Skip to main content
Regulation

Cyberbeveiligingswet (Dutch NIS2)

The Cyberbeveiligingswet is the Dutch implementation of NIS2, Directive (EU) 2022/2555. It entered into force on 15 August 2026 and covers more than 8,000 organisations. Registration, the duty of care and the 24-hour and 72-hour reporting duties applied from day one. Banks are largely displaced to DORA by Articles 22 and 31, but their IT suppliers are not.

Checked by Remmert
7 min read

When did the Cyberbeveiligingswet enter into force?

15 August 2026. The Act was signed on 8 July 2026, published as Staatsblad 2026, 187 on 10 July, and brought into force by Article 35 of the Cyberbeveiligingsbesluit. It implements NIS2, Directive (EU) 2022/2555, covers more than 8,000 Dutch organisations across the sectors listed in Bijlage 1 and Bijlage 2 to the Act, and imposed registration, a duty of care and 24-hour and 72-hour incident reporting from day one.

There is no general transitional period. The only express grace window is two years for board training.

This is a page about who the law catches and what it displaces. See the other regulations we track, including DORA.

Last updated: 17 August 2026, two days after entry into force. Checked against the Staatsblad text and the Cyberbeveiligingsbesluit.

At a glance

Does a Dutch bank fall under the Cyberbeveiligingswet or under DORA?

Under DORA for substance, but not fully out of the Cbw. This is the point most commentary gets wrong, and the Dutch legislator handled it with two separate provisions, not one.

  • Article 22 Cbw disapplies the duty of care (Article 21) where a sector-specific EU act imposes at least equivalent cybersecurity risk-management obligations.
  • Article 31 Cbw disapplies the notification duty (Articles 25 to 30) on the same equivalence test.

DORA is that act. Article 4 and recital 28 of NIS2 name it, and the memorie van toelichting to the Cbw states that DORA's ICT risk-management provisions apply to a large part of the financial sector in place of the NIS2 provisions.

A DORA-covered financial entity is out from under Article 21 Cbw, the duty of care, and with it Articles 5 to 18 of the Cyberbeveiligingsbesluit, and out from under Articles 25 to 30 Cbw, the entire notification chain: 24-hour early warning, 72-hour notification, progress report, final report, and user notification.

It is not out from under the rest of the Act.

What is a DORA-covered bank still in for?

Five things the equivalence test does not touch.

  • Art. 44 Cbw

    Registration

    Essential entities, important entities and domain-name registration service providers must supply data for the national register. A bank remains an essential entity; only the substantive obligations are displaced. Registration goes through MijnNCSC.

  • Art. 47 Cbw

    ENISA register data

    Data for the ENISA register, where applicable.

  • Art. 42 Cbw

    EU representative

    Appointment of an EU representative, for non-EU-established providers in the relevant categories.

  • Wwke

    Critical-entity designation

    The Wwke is entirely unaffected. DORA is lex specialis to NIS2 only, not to the CER Directive, and banking and financial market infrastructure are express Wwke sectors. A designated critical entity gets 9 months for a risk assessment, 10 months for resilience measures, and a 24-hour disruption report.

  • DNB / AFM

    Supervision

    Supervision stays with the financial supervisors for Cbw purposes: DNB for banking, AFM for financial market infrastructure, with the Ministry of Finance as competent authority.

Our IT supplier serves a bank. Are we out too?

No. The lex specialis attaches to the entity, not to the supply chain.

Cloud computing service providers, data centre operators, content delivery networks, managed service providers and managed security service providers are Cbw entities in their own right: digital infrastructure and ICT service management, supervised by the RDI, as soon as they meet the size threshold. A supplier to a bank therefore typically faces two overlapping regimes at once. DORA obligations cascaded contractually from its bank client, plus its own direct duty of care, registration duty and 24-hour and 72-hour reporting duty.

Conversely, a bank's own supply-chain security obligation is a DORA obligation, not Article 21(3) Cbw.

Who is in scope?

The baseline is the size cap. An entity of a type in Annex I or II is caught if it is medium-sized or larger.

