the whole delivery process around it.


    Security Architects and SOC Analysts round out the list. Architects are needed wherever a company is rebuilding its security model from scratch. SOC Analysts are needed because more regulation means more monitoring and more incidents to triage, with senior salaries around €70,000 to €92,000.


    None of these are junior jobs. That's the catch.

    Why cybersecurity hiring isn't like regular IT recruitment

    A backend developer role and a CISO role look similar on paper. Job title, salary range, required skills. In practice, they're nothing alike.


    Security hiring runs on trust, not just skill match. A CISO candidate isn't just being evaluated on technical depth. They're being evaluated on judgment under pressure, on how they'll report a breach to a board, on whether they can carry legal and reputational risk without freezing.


    That's hard to screen for with a keyword search.


    It also means combination profiles matter more here than almost anywhere else in tech. Companies aren't just asking for security knowledge anymore. They want someone who understands cloud infrastructure, or compliance frameworks, or operational technology, on top of security fundamentals. That mix is rare. And rare means expensive.


    Compensation isn't even the only sticking point. Scope, mandate, hybrid work flexibility, and sometimes clearance requirements all weigh in, according to an analysis of government-adjacent cybersecurity hiring. A candidate might turn down a higher salary for a role with more authority, or less red tape.


    If your process treats a security architect search like a standard developer search, you'll lose good candidates before you even get to a second interview. We've seen this happen with clients before they came to us: three months of sourcing, four rounds of interviews, and the candidate takes a competing offer because someone else moved in two weeks. Our work on the cybersecurity talent shortage covers exactly this pattern.

    What actually works when the whole market is hiring at once

    When 8,000 companies need the same type of people at the same time, speed and structure decide who wins, not budget size.


    Structured delivery beats CV-spam here more than in any other niche we work in. You can't screen 200 CVs for judgment and trust. You need senior recruiters who actually understand what a security architect does day to day, who can spot the difference between someone who's managed an incident and someone who's only read about it.


    That's the whole idea behind a Delivery Sprint: intake first, so we understand the actual mandate, not just the job title. Sourcing that targets people who fit that mandate, not a keyword list. Interviews structured so you and the candidate both know exactly where things stand.


    No black box. No guessing whether week six will produce three candidates or zero.


    We've placed cybersecurity specialists into roles other agencies gave up on, partly because we treat every search as a niche search. A generalist recruiter treating a CISO search like a project manager search will lose every time to someone who's spent years only in this space. Our piece on hiring for compliance-driven security roles goes deeper into how regulation reshapes this kind of search.


    This is niche recruitment, not volume recruitment.

    What this means for your hiring plan this year

    If you haven't started your compliance-driven security hiring yet, you're behind. Not disastrously behind. But behind.


    Budget for higher salaries than last year's benchmark. The market moved. Build in retention thinking from day one, because whoever you hire will get poached calls within months. And accept that time-to-hire for senior security roles will likely stretch longer than you'd like, unless your sourcing process is built for this specific market, not adapted from general IT recruitment.


    Companies that treat this as a strategic hire end up with people who stay. Companies that rush it end up re-hiring for the same role a year later. We've watched both play out. Our writeup on the broader hiring gap exposed by recent security incidents shows what the rushed version tends to cost.

    Frequently asked questions
    How do you hire cybersecurity talent in a tight market?

    Start with a clear intake on scope and mandate, not just a job description. Then use recruiters who know the security market specifically, so sourcing targets people with real judgment, not just matching keywords. Speed and structure matter more than a bigger budget.

    Why is there a cybersecurity skills shortage in the Netherlands?

    Demand has outpaced supply for years, with an estimated 28,582 unfilled roles against a workforce of 72,910. New compliance law is now pushing thousands of companies to hire at the same time, tightening the market further.

    What makes cybersecurity hiring different from regular IT recruitment?

    Security hiring depends heavily on trust and judgment, not just technical skill match. Candidates are evaluated on how they'd handle a breach or report to a board, which is hard to screen through standard CV filtering.

    How can companies improve their digital resilience through hiring?

    Hire for the specific mandate, not a generic title. Combination profiles, like cloud security or DevSecOps, close more gaps than a single specialist. And build retention plans early, since these hires get poached fast.

    Conclusion

    New compliance law didn't create the cybersecurity skills shortage. It just made it impossible to ignore. Thousands of companies are now chasing the same small group of experienced security professionals, and generic hiring processes aren't built for that kind of pressure.


    What works is treating this as its own niche: senior recruiters who understand the roles, a structured process that moves fast without cutting corners, and honesty about what a search will actually take. If your last security hire took six months and still wasn't quite right, that's worth a conversation before your next one starts the same way.

    Sources
    1. Cybersecurity Salary Benchmark 2026
    2. Netherlands Cybersecurity Companies: Hiring Guide | Optima Europe
    3. The Hague Cybersecurity Hiring: Why the Government That Fuels This
    4. Dutch NIS2 law nears final vote - Cyber Insider
    5. NIS2 Directive: securing network and information systems
    6. Cybersecurity Salary Checker Netherlands 2026 | MVPeople Group

    Written by our AI, read by a flesh-and-blood recruiter.