NIS2 Country Guide

NIS2 Netherlands: Cyberbeveiligingswet, Deadlines & Authorities

The Dutch Cyberbeveiligingswet (Cbw) transposes NIS2 and applies from 15 August 2026. Around 8,000 organisations are in scope. There is no general grace period: registration, the duty of care and incident reporting all start on day one.

Netherlands In force: 15 Aug 2026 Register from: 15 Aug 2026 Law: Cyberbeveiligingswet (Cbw) Last updated: 1 Aug 2026

Introduction: NIS2 Directive & the Dutch context

The Netherlands has transposed NIS2 through the Cyberbeveiligingswet (Cbw), published as Staatsblad 2026, 187. It applies from 15 August 2026, together with the Cyberbeveiligingsbesluit (Staatsblad 2026, 189), the decree that fills in the detail. The Wet weerbaarheid kritieke entiteiten (Wwke), which implements the CER Directive, starts the same day.

The Cbw replaces the Wbni (2018) and covers roughly 8,000 organisations, many of which had no cybersecurity obligations before. The Netherlands missed the 17 October 2024 transposition deadline, and on 8 July 2026, one day after the Senate approved the bill, the European Commission referred it to the Court of Justice of the EU along with Ireland, Spain and France.

Quick link: Before reading details for the Netherlands, see “What is NIS2?” and “NIS vs NIS2”.

What you must do in the Netherlands

Five obligations, in the order they hit you. All of them start on 15 August 2026.

  1. Work out whether you are in scope, and whether you are an essential or an important entity. The Cbw applies automatically; nobody sends you a letter.
  2. Register on Mijn.NCSC.nl from 15 August 2026. You need eHerkenning at level EH3 or higher. See Registration.
  3. Meet the duty of care from day one. There is no transition period, so the risk-management measures must already be in place on 15 August.
  4. Be able to report an incident within 24 hours. The clock is short and it starts when you become aware. See Incident reporting.
  5. Get your management body trained and keep the evidence. Directors carry final responsibility under the Cbw, and training has to be documented.
If you only do one thing this month: confirm who in your organisation holds eHerkenning EH3. Without it you cannot complete registration, and obtaining it is not instant.

NIS2 implementation in the Netherlands

The Netherlands implements NIS2 through the Cyberbeveiligingswet (Cbw). The Act:

  • replaces the Wbni (2018),
  • extends the scope to around 8,000 organisations,
  • adds obligations for governance, risk management and supply-chain security,
  • strengthens the supervisory powers of the Dutch regulators,
  • sets binding deadlines for reporting cybersecurity incidents.

Status

In force from 15 August 2026. Approved by the Senate on 7 July 2026 and published as Staatsblad 2026, 187, with the Cyberbeveiligingsbesluit as Staatsblad 2026, 189.

Key change

NIS2 brings a much larger scope of essential and important entities, including digital infrastructure, healthcare providers, manufacturing, waste management, postal services, cloud & MSPs.

NIS2 Netherlands: what you need to know about compliance & supervision

The Netherlands will follow the NIS2 essential/important entity model, with strong emphasis on incident reporting, governance, supply-chain security and minimum security measures.

Scope criteria

  • Organisations operating in sectors listed in Annex I or II of NIS2.
  • Medium-sized entities (≥50 employees or ≥€10m turnover) unless specifically excluded.
  • Certain entities covered regardless of size (DNS, TLD registries, cloud services, etc.).
  • MSPs/MSSPs and IT service providers are explicitly in scope.

Core obligations

  • Risk management & security policies (IT/OT)
  • Incident detection, reporting & response
  • Business continuity and crisis procedures
  • Supply-chain & vendor security controls
  • Encryption, access control, patching, vulnerability management
  • Board-level accountability & training

Standards & certification

Dutch regulators refer to ISO 27001, NIST CSF, CIS Controls and sector-specific regulations (healthcare, energy, finance). No single standard is mandated.

Incident reporting: Entities must report significant incidents to the NCSC-NL or their sectoral CSIRT within strict NIS2 timelines (early warning, 24 hours, 72 hours, final report).

Competent authorities & CSIRT

The Netherlands uses a decentralised supervisory structure, coordinated by the Ministry of Justice & Security.

RoleAuthorityNotes
National authority / NIS2 coordinator Ministry of Justice & Security Coordinates national NIS2 policy, enforcement and cross-sectoral standards.
National CSIRT NCSC-NL (Nationaal Cyber Security Centrum) 24/7 incident handling for essential entities; publishes national threat intelligence.
Digital Services Agentschap Telecom (RDI) Supervises digital infrastructure, cloud providers, data centers, DNS, IXPs.
Energy sector ACM & TSO/DSO coordination bodies Supervises operators in electricity, gas and district heating.
Healthcare Ministry of Health (VWS) Oversees hospitals, labs, digital health providers.
Finance DNB & AFM Coordinates NIS2 obligations with DORA regulation.

Registration: who, where, by when

Registration is a legal duty, not an invitation. It opens and becomes mandatory on the same day the law starts.

Where

Mijn.NCSC.nl, the national entity register run by the NCSC.

Login

eHerkenning at level EH3 or higher. Certain public bodies use SSOnRijk instead.

When

Mandatory from 15 August 2026. Changes to your details must be reported within two weeks.

What the register asks for:

  • Organisation name and address
  • The sector you operate in
  • The EU member states where you provide your services
  • Current contact details for cybersecurity matters
  • IP ranges and other technical data, where these apply to your services
Failing to register can lead to a fine or an order subject to a penalty payment (last onder dwangsom). Registration is separate from the duty of care: doing one does not discharge the other.

Incident reporting in the Netherlands

A significant incident is one that causes, or could cause, serious operational disruption to your services or financial loss to your organisation. Reports go to your CSIRT and to your supervisory authority.

