Cbw, the Dutch NIS2 law

Cyberbeveiligingswet: the Dutch NIS2 law and what it requires

The Cyberbeveiligingswet is the Dutch law that transposes NIS2, adopted on 7 July 2026 and in force from 15 August 2026, and it requires registration with the NCSC, the ten Article 21 measures, and incident reporting to a sectoral CSIRT. That is the short version. Below is what each of those three means in practice, who supervises them, and where the Dutch implementation differs from the picture most boards have of NIS2.

Key takeaway: the Cbw does not change what NIS2 asks for. It adds a Dutch supervisor and a Dutch reporting address. Two things in it surprise people: supervision is sectoral rather than central, and incident reports go to the CSIRT for your sector instead of to one national desk. So the first thing worth finding out is which supervisor and which CSIRT are yours, and putting both in the incident plan.

What is the Cyberbeveiligingswet?

The Cyberbeveiligingswet, shortened to Cbw, transposes Directive (EU) 2022/2555 into Dutch law. The directive itself addresses member states; the Cbw is the law a Dutch supervisor holds you to. The Dutch Senate adopted it on 7 July 2026, together with the Wet weerbaarheid kritieke entiteiten, and both enter into force on 15 August 2026, with no separate transition period.

The substance will look familiar if you have read the directive, because it is the directive: risk management measures, incident reporting, registration, supervision, and duties for the management body. If you have spent the past years building a programme against Article 21, the Cbw takes nothing away from it.

Who does the Cyberbeveiligingswet apply to?

Whether the law applies to you follows from your sector and your size, and you run that test yourself. Hold the organisation against the 18 sectors in Annexes I and II, then test the thresholds: medium starts at 50 staff or 10 million euro annual turnover, large at 250 staff or 50 million euro. A separate category is covered regardless of headcount or turnover: DNS providers, top level domain registries, cloud providers, data centres and CDN providers.

If you land in scope, the second question follows: essential or important. That classification sets both your supervision regime and your fine ceiling. Essential entities fall under proactive supervision and face up to 10 million euro or 2 percent of worldwide turnover. Important entities fall under reactive supervision and face up to 7 million euro or 1.4 percent. The measures themselves are the same for both.

The Dutch government publishes a self assessment for this test, the NIS2 Zelfevaluatie. Record the outcome in writing, per legal entity, with the reasoning behind it. A reasoned "not in scope" is worth as much as a registration, and it is only defensible on paper.

What does the Cbw require you to have in place?

Three obligations become concrete on 15 August 2026, and they hang together.

Registering with the NCSC

Entities in scope register with the NCSC, through mijn.ncsc.nl. Treat it as a data job rather than a form: name and legal form, addresses and contact details, sector and subsector, the member states where you provide services, and your IP ranges. Keeping that set current is an obligation in itself, not a one off action.

The ten Article 21 measures

They apply in proportion to your size and your risk: risk analysis and policy, incident handling, business continuity including backup and crisis management, supply chain security, secure acquisition and development, testing effectiveness, basic cyber hygiene and training, cryptography, access control and asset management, and multi factor authentication with secured communications.

A measure you take but cannot evidence counts, under supervision, as a measure that is not there. So give each one an artefact with a date, an owner and a review record.

Reporting to the right CSIRT

This is where the Dutch implementation departs from the picture most boards have. Reporting does not go to one central desk. Significant incidents go to the CSIRT for your sector, with the NCSC acting as the national CSIRT and, for part of the field, as the sectoral one too. Healthcare reports to Z-CERT, municipalities to the IBD of VNG Realisatie. The deadlines come from Article 23: an early warning within 24 hours, a formal notification within 72 hours, and a final report within one month.

Before working out which duties land on you, it helps to know whether you are an essential entity, an important one, or neither. Four questions in the scope check give you that verdict, without leaving an email address.

Who supervises the Cyberbeveiligingswet?

