All articles
ComplianceCybersecurityGovernance

NIS2 in the Netherlands: the Cyberbeveiligingswet, explained in English

Most English-language pages about Dutch NIS2 were written before the law existed. This one was written after it took effect, and cites the Dutch primary sources.

Ilke Tosunoğlu
Ilke Tosunoğlu13 min readUpdated
The Dutch NIS2 transposition set beside the Directive, with the points of divergence highlighted.

The Cyberbeveiligingswet ("Cbw") is the Dutch transposition of the EU NIS2 Directive. It entered into force on 15 August 2026, replacing the 2018 Wbni, and imposes registration, security and incident-reporting duties on roughly 8,000 organizations across eighteen sectors, with no general transition period.

This guide is for foreign parent companies, group CISOs and English-speaking compliance teams with a Dutch entity. The Dutch-language source of truth, which we keep current, is Cyberbeveiligingswet per 15 augustus 2026. Last updated: 16 August 2026.

This is practical guidance, not legal advice.

What is the Cyberbeveiligingswet?

It is the Dutch NIS2 implementing law, in force since 15 August 2026, and it is not a single document.

Four instruments took effect on the same day, with a further layer of ministerial regulations underneath them. Anyone reading only the Act itself is missing most of the operative detail.

Instrument Type Published In force
Cyberbeveiligingswet (Cbw) Act (NIS2 transposition) Stb. 2026, 187 15 Aug 2026
Wet weerbaarheid kritieke entiteiten (Wwke) Act (CER transposition) Stb. 2026, 188 15 Aug 2026
Cyberbeveiligingsbesluit (Cbb) Decree (implements the Cbw) Stb. 2026, 189 15 Aug 2026
Besluit weerbaarheid kritieke entiteiten Decree (implements the Wwke) Stb. 2026, 190 15 Aug 2026

Each ministry has also issued a sector regulation setting, among other things, the thresholds at which an incident becomes reportable. The consolidated statutory text is at wetten.overheid.nl.

Who is in scope?

Organizations in one of the listed sectors with 50 or more employees, or with annual turnover or balance sheet total above €10 million, plus several entity types that are in scope regardless of size.

One note if you check the sources: the NCSC page words the financial test more strictly, as both turnover and balance sheet (NCSC). The SME definition the law relies on uses "or". If you sit close to the threshold, have it checked.

Sectors are set out in two annexes: Annex 1 covers high-criticality sectors (energy, banking, financial market infrastructure, transport, drinking water, wastewater, health, digital infrastructure, ICT service management, space, government); Annex 2 covers other critical sectors (waste management, postal and courier services, chemicals, food, manufacturing, digital providers, research, and (once its regulation exists) higher education) (NCSC brochure, PDF).

In scope regardless of size: providers of public electronic communications networks and services, (qualified) trust service providers, top-level domain name registries, DNS service providers, domain name registration service providers, and all government organizations.

Two further routes matter for group structures:

  • Article 9 Cbw allows designation irrespective of size where the entity is the sole provider of a service essential to critical activities, where disruption would significantly affect public safety, security or health, or where there is significant systemic risk.
  • Article 8 Cbw makes any entity designated critical under the Wwke an essential entity under the Cbw by operation of law.

Note that providers of domain name registration services sit in a third category, neither essential nor important, with a lighter regime of their own (art. 43).

What do we have to register, and where?

Registration runs through Mijn.NCSC.nl using eHerkenning at assurance level 3, it has applied since 15 August 2026, and changes must be reported within two weeks.

Foreign parents should note that eHerkenning is a Dutch national authentication scheme; obtaining it for a Dutch entity takes time and is a common cause of delay. Government bodies use SSOnRijk instead (RDI).

Changes to registered information must be reported "without delay and in any event within two weeks" (art. 44(2) Cbw).

No deadline for initial registration has been published. We could not find one on the NCSC, RDI or NCTV websites; the obligation simply applies from 15 August 2026. Treat any page quoting a specific Dutch registration deadline with suspicion. The practical position is unchanged: there is no transition period, so there is nothing to wait for.

What are the security obligations?

Appropriate and proportionate technical, operational and organizational measures on an all-hazards basis, set out in ten categories in article 21(2).

