
On 7 July 2026, the Dutch Senate approved the Cybersecurity Act (Cyberbeveiligingswet, Cbw). As of 15 August 2026, new and far-reaching obligations therefore apply to a large number of organisations in the Netherlands. The Act implements the European NIS2 Directive and replaces the existing Network and Information Systems Security Act (Wet beveiliging netwerk- en informatiesystemen, Wbni). Organisations subject to the Cbw that fail to take action may face substantial fines and even personal liability for directors. Below, we explain what the Cbw entails, which organisations are subject to it, and what steps can now be taken.
The Cbw applies to essential and important entities in eighteen sectors. These include organisations operating in energy, transport, healthcare, drinking water, wastewater, banking, digital infrastructure, the chemical industry, the food sector, manufacturing and government. Whether an organisation qualifies as “essential” or “important” depends on the sector and the size of the organisation. As a general rule, medium-sized and large enterprises operating in the sectors concerned fall within the scope of the Cbw.
Organisations are responsible for determining themselves whether they fall within the scope of the Cbw. There is no government authority that will automatically notify you. If you are unsure whether the Cbw applies to your organisation, it is advisable to seek legal advice.
The Cbw introduces four main obligations.
Supervisory authorities will have far-reaching powers. Administrative fines may be imposed for breaches of the duty of care or incident reporting obligation. In addition to financial penalties, supervisory authorities may issue binding instructions, require organisations to undergo audits and even order organisations to disclose violations publicly. In serious cases, the court may be asked to temporarily suspend a board member of an essential entity. Individual directors may also face a personal administrative fine of up to €25,000 for failing to comply with their obligations.
15 August 2026 is fast approaching. The following steps are urgent:
Do you have questions about what the Cbw means for your organisation? Please feel free to contact Hieke van Druten, attorney at law specialising in IT, Privacy & Cybersecurity, or one of our other specialists in the IT, Privacy & Cybersecurity team.
Would you like to receive a monthly overview of our latest updates and blogs in your inbox? Subscribe to our newsletter.