Cybersecurity regulation in the Netherlands
Sep 02, 2026What Does the Cybersecurity Act mean for your organization?
The European NIS2 Directive is in the Netherlands implemented through a law called 'de Cyberbeveiligingswet (Cbw)'. The law took effect on August 15, 2026, and sets requirements for the digital resilience of organizations in the Netherlands. Does your organization fall under this law? If so, you will be subject to, among other things, a registration requirement, a duty of care, and a reporting requirement. The board of directors will also have explicit responsibilities in the area of cybersecurity.
What is the Cybersecurity Act?
- The Cybersecurity Act, abbreviated as Cbw, is the Dutch law that implements the European NIS2 Directive. The goal of NIS2 is to achieve a high, common level of cybersecurity within the European Union.
- The Cybersecurity Act replaces the previous Wet beveiliging netwerk- en informatiesystemen (Wbni). According to the NCTV, more than 8,000 organizations are subject to the new law.
The law consists of four main parts:
- Mandatory registration: Organizations subject to the law must register with the Entity Registry;
- Duty of care: Organizations must identify cyber risks and take appropriate and proportionate measures;
- Reporting Requirement: Significant incidents must be reported;
- Board-level responsibility: The board must approve measures to manage cyber risks and oversee their implementation. As a result, cybersecurity is no longer the sole responsibility of the IT department. The board, management, and other parts of the organization also have a role to play.
Who is subject to the Cybersecurity Act?
- Energy;
- Transport;
- Health care;
- Digital infrastructure;
- Water;
- Wastewater and Waste Management;
- Certain manufacturing companies;
- Postal and courier services;
- Digital service providers;
- Government agencies.
What are the requirements of the Cybersecurity Act?
- Mandatory Registration
Organizations subject to the Cybersecurity Act must register in the entity registry. Registration is done through MijnNCSC. Visit the NCSC website to learn how to register your organization. - Duty of Care
The duty of care involves taking appropriate measures to ensure that network and information systems remain secure, resilient, and continuously available. - Reporting Requirement
Significant incidents must be reported. The Cybersecurity Act sets forth a phased reporting procedure for this purpose. It is therefore important for organizations to establish in advance how cyber incidents will be detected, assessed, escalated, and reported.
Getting Started with the Cybersecurity Act in 6 Steps
The Cybersecurity Act in Relation to International Standards and Guidelines
Cybersecurity Act: From Obligation to Digital Resilience
- Active involvement of the board and management;
- Regular risk assessments;
- Clear roles and responsibilities;
- Employee awareness and training;
- Well-established incident procedures;
- Focus on risks within the supply chain;
- Periodic evaluation and improvement of measures.
Official Information on the Cybersecurity Act
DEKRA and the Cybersecurity Act
- Where are the most significant compliance gaps within your organization?
- Which standards are the best fit for your situation?
- What are the next steps?
Frequently Asked Questions About the Cybersecurity Act
Cybercrime in the EU
Overview of Cybersecurity Legislation
Is your organization ready for NIS2?

CCV pentesting quality mark

ISAE 3402 / 3000

ISO 27001 certification

ISO 27017 and ISO 27018

ISO 27701 certification

NEN 7510 certification

Pentesting

RED Directive testing