Cybersecurity Act: Five Actions for Your Organisation

The Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw) has been in force since 15 August 2026. The Act transposes the European NIS2 Directive into Dutch legislation and sets requirements for the digital security of organisations in designated sectors, including energy, digital infrastructure, healthcare, government and transport.

Does your organisation fall under the Cybersecurity Act? Then you need to determine which obligations apply to your organisation and how you will comply with them. In this blog, you will read about the five actions you need to take now.

1. Determine Whether the Act Applies to Your Organisation

Start by assessing whether your organisation falls under the Cybersecurity Act. To do so, evaluate the sector you operate in, the nature of your services and the size of your organisation. Also take into account any exemptions and possible designation by the government. Document whether your organisation qualifies as an essential or important entity.

In addition, assess what security requirements your customers impose on your organisation. If you supply to an organisation that falls under the Act, that does not automatically mean you fall under the Act yourself. However, your customer may impose contractual security requirements on you in order to reduce supply chain risks.

Document your assessment in writing. Describe which activities you have assessed, which criteria you have applied and why your organisation does or does not fall under the Act. This prevents you from having to start from scratch during an audit.

2. Arrange Your Registration

Organisations that fall under the Cybersecurity Act must register in the entity register. In the Netherlands, this is done via MijnNCSC, the portal of the National Cyber Security Centre (NCSC). Make sure to arrange the necessary access and authorisations in good time.

Registration is not a one-off administrative action. Organisations must keep their information up to date and determine internally who is responsible for managing it. Think in advance about the following questions:

  • Who manages the registration?
  • What information needs to be provided?
  • Who monitors changes in activities, contact persons and systems?
  • How do you ensure that a successor can take over the registration without any issues?

An up-to-date registration also helps in the event of incidents. The NCSC and the relevant supervisory authority will then know how to contact your organisation.

3. Embed Board-Level Accountability

The board must approve the security measures and oversee their implementation. Board members must complete appropriate training to enable them to assess cyber risks and measures. Also document which tasks are carried out by management and the IT department.

This requires more than an annual security report. The board must have insight into the key risks, dependencies and areas for improvement. It must also be clear who makes decisions when an incident threatens the continuity of services.

Discuss cybersecurity during regular meetings on plans, budgets and results. Allocate budget, document decisions and improvement actions, and verify that the organisation follows through on those actions. This allows the board to steer effectively.

4. Set Up the Incident Reporting Process

The Cybersecurity Act includes a mandatory reporting obligation for significant incidents. These are incidents that, for example, seriously disrupt your services or may cause considerable damage. Check which thresholds apply to your sector. The reporting obligation proceeds in phases:

  • Early warning: Provide an early warning as quickly as possible, at the latest within 24 hours of becoming aware of (or suspecting) a significant incident.
  • Incident notification: Submit an incident notification generally within 72 hours of becoming aware of the incident, including an initial assessment of its severity and impact.
  • Final report: Submit a final report no later than one month after the incident notification. Is the incident still ongoing? Then submit a progress report and deliver the final report within one month of resolution.

For trust service providers, the deadline for the incident notification is 24 hours. European sector-specific legislation, such as DORA, may also prescribe a different reporting route. Check which rules apply to your organisation.

Do not wait until all the facts are known. Via the central reporting point on MijnNCSC, a single report reaches both the competent Computer Security Incident Response Team (CSIRT) and the supervisory authority. Determine in advance:

  • Who assesses whether an incident is significant?
  • Who is authorised to report on behalf of the organisation?
  • What information must be available?
  • How do you reach the board, IT, communications and legal advisors outside office hours?
  • How do you record decisions and timestamps?

An incident procedure that only exists on paper is of little use during a ransomware attack or major outage. Therefore, test the process with an exercise. For example, simulate that a key supplier fails and have the relevant employees determine when and how to report.

5. Demonstrate Compliance with the Duty of Care

The duty of care requires organisations to take appropriate and proportionate measures to secure their network and information systems. The precise measures depend on the risks, the size of the organisation and the nature of the services provided.

Start with an overview of your key processes, systems, data and suppliers. Then assess which threats could affect the continuity of your services. Think of phishing, ransomware, cloud provider outages, account abuse and software vulnerabilities.

When developing your measures, consider among other things:

  • Access management and multi-factor authentication
  • Back-ups and recovery tests
  • Patch and vulnerability management
  • Logging and monitoring
  • Incident response and crisis communication
  • Supply chain security
  • Regular training and awareness

Document which measures you are taking and why they are appropriate to your organisation's risks. Also test whether they work. Keep records of recovery tests and incident exercises, evaluate the results and document how you follow up on areas for improvement. This makes your compliance with the duty of care visible and demonstrable.

Take the Next Step

Map out which of these five actions your organisation has already completed and where further work is needed. Assign a responsible person and a deadline for each outstanding action. Would you like to know whether your organisation falls under the Cybersecurity Act or where you still need to make adjustments? We can help you with the assessment and the next steps.

Contact us

Back to overview