AI Ethiek & Governance

The National Entity Register: Why NCSC Registration is Your First Cbw Obligation

Geert Haisma

Under the Cyber Security Act (Cbw), all essential and important entities are required to register in the new national entity register. Failure to register can lead to immediate fines. How do you get your compliance data in order on time?

The National Entity Register: Why NCSC Registration is Your First Cbw Obligation

The Cyber Security Act (Cbw) and the Critical Entities Resilience Act (Wwke) officially entered into force on August 15, 2026. For the Dutch private and public sectors, this marks a hard transition from best-effort cybersecurity to strict, enforceable legislation. For executives and compliance officers, this new legal reality does not start with a technical audit, but with one fundamental administrative action: determining your status and completing the corresponding registration.

For many organizations, the registration requirement in the NCSC's national entity register is the first critical hurdle. Ignoring or postponing this obligation is no longer an option; the active term is running, and supervisory authorities have the mandate to intervene directly.

What does registration in the National Entity Register entail?

With the launch of the entity register by the National Cyber Security Centre (NCSC), a centralized overview of all organizations falling under the scope of the Cbw has been created for the first time. Both 'essential' and 'important' entities must proactively register themselves.

During registration, you must provide not only general company details but also in-depth information about your sectoral classification, supply chain dependencies, and the executives responsible for cyber risk management. The government's goal is twofold: creating an overview for crisis management during large-scale incidents, and determining the supervisory population per sector.

Why waiting leads to administrative fines

Under the previous NIS directive, enforcement was often reactive. The Cbw changes this drastically. Supervisory authorities, including the National Inspectorate Digital Infrastructure (RDI) and the Health and Youth Care Inspectorate (IGJ), now hold an active mandate. As we explained earlier in our article on proactive IGJ supervision under the Cbw, regulators no longer have to wait for a data breach to take action.

Failing to fully or accurately comply with the registration requirement in the national entity register is a directly finable offense. Furthermore, an organization's board of directors can be held personally liable if they are found negligent in adhering to these basic requirements.

The challenge: Internal data quality and alignment

It sounds like a simple administrative task: filling out a form with the NCSC. The reality, however, is far more complex. To correctly determine your status as a medium or large enterprise within a specific Cbw annex, your company data must be accurate, consolidated, and verifiable.

In large organizations, the necessary information is often scattered across HR, Legal, IT, and external suppliers. Outdated descriptions of business processes or opaque supply chains can lead to incorrect classification. This is where the compliance challenge directly touches upon what we call information alignment: the process-driven guarantee that your documented business reality matches actual operations.

How IRMA helps with your first Cbw steps

To prevent the registration requirement from becoming a time-consuming and error-prone process, forward-thinking organizations are leveraging intelligent data orchestration.

For this exact purpose, PrudAI positions IRMA (Intelligent Risk Management Agent). This platform is specifically designed to solidify the data foundations for GRC (Governance, Risk & Compliance) processes. IRMA analyzes unstructured source documents regarding your IT landscape, supplier contracts, and corporate structures, and structures them into a unified profile. This empowers your compliance team to submit the required, accurate data points to the NCSC at the push of a button, fully backed by a traceable audit trail.

The registration requirement is just the beginning. With a validated baseline in IRMA, you are immediately prepared for the next phase of the Cbw: periodic reporting and demonstrable duty of care audits.

Would you like to know how your organization can immediately comply with the new legislation and how the IRMA platform seamlessly guides you through the complex web of Cbw registration? View our solutions and contact us via our contact page.

PrudAIAI in organizationsData PrivacyPublic Sector

Geert Haisma

Director

Geert Haisma is the co-founder and director of PrudAI, an AI specialist that supports organizations in securely and custom-deploying generative AI for improved decision-making and process automation. With a background in public administration and years of experience in making organizations more successful, Haisma is the driving force behind PrudAI's strategic and substantive direction.