AI Ethiek & Governance

NIS2 in the Netherlands: does the Cyberbeveiligingswet apply to you, and what must you do?

Geert Haisma

The Dutch Cyberbeveiligingswet (NIS2) has applied since 15 August 2026. Find out whether your organisation is in scope and what registration, the duty of care, incident reporting and board duties require.

Man in wit shirt sluit witte netwerkkabels aan op een zwarte switch in een serverrek

The Cyberbeveiligingswet (Cbw, the Dutch Cybersecurity Act) is how the Netherlands implements the EU NIS2 Directive, and it has applied since 15 August 2026. If NIS2 in the Netherlands covers your organisation, you register with the NCSC, take appropriate security measures, report serious incidents without delay and within 24 hours at the latest, and have your management body approve the measures. Whether the act applies depends on your sector and your size. Public authorities are always in scope, with a few exceptions.

Key points

  • The Cbw and the Cybersecurity Decree (Cyberbeveiligingsbesluit) have applied since 15 August 2026. According to the Dutch government, more than 8,000 organisations are covered.
  • You are either an essential or an important entity. That determines how strict supervision is and how high a fine can be.
  • There are four obligations: registration in MijnNCSC, the duty of care, the reporting obligation and the duties of the management body.
  • A significant incident is reported in stages: an early warning without delay and within 24 hours at the latest, a notification within 72 hours at the latest and a final report no later than one month after that.
  • Members of the management body must demonstrably have sufficient knowledge by 15 August 2028. A training certificate serves as proof.

What is the Cyberbeveiligingswet?

The Cyberbeveiligingswet transposes NIS2, the second EU directive on the security of network and information systems (Directive (EU) 2022/2555). The act was published in the Bulletin of Acts and Decrees as Staatsblad 2026, 187. Together with the Cybersecurity Decree (Staatsblad 2026, 189) it entered into force on 15 August 2026. The previous Dutch law, the Wbni, was repealed on the same day.

The aim is straightforward. Organisations that matter to society and the economy must secure their systems properly and report serious incidents quickly. The Wbni covered a much smaller group of operators. The Cbw reaches far wider: according to the Dutch government (7 July 2026), more than 8,000 organisations.

The rules sit at three levels. The act sets the framework. The Decree details the duty of care, the reporting steps and the training of directors. For each sector, the responsible minister can add a ministerial regulation, for example with thresholds for incidents.

The four obligations under the Dutch Cyberbeveiligingswet: registration in MijnNCSC, the duty of care, reporting with an early warning within 24 hours, and the duties of the management body.

The four obligations under the Dutch Cyberbeveiligingswet: registration in MijnNCSC, the duty of care, reporting with an early warning within 24 hours, and the duties of the management body.

Does NIS2 in the Netherlands apply to your organisation?

You are in scope if you are a public authority, or if you operate in a sector listed in the annexes of the act and are at least medium-sized. The act distinguishes two categories: essential entities and important entities. "Entity" simply means organisation.

Work through three questions:

  1. Are you a public authority or a critical entity? Ministries, independent administrative bodies of central government, provinces, municipalities, water boards and joint arrangements are essential regardless of size, insofar as they qualify as a public administration entity (Article 8 Cbw). The same goes for critical entities under the Dutch Critical Entities Resilience Act (Wwke). Defence, the intelligence services, the Public Prosecution Service, the police and the safety regions are excluded (Article 5).
  2. Do you operate in a sector from Annex 1 or Annex 2? Annex 1 covers, among others, energy, transport, banking, health care, drinking water, waste water, digital infrastructure, business-to-business ICT service management, public administration and space. Annex 2 covers, among others, postal and courier services, waste management, chemicals, food, part of manufacturing (such as medical devices, electronics and machinery), digital providers and research.
  3. How large are you? The EU SME definition applies. Medium-sized means 50 or more staff, or an annual turnover and a balance sheet total each above EUR 10 million. Large means 250 or more staff, or a turnover above EUR 50 million and a balance sheet total above EUR 43 million.

