Skip to main content
Back to overview

The Dutch Cybersecurity Act (Cbw): NIS2 in Force Since 15 August 2026

By NIS2Certify
NIS2NetherlandsCyberbeveiligingswetCbwregistrationcompliance
The Dutch Cybersecurity Act (Cbw): NIS2 in Force Since 15 August 2026

The Cyberbeveiligingswet (Cbw), the Dutch law that transposes the NIS2 Directive (EU) 2022/2555, has applied since 15 August 2026. It replaces the Wbni and requires about 8,000 organisations in 18 sectors to register with the NCSC, manage their cyber risks and report significant incidents. The management body is ultimately responsible.

Sources: the Cbw on wetten.overheid.nl, Rijksoverheid, NCSC, NCTV and European Commission press release IP/26/1499. Status checked on 28 September 2026. The Dutch-language version of this guide is Cyberbeveiligingswet (Cbw): wat nu verplicht is.

Key takeaways

  • In force since 15 August 2026. The Senate (Eerste Kamer) approved the Cbw on 7 July 2026. The Wwke, the Dutch law for the EU CER Directive on critical entities, took effect the same day.
  • You decide yourself whether you're in scope. Nobody sends you a letter. Your sector and your size decide.
  • Registration is with the NCSC, in its entity register via MijnNCSC, and there is no transition period.
  • Significant incidents are reported in three steps: within 24 hours, within 72 hours and within one month of the notification.
  • Fines reach €10 million or 2% of worldwide annual turnover for essential entities and €7 million or 1.4% for important entities, whichever is higher.

Is the Cbw in force?

Yes. The Cyberbeveiligingswet has applied since 15 August 2026, almost two years after the 17 October 2024 transposition deadline. The timing was tight: the Senate approved the law on 7 July 2026, and one day later, on 8 July, the European Commission referred the Netherlands to the Court of Justice of the EU for not having notified full transposition, together with Ireland, Spain and France (IP/26/1499). The law entered into force just over five weeks later.

The Cbw replaces the Wet beveiliging netwerk- en informatiesystemen (Wbni), the Dutch law for the first NIS Directive. The Wbni covered a much smaller group of operators of essential services and digital service providers.

In substance the Cbw follows the directive closely. If you know NIS2, you know most of the Cbw. The Dutch part is the execution: where you register, who supervises you and how reporting works. For the EU-wide rules, read What is NIS2?.

Who is in scope?

The Cbw applies to organisations in the 18 sectors of the directive that are at least medium-sized: 50 or more employees, or fewer than 50 with both an annual turnover and a balance sheet total above €10 million. According to Rijksoverheid and the NCSC, that is about 8,000 organisations.

The "both" matters. A Dutch company with 30 employees, €12 million turnover and a €6 million balance sheet is a small enterprise and usually outside the Cbw.

Some organisations are in scope regardless of size, such as public bodies and DNS service providers. The NCSC has a page on whether your organisation falls under the Cbw, and our applicability check walks through the same questions.

Does NIS2 Apply to Your Organisation?

1

Does your organisation operate in an essential or important sector (energy, transport, health, digital infrastructure, etc.)?

Yes ↓No →
2

Does your organisation have 50 or more employees, or both an annual turnover and a balance sheet total exceeding €10 million?

Yes ↓No →
3

Is your organisation a critical infrastructure provider or a qualified trust service provider?

Yes ↓No →
✗

NIS2 does not directly apply to your organisation.

✓

NIS2 applies to your organisation as an Essential or Important Entity.

!

NIS2 may apply to your organisation — seek legal advice to confirm your status.

Applies
Possibly applies
Does not apply

In-scope organisations are either essential or important entities. The obligations are the same; the supervision and the maximum fines differ. Essential entities are, as a rule, large organisations in the Annex I sectors, such as energy, transport, health, drinking water and digital infrastructure. Important entities are medium-sized organisations in those sectors and medium-sized and large organisations in Annex II, such as postal services, waste management, chemicals, food and manufacturing.

Out of scope isn't the same as unaffected. In-scope customers must weigh the security of their direct suppliers, which is why Dutch suppliers that are not covered themselves now receive questionnaires and new contract clauses. See why supply-chain security reaches suppliers.

The four obligations

The Cbw has four obligations: register with the NCSC, meet the duty of care with ten measures, report significant incidents in three steps, and put the management body in charge.

1. Registration

Organisations under the Cbw register in the entity register of the National Cyber Security Centre, via MijnNCSC. Companies log in with eHerkenning at level EH2+, government organisations with SSOnRijk. There is no transition period: according to the NCSC you must have been registered since 15 August 2026. If your details change later, you report the change within two weeks (article 44 Cbw).