SizeThresholdEffect

Where size does not matter at all: central and decentralised government bodies, qualified trust service providers, TLD name registries, DNS service providers, providers of public electronic communications networks or services, and domain-name registration service providers. Also caught regardless of size: sole providers in the Netherlands of a service essential to critical societal or economic activity, entities whose disruption could significantly affect public safety, security or health, entities that could induce significant systemic risk particularly cross-border, and entities critical at national or regional level.

Essential versus important changes the supervision, not the obligations. Essential entities face proactive, ex ante supervision: compliance is actively checked even with no incident. Important entities face ex post supervision, mainly triggered by signals of non-compliance. The substantive duties are identical.

What does it require?

Six obligation families. Scope decides whether the other five ever reach you.

  • Annex I & II

    Financial institution scope

    Only banks and financial market infrastructure appear in the annexes. Payment institutions, e-money institutions, insurers and investment firms are not caught at all, and DORA only displaces part of what applies to the banks that are.

  • 43 to 47 Cbw + Art. 27 Besluit

    Registration

    Classification, KvK number, entity type, domain names, through MijnNCSC with eHerkenning. Changes notified within two weeks. Mandatory since 15 August 2026.

  • 21 Cbw + Arts. 6 to 18 Besluit

    Duty of care (zorgplicht)

    Ten measure categories: risk analysis and security policy, incident handling, continuity and crisis management, supply chain security, secure acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, HR security and access control, multi-factor authentication and secured communications.

  • 25 to 30 Cbw

    Notification duty (meldplicht)

    Early warning within 24 hours, notification with initial assessment within 72 hours, a progress report on request, and a final report within one month.

  • 24 Cbw

    Board accountability

    The board approves the measures and supervises implementation; members need demonstrable knowledge, evidenced by a certificate of participation.

  • 33 to 34 Cbw

    Voluntary vulnerability reporting

    Open to anyone, including entities outside scope; anonymous reporting permitted.

Who supervises which sector?

The official mapping is the NCTV's Doorverwijsboom Cyberbeveiligingswet.

SectorSupervisor

How fast must you report an incident?

Reports go to both the CSIRT (NCSC) and the sectoral supervisor.

StepDeadlineArticle

The dates

2024

  1. 17 October 2024Passed

    NIS2 transposition deadline, missed

  2. 7 November 2024Passed

    Implementing Regulation (EU) 2024/2690 becomes applicable, directly binding on digital providers

2026

  1. 8 July 2026Passed

    Act signed; Commission refers the Netherlands to the CJEU the same week

  2. 15 August 2026Passed

    Cyberbeveiligingswet, Cyberbeveiligingsbesluit and Wwke enter into force. Registration, duty of care and notification duty apply, and Wwke designations begin. No general transitional period

2027

  1. 17 October 2027Upcoming

    Article 40 NIS2 review of sectors, size criteria and entity types; every 36 months thereafter

2028

  1. 15 August 2028Upcoming

    Board training and knowledge deadline (Art. 24 Cbw, two years)

Differences by country

Member StateInstrumentIn force

Twenty-three of twenty-seven Member States had transposed into primary law by mid-May 2026. The Netherlands, Ireland, Spain and France were the four that had not, and all four were referred to the Court of Justice on 8 July 2026. With the Netherlands now in force the practical count is twenty-four, leaving Ireland, Spain and France. Read carefully: the Commission distinguishes primary-law transposition from full transposition including secondary legislation, so official counts run lower than tracker counts.

The Netherlands therefore sits in the bottom four of the EU-27 on NIS2, roughly 22 months behind Belgium and 8 months behind Germany, and now ahead of three Member States that still have nothing.

What recently changed

15 August 2026: entry into force. Together with the Cyberbeveiligingsbesluit and the Wwke. The inwerkingtredingsbesluit was folded into the Cyberbeveiligingsbesluit itself rather than issued as a separate royal decree.

7 July 2026: the government announced the date. On scope, the figure to use is the NCTV's: "ruim 8.000 organisaties" fall under the Cyberbeveiligingswet. A figure of 10,000 circulates in trade-body material; 8,000 is the official estimate. We have not been able to confirm a per-sector breakdown of that 8,000, or an official count of designated critical entities under the Wwke, on any primary government page. The NCTV's page on who is covered gives no number and states only that sector ministers make the designations. We do not publish the figures that circulate for either.

