NIS2 in the Netherlands: the Cyberbeveiligingswet, explained in English
Most English-language pages about Dutch NIS2 were written before the law existed. This one was written after it took effect, and cites the Dutch primary sources.

The Cyberbeveiligingswet ("Cbw") is the Dutch transposition of the EU NIS2 Directive. It entered into force on 15 August 2026, replacing the 2018 Wbni, and imposes registration, security and incident-reporting duties on roughly 8,000 organizations across eighteen sectors, with no general transition period.
This guide is for foreign parent companies, group CISOs and English-speaking compliance teams with a Dutch entity. The Dutch-language source of truth, which we keep current, is Cyberbeveiligingswet per 15 augustus 2026. Last updated: 16 August 2026.
This is practical guidance, not legal advice.
What is the Cyberbeveiligingswet?
It is the Dutch NIS2 implementing law, in force since 15 August 2026, and it is not a single document.
Four instruments took effect on the same day, with a further layer of ministerial regulations underneath them. Anyone reading only the Act itself is missing most of the operative detail.
| Instrument | Type | Published | In force |
|---|---|---|---|
| Cyberbeveiligingswet (Cbw) | Act (NIS2 transposition) | Stb. 2026, 187 | 15 Aug 2026 |
| Wet weerbaarheid kritieke entiteiten (Wwke) | Act (CER transposition) | Stb. 2026, 188 | 15 Aug 2026 |
| Cyberbeveiligingsbesluit (Cbb) | Decree (implements the Cbw) | Stb. 2026, 189 | 15 Aug 2026 |
| Besluit weerbaarheid kritieke entiteiten | Decree (implements the Wwke) | Stb. 2026, 190 | 15 Aug 2026 |
Each ministry has also issued a sector regulation setting, among other things, the thresholds at which an incident becomes reportable. The consolidated statutory text is at wetten.overheid.nl.
Who is in scope?
Organizations in one of the listed sectors with 50 or more employees, or with annual turnover or balance sheet total above €10 million, plus several entity types that are in scope regardless of size.
One note if you check the sources: the NCSC page words the financial test more strictly, as both turnover and balance sheet (NCSC). The SME definition the law relies on uses "or". If you sit close to the threshold, have it checked.
Sectors are set out in two annexes: Annex 1 covers high-criticality sectors (energy, banking, financial market infrastructure, transport, drinking water, wastewater, health, digital infrastructure, ICT service management, space, government); Annex 2 covers other critical sectors (waste management, postal and courier services, chemicals, food, manufacturing, digital providers, research, and (once its regulation exists) higher education) (NCSC brochure, PDF).
In scope regardless of size: providers of public electronic communications networks and services, (qualified) trust service providers, top-level domain name registries, DNS service providers, domain name registration service providers, and all government organizations.
Two further routes matter for group structures:
- Article 9 Cbw allows designation irrespective of size where the entity is the sole provider of a service essential to critical activities, where disruption would significantly affect public safety, security or health, or where there is significant systemic risk.
- Article 8 Cbw makes any entity designated critical under the Wwke an essential entity under the Cbw by operation of law.
Note that providers of domain name registration services sit in a third category, neither essential nor important, with a lighter regime of their own (art. 43).
What do we have to register, and where?
Registration runs through Mijn.NCSC.nl using eHerkenning at assurance level 3, it has applied since 15 August 2026, and changes must be reported within two weeks.
Foreign parents should note that eHerkenning is a Dutch national authentication scheme; obtaining it for a Dutch entity takes time and is a common cause of delay. Government bodies use SSOnRijk instead (RDI).
Changes to registered information must be reported "without delay and in any event within two weeks" (art. 44(2) Cbw).
No deadline for initial registration has been published. We could not find one on the NCSC, RDI or NCTV websites; the obligation simply applies from 15 August 2026. Treat any page quoting a specific Dutch registration deadline with suspicion. The practical position is unchanged: there is no transition period, so there is nothing to wait for.
What are the security obligations?
Appropriate and proportionate technical, operational and organizational measures on an all-hazards basis, set out in ten categories in article 21(2).
The ten categories transpose Article 21(2) of the Directive: risk analysis and information system security policies; incident handling; business continuity, backup management and crisis management; supply chain security; security in acquisition, development and maintenance including vulnerability handling; policies to assess the effectiveness of measures; cyber hygiene and training; cryptography and encryption; human resources security, access control and asset management; and multi-factor authentication and secured communications.
