The Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw) has been in force since 15 August 2026. The Act transposes the European NIS2 Directive into Dutch legislation and sets requirements for the digital security of organisations in designated sectors, including energy, digital infrastructure, healthcare, government and transport.
Does your organisation fall under the Cybersecurity Act? Then you need to determine which obligations apply to your organisation and how you will comply with them. In this blog, you will read about the five actions you need to take now.
Start by assessing whether your organisation falls under the Cybersecurity Act. To do so, evaluate the sector you operate in, the nature of your services and the size of your organisation. Also take into account any exemptions and possible designation by the government. Document whether your organisation qualifies as an essential or important entity.
In addition, assess what security requirements your customers impose on your organisation. If you supply to an organisation that falls under the Act, that does not automatically mean you fall under the Act yourself. However, your customer may impose contractual security requirements on you in order to reduce supply chain risks.
Document your assessment in writing. Describe which activities you have assessed, which criteria you have applied and why your organisation does or does not fall under the Act. This prevents you from having to start from scratch during an audit.
Organisations that fall under the Cybersecurity Act must register in the entity register. In the Netherlands, this is done via MijnNCSC, the portal of the National Cyber Security Centre (NCSC). Make sure to arrange the necessary access and authorisations in good time.
Registration is not a one-off administrative action. Organisations must keep their information up to date and determine internally who is responsible for managing it. Think in advance about the following questions:
An up-to-date registration also helps in the event of incidents. The NCSC and the relevant supervisory authority will then know how to contact your organisation.
The board must approve the security measures and oversee their implementation. Board members must complete appropriate training to enable them to assess cyber risks and measures. Also document which tasks are carried out by management and the IT department.
This requires more than an annual security report. The board must have insight into the key risks, dependencies and areas for improvement. It must also be clear who makes decisions when an incident threatens the continuity of services.
Discuss cybersecurity during regular meetings on plans, budgets and results. Allocate budget, document decisions and improvement actions, and verify that the organisation follows through on those actions. This allows the board to steer effectively.
The Cybersecurity Act includes a mandatory reporting obligation for significant incidents. These are incidents that, for example, seriously disrupt your services or may cause considerable damage. Check which thresholds apply to your sector. The reporting obligation proceeds in phases:
For trust service providers, the deadline for the incident notification is 24 hours. European sector-specific legislation, such as DORA, may also prescribe a different reporting route. Check which rules apply to your organisation.
Do not wait until all the facts are known. Via the central reporting point on MijnNCSC, a single report reaches both the competent Computer Security Incident Response Team (CSIRT) and the supervisory authority. Determine in advance:
An incident procedure that only exists on paper is of little use during a ransomware attack or major outage. Therefore, test the process with an exercise. For example, simulate that a key supplier fails and have the relevant employees determine when and how to report.
The duty of care requires organisations to take appropriate and proportionate measures to secure their network and information systems. The precise measures depend on the risks, the size of the organisation and the nature of the services provided.
Start with an overview of your key processes, systems, data and suppliers. Then assess which threats could affect the continuity of your services. Think of phishing, ransomware, cloud provider outages, account abuse and software vulnerabilities.
When developing your measures, consider among other things:
Document which measures you are taking and why they are appropriate to your organisation's risks. Also test whether they work. Keep records of recovery tests and incident exercises, evaluate the results and document how you follow up on areas for improvement. This makes your compliance with the duty of care visible and demonstrable.
Map out which of these five actions your organisation has already completed and where further work is needed. Assign a responsible person and a deadline for each outstanding action. Would you like to know whether your organisation falls under the Cybersecurity Act or where you still need to make adjustments? We can help you with the assessment and the next steps.