Cybersecurity regulation in the Netherlands

Sep 02, 2026

What Does the Cybersecurity Act mean for your organization?

The European NIS2 Directive is in the Netherlands implemented through a law called 'de Cyberbeveiligingswet (Cbw)'. The law took effect on August 15, 2026, and sets requirements for the digital resilience of organizations in the Netherlands. Does your organization fall under this law? If so, you will be subject to, among other things, a registration requirement, a duty of care, and a reporting requirement. The board of directors will also have explicit responsibilities in the area of cybersecurity.

De Cyberbeveiligingswet, which in this article we will call the Cybersecurity Act, affects thousands of organizations in sectors such as energy, healthcare, industry, transportation, and digital infrastructure. For these organizations, cybersecurity is thus becoming a critical organization-wide issue.
On this page, you can learn what the Cybersecurity Act in the Netherlands entails, who it applies to, and what steps you can take to get started.

What is the Cybersecurity Act?

  • The Cybersecurity Act, abbreviated as Cbw, is the Dutch law that implements the European NIS2 Directive. The goal of NIS2 is to achieve a high, common level of cybersecurity within the European Union.
  • The Cybersecurity Act replaces the previous Wet beveiliging netwerk- en informatiesystemen (Wbni). According to the NCTV, more than 8,000 organizations are subject to the new law.

The law consists of four main parts:

  • Mandatory registration: Organizations subject to the law must register with the Entity Registry;
  • Duty of care: Organizations must identify cyber risks and take appropriate and proportionate measures;
  • Reporting Requirement: Significant incidents must be reported;
  • Board-level responsibility: The board must approve measures to manage cyber risks and oversee their implementation. As a result, cybersecurity is no longer the sole responsibility of the IT department. The board, management, and other parts of the organization also have a role to play.

Who is subject to the Cybersecurity Act?

The Cybersecurity Act applies to organizations that operate in specific sectors and meet the criteria set forth in the Act. Factors such as the type of organization, the sector, and, in many cases, the size of the organization are decisive in this regard.
These include, for example, organizations in sectors such as:
  • Energy;
  • Transport;
  • Health care;
  • Digital infrastructure;
  • Water;
  • Wastewater and Waste Management;
  • Certain manufacturing companies;
  • Postal and courier services;
  • Digital service providers;
  • Government agencies.
Different rules apply to certain types of organizations, and the law may apply regardless of their size.
The Cybersecurity Act also distinguishes between essential and important entities. This distinction is relevant, among other things, for monitoring compliance with the Act. Use this page to check whether your organization is subject to the Cybersecurity Act.

What are the requirements of the Cybersecurity Act?

Organizations subject to the Cybersecurity Act must comply with various legal obligations. Three aspects are particularly important in this regard.
  1. Mandatory Registration
    Organizations subject to the Cybersecurity Act must register in the entity registry. Registration is done through MijnNCSC. Visit the NCSC website to learn how to register your organization.
  2. Duty of Care
    The duty of care involves taking appropriate measures to ensure that network and information systems remain secure, resilient, and continuously available.
  3. Reporting Requirement
    Significant incidents must be reported. The Cybersecurity Act sets forth a phased reporting procedure for this purpose. It is therefore important for organizations to establish in advance how cyber incidents will be detected, assessed, escalated, and reported.
In addition to these obligations, the law sets requirements regarding the board’s involvement. Among other things, board members must have sufficient knowledge to assess cyber risks and countermeasures.

Getting Started with the Cybersecurity Act in 6 Steps

Are you aware that your organization is subject to the Cybersecurity Act? If so, you can use the steps below to get started in a structured way.
Check which sector your organization operates in and whether you meet the criteria set forth in the law. Also determine whether your organization is classified as an essential or important entity. Check with the NCTV to see if your organization is subject to the law.
Does your organization fall under the scope of the law? If so, be sure to register with the Entity Registry via MijnNCSC.
Assess which cybersecurity measures are already in place. In doing so, consider not only technical security but also policies, processes, responsibilities, incident management, and supply chain risks.
The government offers various tools for this purpose, including the NIS2 Quick Scan and the Cbw Control Framework.
Identify the key risks to your network and information systems. Then assess what measures are needed to manage these risks in an appropriate and proportionate manner.
Compare the existing measures with the requirements of the Cybersecurity Act. Set priorities for measures that are still missing or have not been adequately implemented.
You are responsible for ensuring that your operations comply with the Cybersecurity Act. However, obtaining independent certification from a certification body such as DEKRA will greatly help you comply with this law. DEKRA certifies your organization in accordance with the NIS2 Directive, after which you can declare that you comply with the Cybersecurity Act. Furthermore, an independent audit provides a much broader insight into your organization’s security posture.
Determine who is responsible for cybersecurity, incidents, reporting, and oversight. Also ensure that the board is actively involved.
Cyber risks are constantly changing. Therefore, periodically assess whether your measures are still appropriate and effective, and improve them as needed.

The Cybersecurity Act in Relation to International Standards and Guidelines

Internationally recognized standards help organizations structure their processes, manage risks, and objectively demonstrate compliance. Depending on your organization, various standards may be relevant:

Cybersecurity Act: From Obligation to Digital Resilience

The Cybersecurity Act requires more than just the one-time implementation of a number of security measures. Organizations must manage cyber risks on an ongoing basis and continue to evaluate their measures.
A mature cybersecurity approach therefore includes, among other things:
  • Active involvement of the board and management;
  • Regular risk assessments;
  • Clear roles and responsibilities;
  • Employee awareness and training;
  • Well-established incident procedures;
  • Focus on risks within the supply chain;
  • Periodic evaluation and improvement of measures.
In this way, compliance with the Cybersecurity Act can simultaneously contribute to greater digital resilience and improved business continuity.

Official Information on the Cybersecurity Act

For the latest legal information and resources, please visit the Dutch government's website:

DEKRA and the Cybersecurity Act

The Cybersecurity Act requires organizations to manage cyber risks in a structured manner. International standards can help organizations systematically establish relevant aspects of information and cybersecurity and have them independently assessed. DEKRA supports organizations with independent audits, GAP analyses, and certifications in the field of cybersecurity.
With DEKRA’s expertise, you’ll gain insight into key questions regarding your organization’s cybersecurity:
  • Where are the most significant compliance gaps within your organization?
  • Which standards are the best fit for your situation?
  • What are the next steps?
Would you like to learn more about how DEKRA can help your organization take its cybersecurity to the next level? Simply contact us using the form below.

Frequently Asked Questions About the Cybersecurity Act

The Cybersecurity Act (Cbw) is the Dutch implementation of the European NIS2 Directive. The Act sets requirements for the digital resilience of organizations and includes, among other things, a registration requirement, a duty of care, and a reporting requirement.
No. NIS2 is a European directive, and the Cybersecurity Act is the Dutch law that implements this directive. For organizations in the Netherlands, the legal obligations under NIS2 are therefore set forth in the Cybersecurity Act.
The Cybersecurity Act took effect on August 15, 2026. The Act replaces the previous Network and Information Systems Security Act (Wbni).
Organizations can register in the entity registry via MijnNCSC. The NCSC provides information about the registration process and the required information.
No, ISO 27001 certification is not automatically required to comply with the Cybersecurity Act. However, the standard does address various topics relevant to the duty of care and can therefore serve as a useful foundation for the systematic management of information security.
No. ISO 27001 certification does not automatically mean that your organization complies with all the requirements of the Cybersecurity Act. However, various processes and control measures within an ISMS may align with the provisions of the Act.