
Library
Last updated: 27 July 2026
On 15 August 2026, the Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw) will enter into force. It implements the European NIS2 Directive in the Netherlands and replaces the Network and Information Systems Security Act (Wbni). Together with the Critical Entities Resilience Act (Wwke), it establishes a new foundation for the digital and physical resilience of the Netherlands.
The Act affects more than 8,000 organisations across eighteen sectors, including energy, drinking water, digital infrastructure, healthcare, government and transport. Organisations are responsible for determining whether they qualify as an essential or important entity. They will not necessarily receive an individual notification.
The Act introduces three central obligations:
The Act also establishes explicit board-level accountability. Management bodies must approve cybersecurity measures, oversee their implementation and possess sufficient knowledge to assess cyber risks and controls.
The Cbw has a considerably wider scope than the Wbni. Many medium-sized and large organisations in sectors that were not previously directly regulated may now fall within scope. The requirements also extend into the supply chain: regulated organisations must manage supplier risks and may consequently impose additional security requirements on suppliers.
Assessing applicability therefore requires more than identifying the organisation’s sector. Its size, services, place of establishment and position within critical supply chains are also relevant.
In preparation for the Act, ministries are publishing sector-specific regulations and supervisory decisions. The following formal documents were available on 27 July 2026.
This overview will be updated as additional regulations are published.
With the Act taking effect on 15 August 2026, very little preparation time remains. Organisations should at least complete and document the following steps:
The Cbw requires more than policies and formal documentation. Organisations must demonstrate effective control of cyber risks. Measures should therefore reflect actual threats, dependencies and critical processes. Independent assessment, technical validation and exercises help establish whether controls remain effective under realistic conditions.
Do you need to establish whether your organisation falls within scope, or assess your technical and organisational measures? Contact DeepBlue Security & Intelligence at info@deepbluesecurity.nl or +31 (0) 70 290 6 290.
Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.
Urgent assistance required?
Call +31 (0) 70 290 6 290
or email info@deepbluesecurity.nl