What recently changed
15 August 2026: entry into force. Together with the Cyberbeveiligingsbesluit and the Wwke. The inwerkingtredingsbesluit was folded into the Cyberbeveiligingsbesluit itself rather than issued as a separate royal decree.
7 July 2026: the government announced the date. On scope, the figure to use is the NCTV's: "ruim 8.000 organisaties" fall under the Cyberbeveiligingswet. A figure of 10,000 circulates in trade-body material; 8,000 is the official estimate. We have not been able to confirm a per-sector breakdown of that 8,000, or an official count of designated critical entities under the Wwke, on any primary government page. The NCTV's page on who is covered gives no number and states only that sector ministers make the designations. We do not publish the figures that circulate for either.
7 July 2026: Eerste Kamer adoption, with only FVD against, following Tweede Kamer adoption on 15 April 2026. The bill had been submitted on 2 June 2025, after Raad van State advice of 19 February 2025 that criticised the national-security exception for government bodies, the articulation of the coordinating role, overlapping supervision between ministries and independent authorities, and the RDI's independence in supervising government entities including itself.
18 March 2026: the NCTV published the Doorverwijsboom, the official sector-to-ministry-to-CSIRT-to-supervisor mapping.
20 January 2026: the Commission proposed amending NIS2. COM(2026) 13 final targets simpler jurisdictional rules, faster collection of ransomware attack data and easier cross-border supervision with a stronger ENISA role. It complements the Digital Omnibus proposal for a single entry point for cybersecurity incident reporting across NIS2, GDPR, DORA and the Cyber Resilience Act. It is a proposal only, and does not affect Cbw obligations today.