NIS2 Netherlands: Cyberbeveiligingswet, Deadlines & Authorities
The Dutch Cyberbeveiligingswet (Cbw) transposes NIS2 and applies from 15 August 2026. Around 8,000 organisations are in scope. There is no general grace period: registration, the duty of care and incident reporting all start on day one.
Introduction: NIS2 Directive & the Dutch context
The Netherlands has transposed NIS2 through the Cyberbeveiligingswet (Cbw), published as Staatsblad 2026, 187. It applies from 15 August 2026, together with the Cyberbeveiligingsbesluit (Staatsblad 2026, 189), the decree that fills in the detail. The Wet weerbaarheid kritieke entiteiten (Wwke), which implements the CER Directive, starts the same day.
The Cbw replaces the Wbni (2018) and covers roughly 8,000 organisations, many of which had no cybersecurity obligations before. The Netherlands missed the 17 October 2024 transposition deadline, and on 8 July 2026, one day after the Senate approved the bill, the European Commission referred it to the Court of Justice of the EU along with Ireland, Spain and France.
What you must do in the Netherlands
Five obligations, in the order they hit you. All of them start on 15 August 2026.
- Work out whether you are in scope, and whether you are an essential or an important entity. The Cbw applies automatically; nobody sends you a letter.
- Register on Mijn.NCSC.nl from 15 August 2026. You need eHerkenning at level EH3 or higher. See Registration.
- Meet the duty of care from day one. There is no transition period, so the risk-management measures must already be in place on 15 August.
- Be able to report an incident within 24 hours. The clock is short and it starts when you become aware. See Incident reporting.
- Get your management body trained and keep the evidence. Directors carry final responsibility under the Cbw, and training has to be documented.
NIS2 implementation in the Netherlands
The Netherlands implements NIS2 through the Cyberbeveiligingswet (Cbw). The Act:
- replaces the Wbni (2018),
- extends the scope to around 8,000 organisations,
- adds obligations for governance, risk management and supply-chain security,
- strengthens the supervisory powers of the Dutch regulators,
- sets binding deadlines for reporting cybersecurity incidents.
Status
In force from 15 August 2026. Approved by the Senate on 7 July 2026 and published as Staatsblad 2026, 187, with the Cyberbeveiligingsbesluit as Staatsblad 2026, 189.
Official law
Cyberbeveiligingswet — Staatsblad 2026, 187 and the Cyberbeveiligingsbesluit — Staatsblad 2026, 189. The Cbw replaces the Wbni (2018).
Key change
NIS2 brings a much larger scope of essential and important entities, including digital infrastructure, healthcare providers, manufacturing, waste management, postal services, cloud & MSPs.
NIS2 Netherlands: what you need to know about compliance & supervision
The Netherlands will follow the NIS2 essential/important entity model, with strong emphasis on incident reporting, governance, supply-chain security and minimum security measures.
Scope criteria
- Organisations operating in sectors listed in Annex I or II of NIS2.
- Medium-sized entities (≥50 employees or ≥€10m turnover) unless specifically excluded.
- Certain entities covered regardless of size (DNS, TLD registries, cloud services, etc.).
- MSPs/MSSPs and IT service providers are explicitly in scope.
Core obligations
- Risk management & security policies (IT/OT)
- Incident detection, reporting & response
- Business continuity and crisis procedures
- Supply-chain & vendor security controls
- Encryption, access control, patching, vulnerability management
- Board-level accountability & training
Standards & certification
Dutch regulators refer to ISO 27001, NIST CSF, CIS Controls and sector-specific regulations (healthcare, energy, finance). No single standard is mandated.
Registration: who, where, by when
Registration is a legal duty, not an invitation. It opens and becomes mandatory on the same day the law starts.
Where
Mijn.NCSC.nl, the national entity register run by the NCSC.
Login
eHerkenning at level EH3 or higher. Certain public bodies use SSOnRijk instead.
When
Mandatory from 15 August 2026. Changes to your details must be reported within two weeks.
What the register asks for:
- Organisation name and address
- The sector you operate in
- The EU member states where you provide your services
- Current contact details for cybersecurity matters
- IP ranges and other technical data, where these apply to your services
Incident reporting in the Netherlands
A significant incident is one that causes, or could cause, serious operational disruption to your services or financial loss to your organisation. Reports go to your CSIRT and to your supervisory authority.
NIS2 timeline & key dates (Netherlands)
Sector-specific requirements (Netherlands)
- Energy: electricity, gas, oil, district heating overseen by ACM; strong alignment with EU sector rules.
- Healthcare: hospitals, laboratories, e-health systems, diagnostic services.
- Transport: air, rail, maritime and road infrastructure operators.
- Digital infrastructure: data centres, DNS, IXPs, TLD registries, cloud hosting, MSPs.
- Public sector: municipalities and government agencies affected where providing essential services.
- Finance: coordinated with DNB/AFM under DORA.
How the Dutch law differs from the NIS2 Directive
The Cbw follows NIS2 closely. Three choices are worth knowing about because they affect what you actually have to do.
| Area | What the Netherlands does |
|---|---|
| No grace period | Dutch law provides no general transition period. Several member states phased their obligations in; the Netherlands did not. Everything applies from 15 August 2026. |
| Decentralised supervision | There is no single NIS2 regulator. Supervision sits with the sector authority that already regulates you, so two organisations in different sectors answer to different bodies under the same Act. |
| Dual reporting | Significant incidents go to the CSIRT and to the supervisory authority. One report to one address is not enough. |
Operating in more than one EU country?
This is where organisations most often get it wrong, and the Dutch register makes the distinction explicit.
Register once
DNS providers, TLD registries, cloud computing providers, data centre providers, CDNs, managed service providers and managed security service providers register only in the member state where their main establishment sits, and are supervised there.
Register in each country
Every other type of entity registers separately in each member state where it provides in-scope services. Operating in five countries can mean five registrations and five supervisors.
Rules that are the same everywhere
For the digital and ICT entity types above, Implementing Regulation (EU) 2024/2690 sets the technical requirements directly. It is not transposed, so it reads identically in all 27 member states.
Penalties for non-compliance
The Netherlands applies the NIS2 penalty ceilings. Supervisors can also impose an order subject to a penalty payment (last onder dwangsom), which in practice arrives sooner than a fine.
- Essential entities: up to €10 million or 2% of worldwide annual turnover, whichever is higher.
- Important entities: up to €7 million or 1.4% of worldwide annual turnover, whichever is higher.
- Directors carry final responsibility for compliance, and management training must be documented.
- Orders to take corrective action.
- Mandatory audits and ongoing supervision.
- Temporary suspension of activities in extreme cases.
Additional fines may apply under the Telecommunications Act and other Dutch regulations, depending on the sector.
How to prepare for NIS2 in the Netherlands
- Determine scope: identify whether you qualify as an essential or important entity.
- Perform a NIS2 gap assessment: compare existing controls to NIS2 requirements.
- Strengthen governance: ensure board accountability and assign security responsibilities.
- Update risk management: implement robust IT/OT security measures and monitoring.
- Review supply chain: update contracts to include supplier cybersecurity obligations.
- Prepare for reporting: set up incident detection and escalation procedures.
- Train staff & management: run awareness programs and tabletop exercises.
- Document everything: evidence policies, procedures, controls and improvements.
