Blogs / 

The Cybersecurity Act has entered into force: Works Councils, play your part!

Employment, Employee Participation & Mediation

20 August 2026

Written by

Barbara van Dam

Michelle Wijnant

Blog Image

Cyberattacks targeting hospitals, municipalities, critical infrastructure and other public service providers are no longer exceptional. Organisations therefore need to strengthen their resilience against digital threats. On 15 August 2026, the Cybersecurity Act (Cyberbeveiligingswet, Cbw) entered into force. With this Act, the Netherlands implements the European NIS2 Directive. The aim of the Cbw is to require organisations to take their digital resilience seriously and ensure that it is properly addressed. For management boards, this is primarily a compliance issue. However, a closer look at what these obligations mean in practice shows that the works council also has an important role to play.

Who does the Cbw apply to?

The Cybersecurity Act applies to essential and important entities in various sectors, including healthcare, energy, space, research, digital infrastructure and government. Larger companies in other sectors may also fall within its scope. This may, for example, include companies with more than 50 employees or with an annual turnover and/or balance sheet total exceeding €10 million. Suppliers or subsidiaries of such organisations may also fall within the scope of the Act or be affected by it, depending on their role in the supply chain. Organisations are responsible for determining whether the Cybersecurity Act applies to them. They can use a self-assessment tool to check whether they fall within its scope.

What does the Cybersecurity Act regulate?

The Act requires organisations to take appropriate measures to protect their network and information systems against cyber risks. Broadly speaking, it consists of a duty of care, an incident reporting obligation, various governance obligations (including training requirements and risk management), and a registration requirement. Serious incidents must also be reported to the relevant supervisory authority. Our earlier blogs, “Cybersecurity Act: are you prepared?” and “The Cybersecurity Act enters into force on 15 August 2026. Are you ready?”, explain how cyber risks can be identified within an organisation and what obligations arise under the Act. 

No direct rights for employee representation - but there is a hook

The Cybersecurity Act itself does not grant the works council any direct rights. However, it contains several provisions that, in practice, will almost inevitably touch on matters for which the works council may have consultation, consent or advisory rights under the Dutch Works Councils Act (WOR). These include:

  • mandatory cybersecurity training;
  • stricter system access requirements;
  • multi-factor authentication;
  • new authorisation and control procedures;
  • monitoring the use of IT systems;
  • screening measures for certain positions.

Duty of care and governance (Article 21 Cbw)

The core of the duty of care is set out in Article 21(3), which lists the categories of security measures that entities must take at a minimum. Two elements are directly relevant to the works council. Subsection (g) requires “basic cyber hygiene practices and cybersecurity training”. If the organisation implements this through mandatory, structural training requirements for employees (or a particular group of employees), this may qualify as a change to a scheme concerning employee training within the meaning of Article 27(1)(f) WOR and, depending on how it is structured, potentially also as a scheme concerning employee performance assessment within the meaning of Article 27(1)(g) WOR.

Subsection (i) additionally requires “security aspects relating to personnel, access policies and asset management”. The practical implementation of these requirements — screening procedures upon recruitment, authorisation models and system access controls — may amount to a scheme concerning the processing or protection of employees’ personal data (Article 27(1)(k) WOR) or to a measure enabling the observation or monitoring of employees (Article 27(1)(l) WOR).

If the organisation introduces a substantial new security system — for example, a new access management platform, multi-factor authentication or monitoring system — this may also qualify as a significant technological facility requiring consultation under Article 25(1)(k) WOR. Depending on the amounts involved, it may also constitute a significant investment within the meaning of Article 25(1)(h) WOR.

Governance (Article 24 Cbw)

Article 24 sends an important signal to works councils: do not wait. Management board members are required to have sufficient knowledge of cyber risks and must receive training to this end. They must also formally approve the security measures implemented under the Act.

In practice, this means that many organisations will take decisions in the short term regarding training, access policies, monitoring and other security measures. Because directors may face personal enforcement risks and director liability in the event of non-compliance, there will be considerable pressure to implement these measures quickly. For the works council, this is precisely why it is important to engage in discussions at an early stage and determine whether any consent or advisory rights apply.

What can the works council do now?

We recommend that works council members working in one of the sectors covered by the Cbw actively ask, during discussions on the general state of affairs (Article 24 WOR), what the entry into force of the Act means for their organisation, how it will be implemented and what impact this will have on employees. Management and the works council can then discuss whether and to what extent the works council has formal powers and make arrangements for any employee representation process that may be required.

Does your organisation want to implement the Cybersecurity Act properly while taking employee representation into account? We would be happy to help.

Questions?

If you have any questions, please contact Barbara van Dam-Keuken, Legal Assistant specialising in Employment & Employee Participation, or Michelle Wijnant, Attorney specialising in IT, Privacy & Cybersecurity.

Newsletter

Would you like to receive a monthly overview of our latest legal updates and blog articles? Subscribe to our newsletter.