Supervision is arranged per sector as well. Healthcare falls under the Inspectie Gezondheidszorg en Jeugd, education and research under the Inspectie van het Onderwijs, and other sectors under their own supervisor. The NCTV publishes a referral tree that links sectors to their supervisor and their CSIRT.

The practical consequence: in the Netherlands the question "who calls us" has a different answer per sector. That is worth looking up once and attaching to the incident plan, including out of hours reachability that someone has actually tested.

What does the Cbw mean for the board?

Nothing shifts relative to the directive. Article 20 asks the management body to approve the risk management measures, oversee their implementation, follow cybersecurity training, and accept liability for breaches of Article 21. Those remain personal duties of the people at the top of the organisation.

The evidence for it is as ordinary as it sounds: minutes, attendance records and dated decisions. A policy signed off only by the IT director is a governance finding.

How does the Cbw relate to the Wwke?

The Wet weerbaarheid kritieke entiteiten passed the Senate on the same day and enters into force on the same date, but it asks a different question. The Cbw is about digital security. The Wwke implements CER Directive (EU) 2022/2557 and is about staying standing physically: sabotage, terrorism, natural hazards, accidents.

The difference that matters most is who decides whether you take part. Under the Cbw you test your own scope. Under the Wwke the responsible minister designates critical entities per sector, based on a sectoral risk assessment, and communicates that confidentially. And that is where the two connect: an entity designated under the Wwke automatically counts as an essential entity under the Cbw, the heavier of the two supervision regimes. There is more on that on the page about critical entities resilience.

Where do you start?

Five things return the most, in this order, even if you are starting late.

  • A written scope conclusion, per legal entity, with the reasoning behind it.
  • Your registration data collected, including IP ranges and a named contact, so that registering is an action rather than a project.
  • The right CSIRT and the right supervisor in your incident plan, with out of hours reachability someone has actually tested.
  • A dated board approval of the risk management measures, plus the training record.
  • A gap list against the ten measures. Not a maturity score, but a list with names and dates.

Frequently asked questions

What is the Cyberbeveiligingswet?

The Dutch law that transposes Directive (EU) 2022/2555, better known as NIS2, into national law. It covers risk management measures, incident reporting, registration, supervision and the duties of the management body. It is commonly shortened to Cbw.

When does the Cyberbeveiligingswet enter into force?

On 15 August 2026. The Dutch Senate adopted the law on 7 July 2026, together with the Wet weerbaarheid kritieke entiteiten. There is no separate transition period on top of that date: the obligations apply to entities in scope from then on.

Who does the Cyberbeveiligingswet apply to?

That follows from your sector and your size, and you run that test yourself. As a rule it covers medium and large organisations in the sectors listed: 50 staff or 10 million euro turnover for medium, 250 staff or 50 million euro for large. DNS providers, top level domain registries, cloud providers, data centres and CDN providers are covered regardless of size.

Where do you register under the Cyberbeveiligingswet?

With the NCSC, through mijn.ncsc.nl. Registration asks for name and legal form, addresses and contact details, sector and subsector, the member states where you provide services, and your IP ranges. Keeping that data current is an obligation in itself, not a one off action.

Who supervises the law, and where do you report an incident?

Both are arranged per sector rather than centrally. Healthcare falls under the Inspectie Gezondheidszorg en Jeugd, education and research under the Inspectie van het Onderwijs, other sectors under their own supervisor. Significant incidents go to the CSIRT for your sector: Z-CERT for healthcare, the IBD of VNG Realisatie for municipalities, with the NCSC acting as national CSIRT and as sectoral CSIRT for part of the field.

How does the Cyberbeveiligingswet differ from the Wwke?

The Cyberbeveiligingswet transposes NIS2 and covers digital security. The Wet weerbaarheid kritieke entiteiten implements the CER Directive and covers physical resilience. You test your own scope under the Cbw; under the Wwke the responsible minister designates entities per sector. An entity that is designated automatically counts as an essential entity under the Cbw.

Burak Yazici, PECB Certified NIS2 Lead Implementer

Written by Burak Yazici

PECB Certified NIS2 Lead Implementer