Large organisations in an Annex 1 sector are essential. Medium-sized organisations in Annex 1, and medium-sized and large organisations in Annex 2, are important. Small organisations are usually out of scope. A few types follow their own rule. DNS service providers, top-level domain registries and qualified trust service providers are always essential, however small. Providers of public electronic communications networks and services are essential from medium size upwards (Article 8). Small telecom providers and other small trust service providers are important (Article 12).

Decision tree: is my organisation covered by the Dutch Cyberbeveiligingswet? Public authorities and critical entities are essential. Sector and size then determine whether you are essential, important or out of scope.

Decision tree: is my organisation covered by the Dutch Cyberbeveiligingswet? Public authorities and critical entities are essential. Sector and size then determine whether you are essential, important or out of scope.

In doubt? Use the NIS2 self-assessment of the Dutch Authority for Digital Infrastructure (RDI), which the NCSC refers to. It helps your assessment, but the responsibility stays with you. Note that a minister can also designate an organisation in an Annex 1 or Annex 2 sector as essential, even a small one, for example when it is the only provider of an essential service in the Netherlands (Article 9). Outside the annexes, only higher education institutions can be designated (Articles 11 and 13).

Essential entityImportant entity
WhoLarge organisations in Annex 1, medium-sized and large telecom providers, public authorities, critical entities, DNS providers, TLD registries, qualified trust servicesMedium-sized organisations in Annex 1, medium-sized and large organisations in Annex 2, small telecom providers and small trust service providers
ObligationsRegistration, duty of care, reporting, management dutiesThe same obligations
SupervisionAlso without a prior indicationOnly when there is an indication of an infringement
Maximum fine for duty of care or reportingEUR 10 million or 2% of worldwide annual turnover, whichever is higherEUR 7 million or 1.4% of worldwide annual turnover, whichever is higher

Comparison: an essential entity is supervised also without a prior indication, with a maximum fine of €10 million or 2%; an important entity only on an indication, up to €7 million or 1.4%.

Comparison: an essential entity is supervised also without a prior indication, with a maximum fine of €10 million or 2%; an important entity only on an indication, up to €7 million or 1.4%.

How do you register under the Cbw?

Registration comes first. Since 15 August 2026, every organisation in scope must be registered in the national register. You do this in MijnNCSC (mijn.ncsc.nl), the portal of the Dutch National Cyber Security Centre.

You provide, among other things (Article 44 Cbw and Article 27 of the Decree):

  • name, address and up-to-date contact details, including email addresses, IP ranges and telephone numbers;
  • whether you register as an essential or an important entity;
  • your Chamber of Commerce number, or for public bodies their code in the Register of Government Organisations;
  • your sector, subsector and type of entity;
  • the EU member states where you provide your services, and your domain names.

If anything changes, you report it without delay and in any case within two weeks. The register does not ask for a list of your suppliers. Our article on the Dutch national entity register covers the practical side.

What does the NIS2 duty of care require?

The duty of care (Article 21 Cbw) means you take appropriate and proportionate measures to manage the risks to your network and information systems. Appropriate means matched to your risks, the state of the art and the cost. Proportionate means in line with your size and your exposure.

The act lists ten topics that must at least be covered. The Decree works them out in Articles 6 to 18. The pattern is always the same: you set down your policy in writing and you apply it demonstrably. Use this checklist:

  • Security policy for your systems, with roles and a management system (Decree Article 6)
  • Risk management: a method, risk acceptance criteria, an overview of risks and the security requirements derived from it (Article 7)
  • Incident handling: detect, analyse, respond, document, report and learn, plus logging (Article 8)
  • Business continuity: backups, a recovery plan and a crisis plan, tested periodically (Article 9)
  • Supply chain security, with periodic checks of your direct suppliers (Article 10)
  • Secure acquisition, development and maintenance, with configuration and change management (Article 11)
  • Staff awareness and training (Article 12)
  • Cryptography policy (Article 13)
  • Personnel, access policy and asset management (Articles 14 to 16)
  • Assessment of security advisories you receive, recorded in writing (Article 17)
  • Periodic evaluation of the measures (Article 18)

If you already run a management system based on ISO 27001, NEN 7510 or BIO2 (the Dutch government security baseline), much of this work is done. Some sectors even prescribe such a standard. Health care organisations must demonstrably meet NEN 7510, or ISO 27001 and 27002, or an equivalent level. Public authorities, water boards included, apply ISO 27001 and use the controls of ISO 27002 and BIO2.