Within 24 hours — early warning, from the moment you become aware of the incident. State whether it looks malicious and whether it may have cross-border effects.
Within 72 hours — incident notification, updating the early warning with an initial assessment of severity, impact and any indicators of compromise.
Within one month — final report covering the root cause, the mitigations applied and any cross-border impact.
Build the 24-hour path before you need it. The deadline runs from awareness, not from confirmation, so the decision to report usually has to be made while you still have an incomplete picture. Agree in advance who can trigger a report out of hours.

NIS2 timeline & key dates (Netherlands)

27 Dec 2022 — NIS2 Directive published.
17 Oct 2024 — EU transposition deadline (Netherlands missed).
2024 — Public consultation on the draft Act.
15 Apr 2026 — The House of Representatives (Tweede Kamer) approves the Cyberbeveiligingswet.
7 Jul 2026 — The Senate (Eerste Kamer) approves the Act.
8 Jul 2026 — The European Commission refers the Netherlands to the Court of Justice of the EU over the delayed transposition.
15 Aug 2026 — Cyberbeveiligingswet, Cyberbeveiligingsbesluit and Wwke all enter into force. Registration becomes mandatory. No general grace period.

Sector-specific requirements (Netherlands)

  • Energy: electricity, gas, oil, district heating overseen by ACM; strong alignment with EU sector rules.
  • Healthcare: hospitals, laboratories, e-health systems, diagnostic services.
  • Transport: air, rail, maritime and road infrastructure operators.
  • Digital infrastructure: data centres, DNS, IXPs, TLD registries, cloud hosting, MSPs.
  • Public sector: municipalities and government agencies affected where providing essential services.
  • Finance: coordinated with DNB/AFM under DORA.

How the Dutch law differs from the NIS2 Directive

The Cbw follows NIS2 closely. Three choices are worth knowing about because they affect what you actually have to do.

AreaWhat the Netherlands does
No grace periodDutch law provides no general transition period. Several member states phased their obligations in; the Netherlands did not. Everything applies from 15 August 2026.
Decentralised supervisionThere is no single NIS2 regulator. Supervision sits with the sector authority that already regulates you, so two organisations in different sectors answer to different bodies under the same Act.
Dual reportingSignificant incidents go to the CSIRT and to the supervisory authority. One report to one address is not enough.

Operating in more than one EU country?

This is where organisations most often get it wrong, and the Dutch register makes the distinction explicit.

Register once

DNS providers, TLD registries, cloud computing providers, data centre providers, CDNs, managed service providers and managed security service providers register only in the member state where their main establishment sits, and are supervised there.

Register in each country

Every other type of entity registers separately in each member state where it provides in-scope services. Operating in five countries can mean five registrations and five supervisors.

Rules that are the same everywhere

For the digital and ICT entity types above, Implementing Regulation (EU) 2024/2690 sets the technical requirements directly. It is not transposed, so it reads identically in all 27 member states.

Also in scope elsewhere? See our guides for Germany, Belgium and France, or the full country index.

Penalties for non-compliance

The Netherlands applies the NIS2 penalty ceilings. Supervisors can also impose an order subject to a penalty payment (last onder dwangsom), which in practice arrives sooner than a fine.

  • Essential entities: up to €10 million or 2% of worldwide annual turnover, whichever is higher.
  • Important entities: up to €7 million or 1.4% of worldwide annual turnover, whichever is higher.
  • Directors carry final responsibility for compliance, and management training must be documented.
  • Orders to take corrective action.
  • Mandatory audits and ongoing supervision.
  • Temporary suspension of activities in extreme cases.

Additional fines may apply under the Telecommunications Act and other Dutch regulations, depending on the sector.

How to prepare for NIS2 in the Netherlands

  1. Determine scope: identify whether you qualify as an essential or important entity.
  2. Perform a NIS2 gap assessment: compare existing controls to NIS2 requirements.
  3. Strengthen governance: ensure board accountability and assign security responsibilities.
  4. Update risk management: implement robust IT/OT security measures and monitoring.
  5. Review supply chain: update contracts to include supplier cybersecurity obligations.
  6. Prepare for reporting: set up incident detection and escalation procedures.
  7. Train staff & management: run awareness programs and tabletop exercises.
  8. Document everything: evidence policies, procedures, controls and improvements.

Official links & resources

FAQ: NIS2 in the Netherlands

Has the Netherlands implemented NIS2?
Yes. The Cyberbeveiligingswet applies from 15 August 2026. The Netherlands missed the October 2024 deadline and was referred to the EU Court of Justice on 8 July 2026, one day after the Senate approved the Act.
What law will replace the Wbni?
The Cyberbeveiligingswet (Cbw) replaces the Wbni (2018).
Who will supervise NIS2?
Supervision will be shared between the Ministry of Justice & Security, NCSC-NL and several sectoral regulators, depending on the type of service.
Which entities will be in scope?
Essential and important entities from Annex I & II of NIS2, including energy, healthcare, transport, digital services, public administration, postal services, waste management, manufacturing and more.
Will NIS2 require ISO 27001 certification?
No mandatory certification is imposed, but ISO 27001 or similar frameworks (NIST CSF) provide strong alignment and are widely recommended.
Is there a grace period after 15 August 2026?
No. Dutch law provides no general transition period. Registration, the duty of care and incident reporting all apply from day one.
We operate in several EU countries. Do we register in each one?
It depends on what you provide. DNS, cloud, data centre, CDN and managed service providers register only in the member state of their main establishment. Every other entity type registers separately in each member state where it provides in-scope services.
Information provided for general guidance; consult official Dutch sources for updates as the Cybersecurity Act is finalised.