The ten categories transpose Article 21(2) of the Directive: risk analysis and information system security policies; incident handling; business continuity, backup management and crisis management; supply chain security; security in acquisition, development and maintenance including vulnerability handling; policies to assess the effectiveness of measures; cyber hygiene and training; cryptography and encryption; human resources security, access control and asset management; and multi-factor authentication and secured communications.

"All hazards" is meant literally: physical risk to server rooms is in scope, as is your supply chain. The full ten-row breakdown, with the evidence each category typically produces, is in the Dutch hub.

What is the reporting timeline?

24 hours, 72 hours, one month: one submission, reaching both the sectoral CSIRT and the supervisor.

Stage Deadline To whom Contents
Early warning 24 hours from becoming aware of a significant incident Sectoral CSIRT + supervisor, via Mijn.NCSC.nl Suspected nature, whether unlawful action is suspected, possible cross-border impact
Incident notification 72 hours from awareness Same Updated assessment, severity and impact, indicators of compromise
Interim report On request of the CSIRT or supervisor Same Current status
Final report Within one month of the incident notification Same Description, severity and consequences, root cause, mitigation applied

Sources: NCTV, NCSC.

Two details worth carrying into a group incident-response plan: trust service providers file the incident notification within 24 hours rather than 72; and the receiving CSIRT is the sectoral CSIRT, which is NCSC for most but not all sectors. The clock starts on awareness, not on the incident.

Who supervises us?

Seven authorities, split by sector. And how closely they watch depends on whether you are an essential or an important entity.

RDI covers digital infrastructure, energy, ICT service management (including managed service providers), government, space, postal and courier services, non-medical manufacturing, digital providers and research. ILT covers transport, drinking water, wastewater, water management, waste management, chemicals and meteorology. DNB supervises banking and AFM supervises financial market infrastructure. NVWA covers food, ANVS nuclear, and IGJ health and medical device manufacturing (NCSC).

Essential entities get proactive supervision; important entities are supervised largely after the fact, typically following an incident (RDI). The full sector-by-sector table is in Which supervisor regulates your organization?.

What are the penalties, and what must the board do?

Up to €10 million or 2% of worldwide annual turnover for essential entities, €7 million or 1.4% for important entities. And the board must approve the measures itself and complete training.

On the amounts: they are widely reported and consistent with the Directive, but we were unable to retrieve the verbatim text of the penalty articles: the later chapters of the Dutch Official Gazette resist automated access. The chapter structure is confirmed from the official table of contents: enforcement against essential entities sits in §15.2 (art. 70–80), against important entities in §15.3 (art. 81–87). The figures are attributed to Houthoff, a law firm, and should be verified against Stb. 2026, 187 before being relied on in a board paper.

The Directive also allows supervisors to temporarily ban an individual from managerial functions (art. 32(5)(b)). We could not establish whether the Cbw transposed that power, and prefer to say so rather than assume.

What is unambiguous is article 24(1): "De maatregelen, bedoeld in artikel 21, behoeven de goedkeuring van het bestuur" (the article 21 measures require the approval of the management body). Not noting, not delegating: approving. Board members must also complete training within two years of entry into force, so by roughly 15 August 2028, and new appointees within two years of appointment (Digitale Overheid). Enforcement of these duties has its own paragraph, §15.5.

Note that Dutch sources distinguish verantwoordelijkheid (responsibility) from aansprakelijkheid (liability), and that the NIS2 liability provisions do not apply to public sector organizations.

How does the Dutch transposition differ from Germany and Belgium?

The Netherlands is late but comprehensive, Germany centralised its supervision, and Belgium is the outlier: it made certification compulsory.

If you run a group across these three countries, the differences below are the ones that change your operating model, not just your paperwork.