"All hazards" is meant literally: physical risk to server rooms is in scope, as is your supply chain. The full ten-row breakdown, with the evidence each category typically produces, is in the Dutch hub.
What is the reporting timeline?
24 hours, 72 hours, one month: one submission, reaching both the sectoral CSIRT and the supervisor.
| Stage | Deadline | To whom | Contents |
|---|---|---|---|
| Early warning | 24 hours from becoming aware of a significant incident | Sectoral CSIRT + supervisor, via Mijn.NCSC.nl | Suspected nature, whether unlawful action is suspected, possible cross-border impact |
| Incident notification | 72 hours from awareness | Same | Updated assessment, severity and impact, indicators of compromise |
| Interim report | On request of the CSIRT or supervisor | Same | Current status |
| Final report | Within one month of the incident notification | Same | Description, severity and consequences, root cause, mitigation applied |
Two details worth carrying into a group incident-response plan: trust service providers file the incident notification within 24 hours rather than 72; and the receiving CSIRT is the sectoral CSIRT, which is NCSC for most but not all sectors. The clock starts on awareness, not on the incident.
Who supervises us?
Seven authorities, split by sector. And how closely they watch depends on whether you are an essential or an important entity.
RDI covers digital infrastructure, energy, ICT service management (including managed service providers), government, space, postal and courier services, non-medical manufacturing, digital providers and research. ILT covers transport, drinking water, wastewater, water management, waste management, chemicals and meteorology. DNB supervises banking and AFM supervises financial market infrastructure. NVWA covers food, ANVS nuclear, and IGJ health and medical device manufacturing (NCSC).
Essential entities get proactive supervision; important entities are supervised largely after the fact, typically following an incident (RDI). The full sector-by-sector table is in Which supervisor regulates your organization?.
What are the penalties, and what must the board do?
Up to €10 million or 2% of worldwide annual turnover for essential entities, €7 million or 1.4% for important entities. And the board must approve the measures itself and complete training.
On the amounts: they are widely reported and consistent with the Directive, but we were unable to retrieve the verbatim text of the penalty articles: the later chapters of the Dutch Official Gazette resist automated access. The chapter structure is confirmed from the official table of contents: enforcement against essential entities sits in §15.2 (art. 70–80), against important entities in §15.3 (art. 81–87). The figures are attributed to Houthoff, a law firm, and should be verified against Stb. 2026, 187 before being relied on in a board paper.
The Directive also allows supervisors to temporarily ban an individual from managerial functions (art. 32(5)(b)). We could not establish whether the Cbw transposed that power, and prefer to say so rather than assume.
What is unambiguous is article 24(1): "De maatregelen, bedoeld in artikel 21, behoeven de goedkeuring van het bestuur" (the article 21 measures require the approval of the management body). Not noting, not delegating: approving. Board members must also complete training within two years of entry into force, so by roughly 15 August 2028, and new appointees within two years of appointment (Digitale Overheid). Enforcement of these duties has its own paragraph, §15.5.
Note that Dutch sources distinguish verantwoordelijkheid (responsibility) from aansprakelijkheid (liability), and that the NIS2 liability provisions do not apply to public sector organizations.
How does the Dutch transposition differ from Germany and Belgium?
The Netherlands is late but comprehensive, Germany centralised its supervision, and Belgium is the outlier: it made certification compulsory.
If you run a group across these three countries, the differences below are the ones that change your operating model, not just your paperwork.
| Netherlands | Germany | Belgium | |
|---|---|---|---|
| Law | Cyberbeveiligingswet + Cyberbeveiligingsbesluit | NIS2UmsuCG → BSIG 2025 | Law of 26 April 2024 + Royal Decree of 9 June 2024 |
| In force | 15 Aug 2026 | 6 Dec 2025 | 18 Oct 2024 |
| Registration | Mijn.NCSC.nl, eHerkenning level 3 | BSI-Portal (+ Mein Unternehmenskonto), live 6 Jan 2026 | Safeonweb@Work (CCB) |
| Registration deadline | None published (obligation applies from day one) | 3 months from coming into scope; legacy deadline 6 Mar 2026 | 5 months → 18 Mar 2025 (digital sector: 2 months → 18 Dec 2024) |
| Supervisor model | Seven authorities, split by sector | Single lead authority (BSI) with sectoral carve-outs | Single authority (CCB); CERT.be as CSIRT |
| Fines (essential) | €10m / 2% | €10m / 2% | €500–€10m / 2%, doubled for a repeat within 3 years |
| Fines (important) | €7m / 1.4% | €7m / 1.4% | €500–€7m / 1.4%, doubled on repeat |
| Board duty | Approve measures (art. 24(1)); training by ~15 Aug 2028 | Implement, monitor, train "regelmäßig"; statutory personal liability to the entity (§ 38 BSIG). No deadline | Approve, oversee, train; managerial ban possible |
| Certification | Not required | Not required | Required for essential entities: CyFun® or ISO/IEC 27001, or CCB inspection |
Three things stand out for a group compliance function.
