Blogs / 

The Dutch Cybersecurity Act will enter into force on 15 August 2026. Is your organisation ready?

IT, Privacy & Cybersecurity

4 August 2026

Written by

Hieke van Druten

Blog Image

On 7 July 2026, the Dutch Senate approved the Cybersecurity Act (Cyberbeveiligingswet, Cbw). As of 15 August 2026, new and far-reaching obligations therefore apply to a large number of organisations in the Netherlands. The Act implements the European NIS2 Directive and replaces the existing Network and Information Systems Security Act (Wet beveiliging netwerk- en informatiesystemen, Wbni). Organisations subject to the Cbw that fail to take action may face substantial fines and even personal liability for directors. Below, we explain what the Cbw entails, which organisations are subject to it, and what steps can now be taken.

 Is Your Organisation Subject to the Cybersecurity Act?

The Cbw applies to essential and important entities in eighteen sectors. These include organisations operating in energy, transport, healthcare, drinking water, wastewater, banking, digital infrastructure, the chemical industry, the food sector, manufacturing and government. Whether an organisation qualifies as “essential” or “important” depends on the sector and the size of the organisation. As a general rule, medium-sized and large enterprises operating in the sectors concerned fall within the scope of the Cbw.

Organisations are responsible for determining themselves whether they fall within the scope of the Cbw. There is no government authority that will automatically notify you. If you are unsure whether the Cbw applies to your organisation, it is advisable to seek legal advice.

What Obligations Apply Under the Cybersecurity Act?

The Cbw introduces four main obligations.

  1. Registration obligation. Every entity falling within the scope of the Act must register with the National Cyber Security Centre (NCSC). This obligation applies as of 15 August 2026. Any changes to the registration details must be reported within two weeks.
  2. Duty of care. Organisations must implement appropriate technical, operational and organisational measures to secure their network and information systems and to prevent incidents or mitigate their impact. In practice, this includes, among other things, policies for risk analysis and information security, incident handling, business continuity plans (including back-up and recovery plans), supply chain security and the use of multi-factor authentication.
    Incident reporting obligation. Significant incidents must be reported to the relevant Computer Security Incident Response Team
  3. (CSIRT) and the competent authority. The reporting process consists of several stages: an early warning within 24 hours of becoming aware of the incident, followed by a full notification within 72 hours. The organisation may also be required to submit an interim report. A final report must be submitted no later than one month after the initial notification. In certain circumstances, organisations may also be required to inform recipients of their services.
  4. Management responsibility. The management board must approve the security measures, and each board member must demonstrably have sufficient knowledge and skills to assess cybersecurity risks. This requires a certificate confirming completion of appropriate training. Board members have two years from the entry into force of the Cbw to meet this requirement.

What Sanctions Apply in the Event of a Breach of the Cybersecurity Act?

Supervisory authorities will have far-reaching powers. Administrative fines may be imposed for breaches of the duty of care or incident reporting obligation. In addition to financial penalties, supervisory authorities may issue binding instructions, require organisations to undergo audits and even order organisations to disclose violations publicly. In serious cases, the court may be asked to temporarily suspend a board member of an essential entity. Individual directors may also face a personal administrative fine of up to €25,000 for failing to comply with their obligations.

What Steps Should Your Organisation Take Before 15 August 2026?

15 August 2026 is fast approaching. The following steps are urgent:

  1. Determine whether your organisation falls within the scope of the Cbw. Consider your sector and the size of your organisation. If you operate in one of the sectors mentioned above and qualify as a medium-sized or large enterprise, there is a good chance that certain obligations will apply to you.
  2. Start the registration process with the NCSC via mijn.ncsc.nl.
  3. Have your cybersecurity policies reviewed. Do they meet the requirements of the duty of care? Are your incident response and reporting procedures in place and up to date?
  4. Discuss the issue at board level. Make sure every board member understands what is expected of them and schedule the mandatory training in good time.

Questions About the Cybersecurity Act?

Do you have questions about what the Cbw means for your organisation? Please feel free to contact Hieke van Druten, attorney at law specialising in IT, Privacy & Cybersecurity, or one of our other specialists in the IT, Privacy & Cybersecurity team.

Newsletter

Would you like to receive a monthly overview of our latest updates and blogs in your inbox? Subscribe to our newsletter.