Skip to main content
Adopted, not yet in forceNIS2

NIS2 in Netherlands

The Dutch Senate passed the Cyberbeveiligingswet (Cbw) on 7 July 2026 and it enters into force on 15 August 2026. There is no general transition period — obligations apply from day one for the roughly 8,000 entities in scope.

Transposition law
Cyberbeveiligingswet (Cbw)
Enters into force
15 August 2026
Competent authority
NCSC-NL: National Cyber Security Centre
Max fine (Essential)
€10 million or 2% of global annual turnover
Max fine (Important)
€7 million or 1.4% of global annual turnover
Law adopted
7 July 2026

Key Deadlines

Tweede Kamer adopts the bill
15 April 2026
Eerste Kamer (Senate) passes the Cbw
7 July 2026
Cbw enters into force — obligations apply immediately
15 August 2026

Competent Authority

NCSC-NL: National Cyber Security Centre
Coordination and support; sector supervisors handle enforcement
https://www.ncsc.nl

The Netherlands uses a multi-authority model where sector-specific regulators (Agentschap Telecom for ICT/telecom, DNB for banking, NZa for health) act as competent authorities under the CBW umbrella. NCSC-NL provides cross-sector threat intelligence.

Registration Process

Register through your sector-specific regulator. For most digital service providers and general ICT entities, register via Agentschap Telecom. Healthcare entities register via NZa; financial entities via DNB.

📊 Quick Test

Find out if your company is in scope

Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?

Check NIS2 Scope →

Key Requirements

  • 1Registration with the relevant sector supervisor
  • 2Incident notification within 24 hours (early warning) and 72 hours (full notification) to NCSC-NL
  • 3Annual risk assessment using the NCSC-NL cyber risk assessment methodology
  • 4Duty of care (zorgplicht) requiring proportionate security measures
  • 5Notification of significant changes to services or infrastructure
  • 6Supply chain due diligence requirements

National Additions

The Netherlands added a general 'duty of care' (zorgplicht) concept broader than Article 21's enumerated measures
Dutch water management authorities (waterschappen) are explicitly included
The Cbw introduced a dedicated incident notification portal at meldportaalcyberincidenten.nl
Higher education institutions receive a three-year transition period — the only general exception to immediate application
Scope explicitly covers ministries, municipalities, provinces, water authorities and inter-municipal partnerships

FAQ: NIS2 in Netherlands

Which Dutch regulator is responsible for my sector?
Agentschap Telecom handles telecom and most digital services. De Nederlandsche Bank (DNB) covers banking and financial markets. The Nederlandse Zorgautoriteit (NZa) covers healthcare. The national rail and transport authority handles transport. When in doubt, contact NCSC-NL for guidance.
Does the zorgplicht differ from Article 21 NIS2?
Yes. The Dutch zorgplicht is a principles-based obligation requiring entities to implement 'appropriate and proportionate' measures. It is broader than Article 21's enumerated list and allows the regulator to require additional controls based on risk.
When exactly do Dutch NIS2 obligations start?
15 August 2026. The Senate passed the Cyberbeveiligingswet on 7 July 2026 and there is no general transition period, so the registration duty, duty of care, incident reporting and board-level governance obligations all apply from that date. Higher education institutions are the exception, with a three-year transition.
Why was the Netherlands referred to the EU Court of Justice?
The Netherlands missed the 17 October 2024 transposition deadline by nearly two years. On 8 July 2026 the European Commission referred the Netherlands, alongside Ireland, Spain and France, to the Court of Justice of the EU seeking daily fines. The Cbw entering into force on 15 August 2026 is intended to resolve the Dutch case.

Ready to assess your NIS2 compliance?

Use our free tools to check your NIS2 scope and run a gap assessment.

Currency and sources

The legal details on this page were last checked on 25 July 2026.