Contact
Dutch Cybersecurity Act: 15 August 2026

Library

Dutch Cybersecurity Act: 15 August 2026

Share via

Dutch Cybersecurity Act: 15 August 2026

Last updated: 27 July 2026

On 15 August 2026, the Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw) will enter into force. It implements the European NIS2 Directive in the Netherlands and replaces the Network and Information Systems Security Act (Wbni). Together with the Critical Entities Resilience Act (Wwke), it establishes a new foundation for the digital and physical resilience of the Netherlands.

The Act affects more than 8,000 organisations across eighteen sectors, including energy, drinking water, digital infrastructure, healthcare, government and transport. Organisations are responsible for determining whether they qualify as an essential or important entity. They will not necessarily receive an individual notification.

What does the Cybersecurity Act require?

The Act introduces three central obligations:

  • Registration. Organisations within scope must register in the national entity register maintained by the National Cyber Security Centre (NCSC). Registration through MijnNCSC is already available and becomes a legal obligation on 15 August 2026.
  • Incident notification. Significant cyber incidents must be reported as soon as possible, and within 24 hours at the latest, to the responsible CSIRT and competent authority. Follow-up notifications and a final report must then be submitted within the statutory time limits.
  • Duty of care. Based on a risk assessment, organisations must implement appropriate and proportionate technical, operational and organisational measures. These include incident handling, business continuity, supply-chain security, access control, logging and detection.

The Act also establishes explicit board-level accountability. Management bodies must approve cybersecurity measures, oversee their implementation and possess sufficient knowledge to assess cyber risks and controls.

A broader scope than the Wbni

The Cbw has a considerably wider scope than the Wbni. Many medium-sized and large organisations in sectors that were not previously directly regulated may now fall within scope. The requirements also extend into the supply chain: regulated organisations must manage supplier risks and may consequently impose additional security requirements on suppliers.

Assessing applicability therefore requires more than identifying the organisation’s sector. Its size, services, place of establishment and position within critical supply chains are also relevant.

Formal documentation by ministry

In preparation for the Act, ministries are publishing sector-specific regulations and supervisory decisions. The following formal documents were available on 27 July 2026.

Infrastructure and Water Management

Agriculture, Fisheries, Food Security and Nature

Economic Affairs and Climate Policy

Education, Culture and Science

Justice and Security

This overview will be updated as additional regulations are published.

What should organisations do now?

With the Act taking effect on 15 August 2026, very little preparation time remains. Organisations should at least complete and document the following steps:

  • Determine whether the organisation qualifies as an essential or important entity, or is indirectly affected as a supplier.
  • Prepare registration in the entity register and register in good time through MijnNCSC.
  • Establish an incident-notification process capable of assessing and reporting a significant incident within 24 hours.
  • Assess security measures against the duty of care, including risk analysis, incident response, continuity, supply-chain security, logging and detection.
  • Document responsibilities, decision-making and oversight at board level.

From a legal obligation to demonstrable resilience

The Cbw requires more than policies and formal documentation. Organisations must demonstrate effective control of cyber risks. Measures should therefore reflect actual threats, dependencies and critical processes. Independent assessment, technical validation and exercises help establish whether controls remain effective under realistic conditions.

Contact

Do you need to establish whether your organisation falls within scope, or assess your technical and organisational measures? Contact DeepBlue Security & Intelligence at info@deepbluesecurity.nl or +31 (0) 70 290 6 290.

← Back to library

Direct access to senior cybersecurity expertise

Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.

  • No mailing lists or automated sales follow-up
  • Information is handled confidentially

Urgent assistance required?

Call +31 (0) 70 290 6 290
or email  info@deepbluesecurity.nl

Thank you. The message has been received and will be reviewed by one of our specialists.
The form could not be submitted. Please try again or contact info@deepbluesecurity.nl.