Contact
Plenary chamber with semicircular rows of seats and a Dutch flag, seen from the gallery

Library

Ten supervisors, one Dutch cyber act

Share via

The Dutch Cybersecurity Act enters into force on 15 August 2026 and imposes the same core obligations on every essential and important entity. Who assesses you, how strictly, and when an incident must be reported does differ per sector.

This article covers those differences. If you are looking for the basics first, read The Dutch Cybersecurity Act: 15 August 2026, which sets out the scope, the three core obligations and the formal documentation per ministry.

In this article

Who supervises you?

The Netherlands has not appointed a central cyber supervisory authority. Ten supervisors oversee the same act, each within their own sector. They cooperate in the Collaborative Supervision of Digital Resilience, but remain independent inspectorates with their own working methods and their own supervisory culture.

Which supervisor applies to you depends on your subsector. The same holds for your CSIRT, and that is not always the NCSC.

Sector or subsectorSupervisorCSIRT
EnergyRDINCSC
Digital infrastructureRDINCSC
ICT service managementRDINCSC
TransportILTNCSC
Piped drinking waterILTNCSC
Packaged drinking waterNVWANCSC
FoodNVWANCSC
HealthcareIGJZ-CERT
BankingDNBNCSC
Financial market infrastructureAFMNCSC
MunicipalitiesRDIIBD
Water authoritiesILTCERT-WM

The CSIRT and the supervisor are different parties with different roles. The CSIRT supports you during incidents, the supervisor assesses your compliance. Reporting runs through a single central desk that serves both.

What does proactive or reactive supervision mean?

As an essential entity you receive proactive supervision. No incident is needed before an inspector visits, sends a questionnaire or requests documentation. For important entities the supervisor generally looks back after the fact, following an incident or on signs that the act is not being complied with.

The enforcement toolkit covers security scans and audits, binding instructions, penalty payments, publication of a breach and administrative fines. Those fines run up to 10 million euro or 2 per cent of worldwide annual turnover for essential entities, and up to 7 million euro or 1.4 per cent for important entities.

For essential entities a supervisor can also request temporary suspension of a certification, a licence or even a board member. That instrument does not exist for important entities.

Why are the reporting thresholds not in the act itself?

The Cbw is not simply one document. The act provides the framework, the Cybersecurity Decree works the obligations out for all sectors, and beneath that sit ministerial regulations per sector.

The Cybersecurity Decree gives the relevant minister the power to set separate criteria per subsector. The actual reporting threshold therefore differs per sector, while the statutory standard stays the same for everyone. Read the act alone and you miss precisely the number that counts during an incident.

When is an incident reportable?

The act gives an open standard for this. An incident is significant in the event of serious operational disruption, financial loss, or considerable damage to others. That is of little use during an incident.

The ministerial regulations make this concrete. Under the EZK Cybersecurity Regulation of 21 July 2026, an incident at a telecoms provider is in any case significant if an interruption affects at least 50,000 users for four hours or longer. For an internet exchange point the threshold is loss of 25 per cent of current traffic for at least 30 minutes.

These limits give direction, but they are certainly not a hard floor. Stay within them and you must still test against the open standard in the act. The reporting duty also applies beyond attacks. An incorrectly executed system update, or the accidental disclosure of confidential data, can be reportable too.

Check as well which framework applies to you. Providers of cloud computing, data centres, DNS, CDN, trust services and managed security services fall directly under Implementing Regulation (EU) 2024/2690. They sit in the same sector and have the same supervisor, but follow different rules.

What if you operate in several sectors?

An organisation that manufactures, runs its own data centre and delivers managed ICT services can face several supervisors, several ministerial regulations and several reporting thresholds at once. The supervisors carry out ecosystem analyses to map those dependencies, and where activities overlap one of them can act as coordinating supervisor.

That coordination is an administrative arrangement between inspectorates, not a statutory exemption. The obligations continue to apply per entity, and the distinction between essential and important entity also works through per business unit. Determine your position per legal entity, not at organisation level.

And if you supply an organisation under the act?

Then the act affects you indirectly, even if it does not apply to you. Organisations under the Cbw must include their supply chain in their risk management and can therefore impose requirements on you. That applies in particular if you supply services or components that form part of their network and information systems, or if you have access to those systems.

A certification such as ISO 27001 makes that conversation easier, but does not automatically cover the risk your client has identified. A supervisor does not supervise suppliers and cannot fine you. Your client can impose requirements in the contract, or place the work elsewhere.

Where to start

Record per legal entity which supervisor, which CSIRT, which ministry and which ministerial regulation apply. Without that overview you will not know during an incident where to report and against which threshold to test.

Next, translate the threshold values from your regulation into your incident process, so nobody has to debate whether the clock is already running. Then establish a single information position towards all supervisors involved, using the same risk analysis and the same evidence, so that different inspectorates do not encounter different documentation.

The supervisors start on 15 August 2026 without experience of this act. Their supervisory frameworks, intervention policies and the role of the coordinating supervisor still have to prove themselves. The obligations, meanwhile, apply from day one.

Which DeepBlue services fit this work

The Dutch Cybersecurity Act asks for demonstrable control of risk, not for policy documents alone. DeepBlue Security & Intelligence supports organisations in establishing their position, validating their measures and setting up detection and response. Which services fit depends on your sector, your size and the measures already in place.

  • Compliance and governance translates the duty of care into concrete processes, roles and evidence, including the documentation that makes a board decision demonstrable.
  • Penetration testing establishes whether technical measures hold under realistic attack conditions, across IT, cloud, applications, OT and identity environments.
  • Incident response and digital forensics supports triage, containment and forensic investigation, and produces the facts needed for the 24-hour early warning and the final report.
  • Managed SOC provides continuous detection and response, so a significant incident is noticed while the reporting deadline still leaves room to act.
  • Physical resilience assessment examines under controlled conditions whether unauthorised people can reach critical systems physically, which counts under the all hazards approach in the act.

A penetration test, assessment or compliance engagement does not demonstrate compliance and does not guarantee security. It provides independent technical evidence on whether controls work, which you can use to inform the board and the supervisor on a substantiated basis.

Sources

Last reviewed: 6 August 2026.

← Back to library

Direct access to senior cybersecurity expertise

Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.

  • No mailing lists or automated sales follow-up
  • Information is handled confidentially

Urgent assistance required?

Call +31 (0) 70 290 6 290
or email  info@deepbluesecurity.nl

Thank you. The message has been received and will be reviewed by one of our specialists.
The form could not be submitted. Please try again or contact info@deepbluesecurity.nl.