Netherlands Germany Belgium
Law Cyberbeveiligingswet + Cyberbeveiligingsbesluit NIS2UmsuCG → BSIG 2025 Law of 26 April 2024 + Royal Decree of 9 June 2024
In force 15 Aug 2026 6 Dec 2025 18 Oct 2024
Registration Mijn.NCSC.nl, eHerkenning level 3 BSI-Portal (+ Mein Unternehmenskonto), live 6 Jan 2026 Safeonweb@Work (CCB)
Registration deadline None published (obligation applies from day one) 3 months from coming into scope; legacy deadline 6 Mar 2026 5 months → 18 Mar 2025 (digital sector: 2 months → 18 Dec 2024)
Supervisor model Seven authorities, split by sector Single lead authority (BSI) with sectoral carve-outs Single authority (CCB); CERT.be as CSIRT
Fines (essential) €10m / 2% €10m / 2% €500–€10m / 2%, doubled for a repeat within 3 years
Fines (important) €7m / 1.4% €7m / 1.4% €500–€7m / 1.4%, doubled on repeat
Board duty Approve measures (art. 24(1)); training by ~15 Aug 2028 Implement, monitor, train "regelmäßig"; statutory personal liability to the entity (§ 38 BSIG). No deadline Approve, oversee, train; managerial ban possible
Certification Not required Not required Required for essential entities: CyFun® or ISO/IEC 27001, or CCB inspection

Three things stand out for a group compliance function.

The Netherlands split supervision where its neighbours consolidated it. Germany routes almost everything through the BSI; Belgium through the CCB. A Dutch group operating across, say, manufacturing and healthcare answers to two different Dutch regulators with different postures, while its German sister company answers to one. Budget for that.

Belgium made conformity assessment mandatory, and the Netherlands did not. Under the Royal Decree of 9 June 2024, Belgian essential entities must obtain certification against CyberFundamentals (CyFun®) or ISO/IEC 27001, or submit to CCB inspection, with an 18 April 2026 milestone and full certification due by April 2027. The CCB calls it "a binding regulatory obligation, not a procedural formality." The Directive left this optional (art. 24); Belgium took it, the Netherlands and Germany did not. If your group standardized on the Belgian approach, do not assume it discharges the Dutch duty of care, and if you standardized on the Dutch one, your Belgian entity has a deadline you may have missed.

Germany writes personal liability into statute; the Netherlands is quieter about it. § 38(2) BSIG states that management bodies breaching their duties "haften ihrer Einrichtung für einen schuldhaft verursachten Schaden" (they are liable to their own entity for culpably caused damage). The Dutch Act imposes an approval duty and a training duty; how far personal liability extends is less clearly published, and we have not asserted more than the sources support.

One caution on Germany: the European Commission's own country page still describes Germany as having failed to notify full transposition. That page is out of date: the BSI announced entry into force on 6 December 2025. Do not cite the Commission tracker as current status for Germany.

Where Soveryne fits

Groups operating across NL, DE and BE end up maintaining three near-identical control sets with different evidence expectations attached. Soveryne Command maps controls to assets and to framework requirements once, so the same control can evidence NIS2, ISO 27001 and DORA obligations rather than being re-documented per jurisdiction. Counsel, our compliance assistant, answers questions against these frameworks with citations to the source, running on a platform we operate ourselves inside the EU.

Frequently asked questions

Does our foreign parent company need to register in the Netherlands? The obligation attaches to the entity established in the Netherlands, not to the group. A parent without Dutch establishment does not register in the Netherlands, but the Dutch entity does, and it needs eHerkenning to do so, which takes lead time.

We already comply with NIS2 in Germany. Is that enough for the Netherlands? The security obligations derive from the same Directive article, so the substance largely carries over. The procedure does not: registration, the reporting portal, the supervisor and the board training deadline are all Dutch-specific.

Which supervisor applies to a group active in several sectors? Supervision follows the sector of the activity, so a group active in two sectors can face two supervisors with different postures. See the supervisor guide.

Is there a transition period? No general one. The obligations applied from 15 August 2026. The board training duty runs to roughly August 2028, and higher education is not yet in scope.

Does ISO 27001 satisfy the Dutch duty of care? It is strong evidence for much of it, but not a substitute for registration, the reporting process or board approval. And unlike Belgium, the Netherlands does not accept certification as a route to presumed conformity. Our full analysis is in Dutch: Telt ISO 27001 als bewijs?

Sources

Primary: Netherlands

Primary: Germany and Belgium

Secondary (used as such)

Further reading