Registration is the easy part of the law, and it still gets left on the list. Without it your sector CSIRT doesn't know you exist, and the first time you open MijnNCSC could be in the middle of an incident.

2. Duty of care

You map the risks to your network and information systems and take appropriate and proportionate measures. Article 21(2) of NIS2 names ten areas you must cover at a minimum, from risk analysis and incident handling to backups, supply-chain security, cryptography, access control and multi-factor authentication. The ten measures explained covers each one.

For digital providers such as cloud providers, data centres and managed service providers, Implementing Regulation (EU) 2024/2690 spells the measures out in more detail.

To turn the legal requirements into testable controls, the Auditdienst Rijk (the central government audit service) and NOREA published the Cbw Control Framework on 30 September 2025. If you need something an auditor will recognise, start there.

3. Reporting duty

You report a significant incident via mijn.ncsc.nl, and the report reaches the CSIRT and the supervisor for your sector. Article 29 of the Cbw sets three deadlines:

  1. Within 24 hours of becoming aware of it: an early warning.
  2. Within 72 hours: an incident notification with a first assessment of severity and impact.
  3. Within one month of the notification: a final report with the cause, the severity and the measures taken.

The difference between a report on time and a late one is rarely technical. It is whether someone is allowed to decide, at three in the morning, that this incident gets reported. More in the 24-hour, 72-hour and one-month deadlines.

4. The management body

Directors approve the measures, supervise their implementation and must know enough to recognise and assess cyber risks. Article 24 of the Cbw requires them to follow training on these subjects; directors already in office have two years to do so. A CISO can arrange a lot, but not that signature. Read more about personal board liability.

Who supervises you?

It depends on your sector. There is no single Cbw regulator: each domain has its own ministry, CSIRT and supervisory authority. The NCTV (the national coordinator for security and counterterrorism) publishes a referral tree that shows who is responsible per sector. Look yours up before you need it.

If you are a supplier working for customers in several sectors or countries, who supervises can differ per customer. See which regulator supervises your client.

Fines

The Cbw sets its maximum fines in the law itself: article 80 for essential entities, up to €10 million or 2% of worldwide annual turnover, and article 87 for important entities, up to €7 million or 1.4%, in both cases whichever is higher. Those maximums apply to breaches of the duty of care and the reporting duty. Other breaches, such as not reporting registration details or reporting them late, carry a maximum of €1 million.

NIS2 Penalty Escalation — Beyond the Fine

!

Trigger event

Non-Compliance Detected or Incident Occurs

A supervisory authority identifies a compliance gap or an organisation fails to meet NIS2 requirements

Authorities can impose
▼
Non-Monetary Penalties
1

Compliance orders with binding deadlines

2

Mandatory security audits at your expense

3

Public disclosure of violations

4

Binding instructions on specific security measures

Escalates to
▼
Operational & Personal Consequences
1

Suspension of certifications or operating licences

2

Temporary ban on management functions for individuals

3

Public naming of responsible natural persons

Trigger
Non-monetary
Operational / personal

A fine isn't the supervisor's only tool. It can also issue binding instructions and set a deadline to fix shortcomings, and those cost time and attention too. Penalties worse than a fine covers them.

What to do now

  1. Check whether you're in scope, per legal entity, with the size test and the NCSC's explanation.
  2. Register via MijnNCSC if you haven't. There is no grace period.
  3. Find your supervisor and CSIRT in the NCTV referral tree.
  4. Measure the gap against the ten measures, for example with the Cbw Control Framework or a NIS2 gap analysis.
  5. Book the board's training and put the approval of the measures on the agenda.

Want a first reading against the ten measures? Take the free NIS2 quick scan.

Frequently asked questions

When did the Cyberbeveiligingswet enter into force?

On 15 August 2026. The Senate approved the law on 7 July 2026. It replaced the Wbni, and the Wwke for critical entities took effect on the same day.

Where do I register?

In the NCSC's entity register, via MijnNCSC. Companies use eHerkenning at level EH2+, government organisations SSOnRijk. There is no later deadline: the registration duty has applied since 15 August 2026, and changes must be reported within two weeks.

Does the Cbw apply to small companies?

Usually not. Organisations with fewer than 50 employees and a turnover or balance sheet total of up to €10 million generally fall outside it. Exceptions include public bodies and DNS service providers, which are in scope regardless of size. Small suppliers often get the requirements through their customers anyway.

Is the Cbw the same as NIS2?

The Cbw is the Dutch implementation of NIS2. The obligations come from the directive; the law arranges the Dutch execution, such as registration with the NCSC and the supervisor per sector.

How many organisations fall under the Cbw?

About 8,000 organisations in 18 sectors, according to Rijksoverheid and the NCSC.

Still have a question?

Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.