The Netherlands split supervision where its neighbours consolidated it. Germany routes almost everything through the BSI; Belgium through the CCB. A Dutch group operating across, say, manufacturing and healthcare answers to two different Dutch regulators with different postures, while its German sister company answers to one. Budget for that.
Belgium made conformity assessment mandatory, and the Netherlands did not. Under the Royal Decree of 9 June 2024, Belgian essential entities must obtain certification against CyberFundamentals (CyFun®) or ISO/IEC 27001, or submit to CCB inspection, with an 18 April 2026 milestone and full certification due by April 2027. The CCB calls it "a binding regulatory obligation, not a procedural formality." The Directive left this optional (art. 24); Belgium took it, the Netherlands and Germany did not. If your group standardized on the Belgian approach, do not assume it discharges the Dutch duty of care, and if you standardized on the Dutch one, your Belgian entity has a deadline you may have missed.
Germany writes personal liability into statute; the Netherlands is quieter about it. § 38(2) BSIG states that management bodies breaching their duties "haften ihrer Einrichtung für einen schuldhaft verursachten Schaden" (they are liable to their own entity for culpably caused damage). The Dutch Act imposes an approval duty and a training duty; how far personal liability extends is less clearly published, and we have not asserted more than the sources support.
One caution on Germany: the European Commission's own country page still describes Germany as having failed to notify full transposition. That page is out of date: the BSI announced entry into force on 6 December 2025. Do not cite the Commission tracker as current status for Germany.
Where Soveryne fits
Groups operating across NL, DE and BE end up maintaining three near-identical control sets with different evidence expectations attached. Soveryne Command maps controls to assets and to framework requirements once, so the same control can evidence NIS2, ISO 27001 and DORA obligations rather than being re-documented per jurisdiction. Counsel, our compliance assistant, answers questions against these frameworks with citations to the source, running on a platform we operate ourselves inside the EU.
Frequently asked questions
Does our foreign parent company need to register in the Netherlands? The obligation attaches to the entity established in the Netherlands, not to the group. A parent without Dutch establishment does not register in the Netherlands, but the Dutch entity does, and it needs eHerkenning to do so, which takes lead time.
We already comply with NIS2 in Germany. Is that enough for the Netherlands? The security obligations derive from the same Directive article, so the substance largely carries over. The procedure does not: registration, the reporting portal, the supervisor and the board training deadline are all Dutch-specific.
Which supervisor applies to a group active in several sectors? Supervision follows the sector of the activity, so a group active in two sectors can face two supervisors with different postures. See the supervisor guide.
Is there a transition period? No general one. The obligations applied from 15 August 2026. The board training duty runs to roughly August 2028, and higher education is not yet in scope.
Does ISO 27001 satisfy the Dutch duty of care? It is strong evidence for much of it, but not a substitute for registration, the reporting process or board approval. And unlike Belgium, the Netherlands does not accept certification as a route to presumed conformity. Our full analysis is in Dutch: Telt ISO 27001 als bewijs?
Sources
Primary: Netherlands
- Cyberbeveiligingswet, Stb. 2026, 187 · consolidated text
- Rijksoverheid: entry into force
- NCSC: scope · brochure (PDF) · supervision
- RDI: registration · supervision
- NCTV: reporting
- Digitale Overheid: obligations
Primary: Germany and Belgium
- BSI: NIS2UmsuCG in force · BSI portal · BGBl. I 2025 Nr. 301
- CCB: NIS2 · Safeonweb@Work · 18 April 2026 deadline · CyberFundamentals
- NIS2 Directive (EU) 2022/2555
Secondary (used as such)
- Houthoff: Dutch fine ceilings
- German fine ceilings and § 38 BSIG text via lxgesetze, corroborated by Greenberg Traurig
- Belgian fine ceilings via PwC Legal and Freshfields



