
Library
The Dutch Cybersecurity Act enters into force on 15 August 2026 and imposes the same core obligations on every essential and important entity. Who assesses you, how strictly, and when an incident must be reported does differ per sector.
This article covers those differences. If you are looking for the basics first, read The Dutch Cybersecurity Act: 15 August 2026, which sets out the scope, the three core obligations and the formal documentation per ministry.
The Netherlands has not appointed a central cyber supervisory authority. Ten supervisors oversee the same act, each within their own sector. They cooperate in the Collaborative Supervision of Digital Resilience, but remain independent inspectorates with their own working methods and their own supervisory culture.
Which supervisor applies to you depends on your subsector. The same holds for your CSIRT, and that is not always the NCSC.
| Sector or subsector | Supervisor | CSIRT |
|---|---|---|
| Energy | RDI | NCSC |
| Digital infrastructure | RDI | NCSC |
| ICT service management | RDI | NCSC |
| Transport | ILT | NCSC |
| Piped drinking water | ILT | NCSC |
| Packaged drinking water | NVWA | NCSC |
| Food | NVWA | NCSC |
| Healthcare | IGJ | Z-CERT |
| Banking | DNB | NCSC |
| Financial market infrastructure | AFM | NCSC |
| Municipalities | RDI | IBD |
| Water authorities | ILT | CERT-WM |
The CSIRT and the supervisor are different parties with different roles. The CSIRT supports you during incidents, the supervisor assesses your compliance. Reporting runs through a single central desk that serves both.
As an essential entity you receive proactive supervision. No incident is needed before an inspector visits, sends a questionnaire or requests documentation. For important entities the supervisor generally looks back after the fact, following an incident or on signs that the act is not being complied with.
The enforcement toolkit covers security scans and audits, binding instructions, penalty payments, publication of a breach and administrative fines. Those fines run up to 10 million euro or 2 per cent of worldwide annual turnover for essential entities, and up to 7 million euro or 1.4 per cent for important entities.
For essential entities a supervisor can also request temporary suspension of a certification, a licence or even a board member. That instrument does not exist for important entities.
The Cbw is not simply one document. The act provides the framework, the Cybersecurity Decree works the obligations out for all sectors, and beneath that sit ministerial regulations per sector.
The Cybersecurity Decree gives the relevant minister the power to set separate criteria per subsector. The actual reporting threshold therefore differs per sector, while the statutory standard stays the same for everyone. Read the act alone and you miss precisely the number that counts during an incident.
The act gives an open standard for this. An incident is significant in the event of serious operational disruption, financial loss, or considerable damage to others. That is of little use during an incident.
The ministerial regulations make this concrete. Under the EZK Cybersecurity Regulation of 21 July 2026, an incident at a telecoms provider is in any case significant if an interruption affects at least 50,000 users for four hours or longer. For an internet exchange point the threshold is loss of 25 per cent of current traffic for at least 30 minutes.
These limits give direction, but they are certainly not a hard floor. Stay within them and you must still test against the open standard in the act. The reporting duty also applies beyond attacks. An incorrectly executed system update, or the accidental disclosure of confidential data, can be reportable too.
Check as well which framework applies to you. Providers of cloud computing, data centres, DNS, CDN, trust services and managed security services fall directly under Implementing Regulation (EU) 2024/2690. They sit in the same sector and have the same supervisor, but follow different rules.
An organisation that manufactures, runs its own data centre and delivers managed ICT services can face several supervisors, several ministerial regulations and several reporting thresholds at once. The supervisors carry out ecosystem analyses to map those dependencies, and where activities overlap one of them can act as coordinating supervisor.
That coordination is an administrative arrangement between inspectorates, not a statutory exemption. The obligations continue to apply per entity, and the distinction between essential and important entity also works through per business unit. Determine your position per legal entity, not at organisation level.
Then the act affects you indirectly, even if it does not apply to you. Organisations under the Cbw must include their supply chain in their risk management and can therefore impose requirements on you. That applies in particular if you supply services or components that form part of their network and information systems, or if you have access to those systems.
A certification such as ISO 27001 makes that conversation easier, but does not automatically cover the risk your client has identified. A supervisor does not supervise suppliers and cannot fine you. Your client can impose requirements in the contract, or place the work elsewhere.
Record per legal entity which supervisor, which CSIRT, which ministry and which ministerial regulation apply. Without that overview you will not know during an incident where to report and against which threshold to test.
Next, translate the threshold values from your regulation into your incident process, so nobody has to debate whether the clock is already running. Then establish a single information position towards all supervisors involved, using the same risk analysis and the same evidence, so that different inspectorates do not encounter different documentation.
The supervisors start on 15 August 2026 without experience of this act. Their supervisory frameworks, intervention policies and the role of the coordinating supervisor still have to prove themselves. The obligations, meanwhile, apply from day one.
The Dutch Cybersecurity Act asks for demonstrable control of risk, not for policy documents alone. DeepBlue Security & Intelligence supports organisations in establishing their position, validating their measures and setting up detection and response. Which services fit depends on your sector, your size and the measures already in place.
A penetration test, assessment or compliance engagement does not demonstrate compliance and does not guarantee security. It provides independent technical evidence on whether controls work, which you can use to inform the board and the supervisor on a substantiated basis.
Last reviewed: 6 August 2026.
Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.
Urgent assistance required?
Call +31 (0) 70 290 6 290
or email info@deepbluesecurity.nl