When must you report an incident under the Cyberbeveiligingswet?

You report every significant incident. An incident is significant if it causes severe disruption of your services or financial loss, or if it causes considerable damage to others. An incident that could cause this also counts (Article 25 Cbw).

The exact thresholds differ per sector and are set in ministerial regulations. Two examples:

SectorExample thresholds (the incident leads or may lead to)Source
Health carea critical business process is fully or partly down for more than four hours; critical systems are compromised; special categories of personal data or citizen service numbers are affected by suspected malicious actionCybersecurity Regulation for health care, Article 2.2
Municipalities, provinces, water boardsservice outage of at least four hours; financial consequences the budget cannot absorb; serious injury or deathCybersecurity Regulation for public administration, Article 6; for water boards the Cybersecurity Regulation of the Ministry of Infrastructure and Water Management, Article 28

In both regulations, planned maintenance does not count as a significant incident.

You report in MijnNCSC. One report reaches both your CSIRT (the incident response team for your sector) and your supervisory authority. The deadlines run from the moment you become aware of the significant incident:

  1. Without delay, within 24 hours at the latest: early warning. Is the incident suspected to be malicious? Could it have cross-border effects? Who is your contact person? Also state the likely start time and, where possible, the nature, an expected recovery time and your measures (Article 26 Cbw, Article 24 of the Decree).
  2. Without delay, within 72 hours at the latest: notification. You update the information and give an initial assessment of severity and impact, with indicators of compromise if available (Article 27).
  3. On request: intermediate report with relevant updates (Article 28).
  4. No later than one month after the notification: final report. It contains a detailed description, the likely root cause, the measures taken and any cross-border effects. If the incident is still ongoing, you send a progress report instead and the final report follows within one month of handling the incident (Article 29).

Timeline of the reporting obligation under the Dutch Cyberbeveiligingswet: early warning within 24 hours at the latest, notification within 72 hours at the latest, intermediate report on request and final report no later than one month after the notification.

Timeline of the reporting obligation under the Dutch Cyberbeveiligingswet: early warning within 24 hours at the latest, notification within 72 hours at the latest, intermediate report on request and final report no later than one month after the notification.

If the incident affects your customers, you inform them without delay (Article 30). Near misses do not have to be reported, but you may report them voluntarily to your CSIRT (Article 33). Do record them internally. It shows that your incident handling works, and you learn from them before something goes wrong. According to the explanatory memorandum, a report does not increase your liability. If personal data is involved, the GDPR breach notification to the Dutch Data Protection Authority applies as well.

What does the Cbw mean for your suppliers?

The duty of care includes your supply chain. The act mainly means your direct suppliers and service providers, such as your cloud provider, your IT managed service provider and your software vendor (Article 21(3) and (4) Cbw). It does not extend to every link down the chain.

The Decree makes it concrete (Article 10):

  • you set down in policy how you deal with dependencies on suppliers that can affect the security of your systems;
  • you check whether your direct suppliers meet the security requirements you derived from your own risk analysis;
  • you repeat that check periodically.

When choosing measures, you consider each supplier's vulnerabilities, the quality of their products and their own security practices, including secure development.

In practice this comes together in contracts. Agree, for example, how fast a supplier informs you about an incident. That matters, because your own 24-hour clock starts as soon as you know. Add audit rights and requirements for vulnerability management too. Our article on NIS2 supply chain security and vendor audits goes into more detail.

