Key takeaway: the Netherlands now has a date. The Cyberbeveiligingswet and the Wet weerbaarheid kritieke entiteiten were adopted by the Eerste Kamer on 7 July 2026 and take effect on 15 August 2026. There is no separate grace period bolted on afterwards: from that date the duties apply. Registration with the NCSC is already open, which makes the weeks before the date the cheapest ones you will get.

For two years the honest answer to "when does NIS2 actually bite in the Netherlands" was "when the law passes". That answer expired on 7 July 2026, when the Eerste Kamer adopted both the Cyberbeveiligingswet (Cbw) and the Wet weerbaarheid kritieke entiteiten (Wwke). Both enter into force on 15 August 2026.

This article covers what each law asks of you, who supervises it, where incidents go, and what is worth having on the shelf before the date rather than after.

Two laws, two different questions

They arrived together and they are often mentioned in one breath, but they ask different things.

The Cbw is the Dutch NIS2

The Cyberbeveiligingswet transposes Directive (EU) 2022/2555 into Dutch law. It covers digital security: risk-management measures, incident reporting, registration, supervision, and duties for the management body. Whether it applies to you follows from your sector and your size, and you work that out yourself. The government publishes a self-assessment, the NIS2 Zelfevaluatie, that walks through the test.

The Wwke is about staying standing, physically

The Wet weerbaarheid kritieke entiteiten implements the CER Directive and covers physical resilience of critical entities: sabotage, natural hazards, accidents, disruption of the service itself. Here you do not assess yourself into scope. The responsible minister designates critical entities per sector on the basis of a sectoral risk assessment, and tells them confidentially. If you have not been designated, you are not a critical entity under the Wwke.

The link between the two: an entity designated as critical under the Wwke automatically counts as an essential entity under the Cbw. One letter therefore lands you in both regimes at once, with the heavier supervisory tier of the two.

What the Cbw asks from 15 August

The substance will be familiar to anyone who has read the directive, because it is the directive. Four things become concrete on the date.

Registration with the NCSC

Entities in scope register with the NCSC. The portal at mijn.ncsc.nl is already open, so registration can be finished before the law takes effect. Treat it as a data exercise rather than a form: name and legal form, addresses and contact details, sector and subsector, the member states where you provide services, and your IP ranges. Keeping that set current is itself a duty, not a one-off.

Security measures

The ten measures of Article 21 apply, proportionate to your size and risk: risk analysis and policy, incident handling, business continuity including backup and crisis management, supply chain security, secure acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication with secured communications.

Incident reporting to a sectoral CSIRT

This is where the Dutch implementation differs from the mental model most boards carry. Reporting does not run to one central desk. Significant incidents go to the CSIRT for your sector, with the NCSC acting as the national CSIRT and as the sectoral CSIRT for part of the field. Healthcare reports to Z-CERT, municipalities to the IBD of VNG Realisatie. Find out today which CSIRT is yours, and put the contact details in the incident plan rather than in someone's inbox.

Sectoral supervision

Supervision is also sectoral. Healthcare falls to the Inspectie Gezondheidszorg en Jeugd, education and research to the Inspectie van het Onderwijs, and other sectors to their own regulators. The NCTV publishes a decision tree that maps sectors to their supervisor and CSIRT. That mapping is worth printing once and attaching to the incident plan.

What a Wwke designation starts

A designation is not a status you carry quietly. It starts two clocks.

  • Nine months to complete your own broad risk assessment, covering everything that could disrupt your service: sabotage, terrorism, natural hazards, accidents.
  • Ten months to meet all duties: appropriate physical measures, direct suppliers mapped, access control, protection against natural and climate hazards, a crisis and continuity plan, incident reporting, information sharing with the authorities, and a permanent contact point reachable around the clock.

Ten months sounds generous until you count what sits inside it: a supplier mapping exercise, physical measures with a procurement cycle, and a contact point that has to be staffed rather than named.

What to have ready before 15 August

Five things are worth finishing in the weeks before the date, because each of them gets more expensive afterwards.

  • A scope conclusion in writing, per legal entity, with the reasoning. A defensible "we are out of scope" is as valuable as a registration, and it is only defensible on paper.
  • Your registration data assembled, including IP ranges and a named contact, so registration is a submission rather than a project.
  • The right CSIRT and supervisor written into the incident plan, with out-of-hours contact details that someone has actually tested.
  • A dated board approval of the risk-management measures, plus the training record. Under the Cbw, as under the directive, this is where an inspection starts.
  • A gap list with owners against the ten measures. Not a maturity score, a list of names and dates.

One practical note on timing: registration being open before the date is a gift. The organisations that register in the first weeks after 15 August will be doing it in a queue, with a supervisor already able to ask why the data is incomplete.

What does not change

Two things are worth saying plainly, because a national law has a way of resetting conversations that were already settled.

First, the substance of the security measures does not change. If you built a programme against Article 21 over the last two years, the Cbw does not invalidate it. It gives it a Dutch supervisor and a reporting address.

Second, the responsibility of the management body does not move. Approval, oversight and training remain personal duties of the people at the top of the organisation, and the evidence for them is still minutes, attendance records and dated decisions.

Frequently asked questions

When do the Cyberbeveiligingswet and the Wwke take effect?

The Eerste Kamer adopted both laws on 7 July 2026 and they enter into force on 15 August 2026. From that date the obligations apply to entities in scope, without a separate implementation period.

Do I have to register, and where?

Entities in scope of the Cbw register with the NCSC. Registration is already open through mijn.ncsc.nl, so you can complete it before the law takes effect rather than in the queue afterwards.

How do I know whether the Cbw applies to us?

Scope follows sector and size, the same test as the directive. The government publishes a self-assessment, the NIS2 Zelfevaluatie, that walks through it. A negative outcome is worth documenting as carefully as a positive one.

Who supervises us, and where do we report incidents?

Supervision is sectoral rather than central. Healthcare falls to the IGJ, education and research to the Inspectie van het Onderwijs, and other sectors to their own regulators. Incident reporting runs to the sectoral CSIRT, with the NCSC acting as national CSIRT and as sectoral CSIRT for part of the field. Z-CERT serves healthcare, the IBD serves municipalities.

What is the difference between the Cbw and the Wwke?

The Cbw is the Dutch transposition of NIS2 and covers digital security. The Wwke covers physical resilience of critical entities. You determine Cbw scope yourself; under the Wwke the responsible minister designates entities per sector, confidentially, so you cannot self-assess into it.

What happens after a Wwke designation?

A designated entity has nine months to complete its own broad risk assessment and ten months to meet all Wwke duties, including physical protection, a crisis and continuity plan, incident reporting and a permanent contact point reachable around the clock. Designation also makes you an essential entity under the Cbw.