Skip to main content
NIS2 · NETHERLANDS

NIS2 in the Netherlands — the Cyberbeveiligingswet is now in force.

The Netherlands transposed late and then all at once. The Cyberbeveiligingswet (Cbw) was adopted by the Eerste Kamer on 7 July 2026 and entered into force on 15 August 2026, alongside the Wet weerbaarheid kritieke entiteiten that transposes the CER Directive. It replaces the Wet beveiliging netwerk- en informatiesystemen (Wbni) and brings roughly 8,000 organizations across 18 sectors into scope — most of them for the first time.

There is no transition period. The duty of care, the registration duty and the incident-reporting duty all apply from 15 August 2026 and are enforceable from that date. For organizations that waited for the law to be final before starting, the final law arrived with the obligations already running.

Who it applies to

Essential and important entities across the 18 sectors of the directive, established in the Netherlands or offering services there. The Dutch model spreads supervision across sectoral toezichthouders — the Rijksinspectie Digitale Infrastructuur (RDI) for digital infrastructure and central government, the Inspectie Leefomgeving en Transport for the water boards, and sector regulators elsewhere — while the Nationaal Cyber Security Centrum (NCSC) runs the national entity register and the incident portal. Essential entities face proactive and reactive supervision; important entities are supervised reactively. Which inspector you answer to depends on which sector you are in, and the answer is not always obvious for a group with several activities.

The clock

Competent authority: sectoral supervisors under the Cyberbeveiligingswet — RDI for digital infrastructure and central government, ILT for the water boards, sector regulators elsewhere — with NCSC-NL as national CSIRT and registrar. Transposition: Cyberbeveiligingswet (Cbw).

NIS2 in Netherlands · timeline
WhenWhat happens
7 July 2026Eerste Kamer adopts the Cyberbeveiligingswet and the Wet weerbaarheid kritieke entiteiten
15 August 2026Both laws enter into force · Wbni replaced · no transition period
15 August 2026Duty of care, registration duty (Mijn NCSC) and reporting duty apply and are enforceable

One register, many supervisors

The Cbw separates the two things most organizations expect to find in one place. Registration and incident reporting go to the NCSC, which acts as national CSIRT and operates the entiteitenregister and the notification portal. Supervision and enforcement sit with the sectoral toezichthouder for your activity, and a group operating in two sectors can have two. The public sector additionally carries the BIO2 baseline as its measure of the duty of care. TruSecure holds the classification — sector, entity class, supervisor, CSIRT — as a record on the entity rather than as tribal knowledge, so an incident is routed to the right portal and the right inspector on the first attempt, and the evidence an RDI inspector asks for is the same evidence a health or finance supervisor would read in their own shape.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Netherlands transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Netherlands requirements · how TruSecure answers them
What the law asksWhere it is answered
Register in the national entity register via Mijn NCSCEntity profile · classification, sector and supervisor held as records
Meet the duty of care, with measures you can showControl library · continuously monitored, evidence attached
Report significant incidents within the statutory timelinesIncident workflow · clocked from awareness, routed to CSIRT and supervisor
Show the management body approved and was trainedGovernance workspace · approvals and training records, dated
Answer the sectoral inspector — proactively if essentialSupervisor export · per control, sealed

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Netherlands Cbw readiness file · excerptSample data
Classification
important · digital infrastructure · supervisor RDI
Registration
Mijn NCSC · completed
Controls evidenced
54/61 · 7 open, each with an owner and a date
Incident routing
NCSC portal + RDI · tested
Export
sealed · sha256:b1f4...08d7

Where teams usually start

With a demo walked through by TruSecure — your classification under the Cbw, the supervisor and CSIRT that follow from it, the controls you already operate mapped against the duty of care, and a sample incident routed through the NCSC portal. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Netherlands by sectoral supervisors under the Cyberbeveiligingswet — RDI for digital infrastructure and central government, ILT for the water boards, sector regulators elsewhere — with NCSC-NL as national CSIRT and registrar. TruSecure determines applicability against Netherlands's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Does NIS2 apply to Dutch data center operators specifically?
Often yes, though the Netherlands' strong digital-infrastructure sector makes Annex I/II sector classification an unusually common point of confusion — TruSecure's applicability engine resolves the specific classification rather than a general reading of the Annexes.