What must the management body do under the Cyberbeveiligingswet?

The management body carries final responsibility, and the Cbw makes this concrete in Article 24. The act does not contain a direct personal liability for damages. It does give directors their own duties, with their own sanctions.

The duties of the management body:

  • Approve. The management body approves the duty-of-care measures.
  • Knowledge. Each member can identify risks, assess measures and judge the impact on the services.
  • Deadline. Sitting members must meet the knowledge requirement within two years of entry into force, so by 15 August 2028. A newly appointed member has two years from appointment (Article 24(3)).
  • Certificate. Each member demonstrates this knowledge with a certificate of a training covering these topics (Article 24(5)). The certificate states, among other things, name, dates, topics and provider (Article 22 of the Decree).
  • Keep it current. The knowledge must demonstrably stay up to date.

For municipalities, the management body is the board of mayor and aldermen; for provinces, the provincial executive; for water boards, the executive board.

The sanctions:

  • The supervisor can impose an order subject to a penalty, or a fine of up to EUR 25,000, on a member who does not meet the knowledge or training duty (Articles 92 and 93).
  • If an essential entity ignores an imposed deadline, the supervisor can ask the court to suspend members of the management body temporarily (Article 78). This does not apply to public authorities.
  • According to the explanatory memorandum, the supervisor can also act under the General Administrative Law Act against whoever ordered an infringement or directed it in practice. In addition, the organisation can hold a director liable under civil law for improper management (Article 2:9 of the Dutch Civil Code).

What this means for the personal position of directors is covered in our article on director liability under NIS2 in the Netherlands.

Who supervises the Cyberbeveiligingswet?

Each sector has its own supervisory authority. For most sectors the NCSC is the CSIRT, the team that helps you with incidents. The NCSC does not supervise.

SectorSupervisory authority
Digital infrastructure, ICT service management, energy, public administration, digital providers, postal services, space, manufacturing (except medical devices)Dutch Authority for Digital Infrastructure (RDI)
Transport, drinking water, waste water, water boards, waste management, chemicalsHuman Environment and Transport Inspectorate (ILT)
Health care and the manufacture of medical devicesHealth and Youth Care Inspectorate (IGJ), with Z-CERT as CSIRT
Banking and financial market infrastructureDNB and AFM
FoodNVWA

For essential entities, the supervisor may inspect without a prior indication, for example with a security scan or a mandatory audit. For important entities, this is only possible when there is an indication of an infringement (Article 81). A fine comes together with or after a warning or another enforcement decision (Articles 80 and 87). For other infringements, such as failing to register, the maximum fine is EUR 1 million. The full overview per sector is in the NCSC referral chart.

How it works at Prudai

Prudai builds IRMA, software for governance, risk and compliance (GRC) and an information security management system (ISMS). This is how the Cbw looks when you set it up in IRMA:

Cbw obligationWhere it lives in IRMA
Duty of care and risk managementRisk register with likelihood, impact and treatment choice, with linked controls
Showing which measures applyNIS2/Cyberbeveiligingswet framework (duty of care and reporting), alongside ISO/IEC 27001:2022, BIO2 and NEN 7510, with a versioned Statement of Applicability
Incident handlingRegisters for incidents and for data breaches
Supply chainRegisters for suppliers and contracts
Approval by the management bodyRecording policies and management reviews
EvaluationAudits with findings

Two things are deliberate. First, the registers work entirely without AI. If you opt for AI suggestions, we switch them on for your organisation. The IRMA assistant then searches your own documents for risks and suggests risks, controls, process steps and draft policies. Only after an employee approves a suggestion does it enter the register, and every approved change is recorded in the audit log. Second, the assistant works with more than thirty sources, including the security advisories of the NCSC and ENISA.

Have risks assessed by the people who know them. With an email request, you ask risk owners for their assessment, with a response deadline. With a group assessment, participants score likelihood and impact through a personal link, without an account. Results are reviewed before they enter the register. Registers and attachments are stored in a dedicated database on Prudai's own server in an EU data centre (Hetzner, Germany).

