The Dutch Cyber Security Act has been in force since 15 August 2026. Around 8,000 organisations across eighteen sectors must register, meet a duty of care and set up incident reporting. The board is personally accountable for it. That obligation is translated into a workable programme.
The Dutch Cyber Security Act (Cbw) and the Critical Entities Resilience Act (Wwke) entered into force on 15 August 2026. The Cbw replaces the Network and Information Systems Security Act (Wbni). Around 8,000 organisations across eighteen sectors fall under the new obligations. They are themselves responsible for determining whether they do.
NIS2 is a European directive; the Cyber Security Act is its Dutch implementation. Only that Dutch act matters to you: it applies to your organisation directly and it is what will be enforced. The act imposes four obligations.
Organisations covered by the act must register in the national entity register, maintained by the National Cyber Security Centre (NCSC). Registration runs through MijnNCSC using eHerkenning or SSOnRijk. Once registered, you gain access to the services of your sectoral CSIRT: threat intelligence and assistance during incidents. Registration is not a formality. It is the door to the support you are entitled to.
You must take appropriate and proportionate measures to manage the risks to your network and information systems, and to prevent incidents or limit their impact. “Appropriate and proportionate” is deliberately open-ended: what is expected of a regional water utility differs from what applies to a hospital or a grid operator. Translating that to your context is exactly where it often becomes difficult in practice.
Significant incidents are reported through the central reporting point on MijnNCSC. A single report reaches both your sectoral CSIRT and the regulator. What counts as “significant” varies by sector: the thresholds are set out in the ministerial regulation for your sector. Reporting is phased, and the deadlines run from the moment you become aware of the incident.
Trust service providers face a shorter deadline of 24 hours rather than 72. If you also fall under a European sector-specific law with its own reporting rules (such as DORA or the network code on cybersecurity for electricity), a different route and shorter deadlines may apply.
This is the provision most boards underestimate. The management body approves the measures and oversees their implementation. Directors must also have sufficient knowledge to assess risks and security measures, and are required to undergo appropriate training. Cyber security is no longer something you can fully delegate to IT.
The act applies to organisations providing essential or important services within eighteen sectors, including energy, drinking water, digital infrastructure, healthcare, public administration, transport, waste water, chemicals, and food production and distribution. Whether it applies to you depends on your sector, your activities and your size.
Two things are routinely overlooked here. First: you must determine this yourself: no letter from the government will arrive designating you. Second: even if the act does not apply to you directly, it may reach you through your customers. The duty of care extends to the supply chain, so entities that are covered will pass requirements down to their suppliers.
Most organisations start with their IT: office automation, identity management, backups. That is understandable and useful, but it is not what the continuity of an essential service rests on. That rests on operational technology: the control systems, the PLCs, the SCADA environment, the installations that actually treat water, transport electricity or keep a production line running.
That environment behaves differently from IT: equipment with a fifteen- to twenty-year lifespan, vendor dependency, maintenance windows planned months ahead, and integrity and availability as the top priorities rather than confidentiality. An IT security policy mapped one-to-one onto OT does not work there. At audit it leaves a gap you cannot close quickly.
More about the approach to OT security.
The work follows CAISSON, the four-phase model that starts from your business continuity rather than from a checklist. Phase 1, the Scan, establishes the scope across the five legal frameworks and tests your critical processes against the duty of care; the result is an impact and gap matrix, with an explicit gate before any work on measures begins. Phase 2, the Blueprint, translates those gaps into a master plan prioritised by risk, impact and implementation effort. Phase 3, the Implementation, puts the measures in place, with an emphasis on IT/OT integration and on the zone-and-conduit framework. Phase 4, Ongoing management, embeds the whole in a plan-do-check-act rhythm with periodic audits and supply chain monitoring.
In the scan, testing covers not only the Cyber Security Act but the wider Dutch framework: the GDPR, the Critical Entities Resilience Act (Wwke) and, where relevant, the Open Government Act and the Archives Act. The Archives Act 2026 replaces it on 1 January 2027. See the full four-phase model.
On 15 August 2026. The Senate passed the bill on 7 July 2026. The Critical Entities Resilience Act (Wwke), the Dutch implementation of the European CER Directive, entered into force on the same date.
NIS2 is a European directive and has no direct effect. Each member state transposes it into national law. The Cyber Security Act is that Dutch transposition and is the law enforced in the Netherlands. In practice the terms are used interchangeably; legally, the Cbw is the relevant text.
You must determine this yourself, based on your sector, your activities and your size. The NCSC provides a decision tree for this. For composite organisations, holding structures or activities spanning several sectors the answer is rarely clear-cut. That is one of the first things we established for you in the scan.
No, not automatically. But you do have a considerable head start. ISO 27001 covers much of the duty of care, but the Cbw adds requirements on registration, reporting deadlines, supply chain responsibility and management accountability. Moreover, the scope of an ISO certification is in practice often limited to the IT environment, whereas the act touches your entire service delivery, including OT.
Regulators supervise compliance and can request information, conduct investigations, issue binding instructions and impose administrative fines. More significant for the board is that the act explicitly assigns management responsibility for approving and overseeing the measures. That shifts the conversation from “what does it cost” to “who is liable”.
With three questions, in this order.
1. Is the organisation covered by the act?
2. Which services and systems are so critical that failure would affect service delivery?
3. Where does the organisation stand today against the duty of care?
Only once those three are answered does it make sense to discuss measures and budget. A readiness assessment answers them within a few weeks.
A readiness assessment tells you within a few weeks whether the act applies to you, where your gaps are and what needs to happen first. Schedule an introductory call.
Schedule an introductory call