7 July 2026: Eerste Kamer adoption, with only FVD against, following Tweede Kamer adoption on 15 April 2026. The bill had been submitted on 2 June 2025, after Raad van State advice of 19 February 2025 that criticised the national-security exception for government bodies, the articulation of the coordinating role, overlapping supervision between ministries and independent authorities, and the RDI's independence in supervising government entities including itself.

18 March 2026: the NCTV published the Doorverwijsboom, the official sector-to-ministry-to-CSIRT-to-supervisor mapping.

20 January 2026: the Commission proposed amending NIS2. COM(2026) 13 final targets simpler jurisdictional rules, faster collection of ransomware attack data and easier cross-border supervision with a stronger ENISA role. It complements the Digital Omnibus proposal for a single entry point for cybersecurity incident reporting across NIS2, GDPR, DORA and the Cyber Resilience Act. It is a proposal only, and does not affect Cbw obligations today.

What can GenCompl.ai do for you?

Our pipeline tracks the Cbw, the Cyberbeveiligingsbesluit, the sectoral Cyberbeveiligingsregelingen and their EU parents, and derives which regime actually applies to a given entity. That includes the Article 22 and Article 31 displacement to DORA, and the point at which a group's IT subsidiary picks up its own Cbw duties that its regulated parent does not have. Each conclusion carries the article, the source and the date it was last recalculated.

Questions and answers

Do I have to register, and where?
Is my company in scope if it has fewer than 50 employees?
Can a director be held personally liable?
How high are the fines?
Is there a transition period?
How fast must I report an incident?
We are a DORA entity. Do we ignore the Cyberbeveiligingswet entirely?
Wasn't the Netherlands late? What were the consequences?

Glossary

  • Incident (Cyberbeveiligingswet)

    Een gebeurtenis die de beschikbaarheid, authenticiteit, integriteit of vertrouwelijkheid van opgeslagen, verzonden of verwerkte gegevens of van de diensten die via netwerk- en informatiesystemen worden aangeboden of toegankelijk zijn, aantast. De Cyber Resilience Act hanteert een andere definitie.

  • ICT-dienst

    Een dienst die volledig of hoofdzakelijk bestaat in de verzending, opslag, opvraging of verwerking van gegevens door middel van netwerk- en informatiesystemen.

  • Hoofdvestiging

    De plaats waar de beslissingen in verband met de maatregelen voor het beheer van cyberbeveiligingsrisico’s hoofdzakelijk worden genomen binnen de Europese Unie.

  • Grootschalig cyberbeveiligingsincident

    Een incident dat een dermate grote verstoring veroorzaakt dat het de capaciteit van een lidstaat om erop te reageren te boven gaat, of dat aanzienlijke gevolgen heeft voor ten minste twee lidstaten.

  • Gekwalificeerde vertrouwensdienst

    Een vertrouwensdienst die voldoet aan de toepasselijke eisen zoals vastgelegd in Verordening (EU) nr. 910/2014.

  • Gekwalificeerde verlener van vertrouwensdiensten

    Een verlener van vertrouwensdiensten die een of meer gekwalificeerde vertrouwensdiensten verleent en aan wie door het toezichthoudend orgaan de gekwalificeerde status is toegekend zoals vastgelegd in Verordening (EU) nr. 910/2014.

  • Essentiële entiteit

    Een essentiële entiteit als bedoeld in artikel 3, eerste lid, van de NIS2-richtlijn en bedoeld in de artikelen 8 tot en met 11 van deze wet.

  • Entiteit die domeinnaamregistratiediensten verleent

    Een registrar of een agent die namens registrars optreedt, zoals een verlener van privacy- of proxyregistratiediensten of een wederverkoper.

  • Entiteit

    Een natuurlijke persoon of rechtspersoon die is opgericht en erkend krachtens het nationale recht van de plaats van vestiging, die onder eigen naam rechten kan uitoefenen en aan verplichtingen kan worden onderworpen.

  • Enisa

    Het Agentschap van de Europese Unie voor cyberbeveiliging, opgericht bij Verordening (EU) 2019/881.