What IRMA does not do: file the report with the NCSC. You do that yourself in MijnNCSC. And a framework in IRMA does not make you compliant by itself: it helps you show what you have put in place. Why we record every fact in one place is explained in our article on information architecture: one fact, one place.

For the specialist

  • Jurisdiction. The Cbw applies to entities established in the Netherlands (Article 4). Telecom providers are covered as soon as they offer their services in the Netherlands, even without an establishment here. For cloud and data centre providers, managed (security) service providers, DNS and online platforms, among others, the main establishment counts. These digital providers also submit their details for the ENISA register, within one month of coming into scope (Article 47).
  • Digital providers and trust services. Articles 6 to 18 of the Decree do not apply to this group. Commission Implementing Regulation (EU) 2024/2690 applies instead, and also defines when an incident is significant (Article 4 of the Decree).
  • Size. Under Recommendation 2003/361/EC, data of partner and linked enterprises in principle count towards the SME test.
  • Financial sector. For banks and financial market infrastructure, DORA (Regulation (EU) 2022/2554) is a sector-specific act. Its rules on ICT risk management and incident reporting apply instead of the Cbw duty of care and reporting obligation, which also removes the management body duties (Articles 22, 24 and 31 Cbw).
  • Higher education. Designated institutions get 36 months for the duty of care and the management duties (Article 97).
  • Former operators of essential services. An organisation designated under the Wbni as an operator of an essential service can be designated as an essential entity (Article 10).
  • Transition. A Wbni report made before 15 August 2026 counts as an early warning under the Cbw, provided the reporting organisation has been subject to the Cbw reporting obligation since that date (Article 95).
  • Trust services. If a significant incident affects the trust service, the notification deadline is 24 hours instead of 72 hours (Article 27(2)).
  • Sector rules. Read the regulation for your sector, such as the Cybersecurity Regulation for health care or the Cybersecurity Regulation for public administration (both in Dutch). They set the thresholds and sometimes a mandatory standard.

Frequently asked questions

Does the Cyberbeveiligingswet apply to small businesses?

Usually not. Organisations with fewer than 50 staff and a turnover or balance sheet total of at most EUR 10 million are generally out of scope. Exceptions include DNS service providers, top-level domain registries, telecom providers and trust service providers. If your customers are in scope, they may still impose requirements on you through contracts.

Is there a transition period for the Cbw?

Hardly. The act and the Decree have applied since 15 August 2026, and registration was required from that date. Only members of the management body have until 15 August 2028 to meet the knowledge requirement. Designated higher education institutions get 36 months for the duty of care.

Do I have to report a near miss?

No. The reporting obligation only covers significant incidents. You may report a near miss voluntarily to your CSIRT. Record it internally as well: it shows that your incident handling works.

How does a Cbw report differ from a GDPR breach notification?

The Cbw report goes through MijnNCSC to your CSIRT and supervisor, for every significant incident. The GDPR notification goes to the Dutch Data Protection Authority and concerns personal data. If one incident triggers both, you file both.

Which supervisory authority applies to my organisation?

That depends on your sector. For digital infrastructure, energy and public administration it is usually the RDI, for health care the IGJ and for transport and water the ILT. The NCSC referral chart lists the ministry, the CSIRT and the supervisor for each sector.

Sources

Would you like to know how IRMA keeps your duty of care, incidents and suppliers under the Cyberbeveiligingswet in connected registers? See IRMA, GRC and ISMS software by Prudai (in Dutch) or request a trial environment.

Updated on 2 October 2026

Photo: StockSnap via Pixabay

PrudaiData Privacy

Geert Haisma

Director

Geert Haisma is the co-founder and director of Prudai, an AI specialist that supports organizations in securely and custom-deploying generative AI for improved decision-making and process automation. With a background in public administration and years of experience in making organizations more successful, Haisma is the driving force behind Prudai's strategic and substantive direction.