After a prolonged drafting process, the Dutch implementation of the NIS2 Directive has reached its final stage. On 7 July 2026, the Dutch Senate approved the Cyberbeveiligingswet (Cbw), which is set to enter into force on 15 August 2026, together with the Cyberbeveiligingsbesluit (Cbb), the implementing decree that fills in the detail on matters such as management body training, certification, and incident notification. Before the Cbw can formally enter into force, it must be published in the Staatsblad. That publication is still pending, but entry into force of both the Cbw and the Cbb remains planned for 15 August 2026.
The Netherlands had missed the original NIS2 transposition deadline of 17 October 2024, leaving organisations to plan on the basis of draft texts. That position is about to change. From 15 August 2026, the Dutch supervisory and enforcement architecture will be live, and the Commission Implementing Regulation (EU) 2024/2690 (CIR), which prescribes detailed technical and methodological requirements for cloud, data centre, managed service, and managed security service providers, continues to apply alongside the national framework.
Practical enforcement is unlikely to be far behind. Organisations within scope, and those in the supply chain of in-scope entities, should now approach the Cbw as an active compliance file.
Enforcement Architecture
The Cbw assigns supervision to sectoral authorities rather than centralising it under a single regulator. The Rijksinspectie Digitale Infrastructuur (RDI) supervises digital infrastructure providers, including cloud computing, data centre, managed service, and managed security service providers. Other authorities take responsibility for their respective sectors, such as DNB and AFM for finance, IGJ for healthcare, and ILT for transport. The Nationaal Cyber Security Centrum (NCSC) is the national Computer Security Incident Response Team (CSIRT) and the destination for incident notifications. This is a purpose choice to ensure effective supervision through authorities familiar with their sectors.
The authorities can issue binding instructions, fines, conduct audits, publicly disclose violations, and appoint a monitoring officer for essential entities. Most notably, there is also the potential for judicial suspension of management body members, which the supervisor of an essential entity can request from the court.
Fines for breaching the central obligations (the duty of care, the incident notification obligations, or the obligation to inform service recipients) reach up to EUR 10,000,000 or 2 percent of worldwide annual turnover for essential entities, whichever is higher, and EUR 7,000,000 or 1.4 percent of worldwide annual turnover for important entities. Other procedural breaches, such as failure to register on the national entity register, are capped at EUR 1,000,000. Individual members of the management body face personal fines of up to EUR 25,000 for breach of the training obligations under Article 24 Cbw, on top of the corporate fine.
Who is In Scope
Applicability of the Cbw turns on sector, size, and territorial nexus. On sector, the entity must operate in Annex I (high-criticality sectors such as energy, transport, banking, health, digital infrastructure, ICT service management, and public administration) or Annex II (other critical sectors such as postal services, waste management, chemicals, food, and digital providers). On size, important-entity status applies from 50 employees or EUR 10 million in annual turnover and balance sheet; in Annex I sectors, entities that exceed 250 employees or EUR 50 million in turnover and EUR 43 million in balance sheet qualify as essential entities, with a stricter supervisory regime. On territory, the Cbw reaches entities established in the Netherlands and, for cloud, data centre, managed service, and managed security service providers, entities whose main establishment under Article 26 NIS2 is in the Netherlands (the location where cybersecurity decisions are predominantly taken), regardless of where the entity is established in the EU or beyond.
Main Obligations
The Cbw imposes the following principal obligations on essential and important entities.
- Registration: In-scope entities must register on the national entity register, providing contact details, IP ranges, the sectors in which they operate, and the Member States in which they provide services. This must be done within one month after Article 43 Cbw enters into force. Entities should prepare the information needed for registration in time, as this is likely to be one of the first visible compliance steps.
- Duty of care: Entities must take appropriate and proportionate technical, operational, and organisational measures to manage risks to their network and information systems and limit the impact of incidents. Minimum measure areas include risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, secure acquisition and development of systems, assessment of effectiveness, cyber hygiene and training, cryptography, HR security and access control, and multi-factor authentication and secured communications. For entities within scope of the CIR, the technical and methodological requirements in the CIR Annex apply directly and prevail over national rules on the same subject matter.
- Management body governance: The statutory executive directors registered with the trade registry, must approve the cybersecurity risk-management measures and oversee their implementation. Each member must also undergo training to identify and manage cybersecurity risks, assess risk-management measures, and evaluate the consequences for the entity's services. Compliance with the training obligation is evidenced by a certificate from a training programme meeting the content and form requirements of Cbb Articles 21 to 23.
- Incident notification: Significant incidents must be reported to the entity's CSIRT (NCSC, IBD, Z-CERT, or CERT Watermanagement, depending on sector) and to the competent supervisor under a staged process: an early warning within 24 hours of becoming aware of the incident (Article 26); a notification with an initial assessment within 72 hours (Article 27); an intermediate report if requested (Article 28); and a final report within one month (Article 29). A separate voluntary regime under Article 33 Cbw covers non-significant incidents, near-misses, and cyberthreats.
Supply Chain: Indirect Exposure for Organisations Outside the Direct Scope
A significant number of organisations will feel the Cbw's effects without falling within its direct scope. Article 21 para. 3 lit. d Cbw requires essential and important entities to manage supply chain risks, which in practice means imposing security requirements on their suppliers, sub-contractors, and other third parties. Suppliers servicing NIS2-regulated customers should anticipate due diligence questionnaires, contractual clauses on information security, incident notification, audit rights, sub-contracting limitations, and termination triggers, as well as requests to evidence compliance with recognised security standards. For many organisations, supply chain pressure will reach them before any direct supervisor does, and a failure to engage with these expectations can translate quickly into lost contracts.
Priorities for Organisations
Organisations should expect closer attention to whether the management body has approved cybersecurity measures, whether individual board members hold a valid training certificate, whether incident notification processes work in practice, and whether the duty-of-care measures have been implemented in line with the CIR and the Cbb.
Where readiness is not yet there, that gap will be visible. Customer and contractual pressure will compound this, as in-scope entities push their NIS2 obligations down to their supply chain partners.
A reasonable starting point is to confirm whether the organisation is in scope and, if so, in which category, then to map its obligations under the Cbw, the Cbb, and (where applicable) the CIR. From there, management body approval of the cybersecurity measures should be formalised, training arranged for the executive directors, the information required for registration on the national entity register prepared, the NCSC reporting pathway built into the incident handling process, and the supplier and customer contractual stack reviewed against NIS2 expectations.
Looking Ahead
The Cbw does not impose obligations beyond those that NIS2 and the CIR already set out. What it does is switch on the national enforcement infrastructure and confirm which Dutch authority is competent in each sector.
For organisations within scope, that switch is the operative moment. The fines are real and, from 15 August 2026, the supervisors will be equipped to act. Supply chain pressure is already moving down the contractual chain. Visible enforcement will take time, but expectations on readiness are already being formed.
No comments