NIS2 in the Netherlands — the Cyberbeveiligingswet is now in force.
The Netherlands transposed late and then all at once. The Cyberbeveiligingswet (Cbw) was adopted by the Eerste Kamer on 7 July 2026 and entered into force on 15 August 2026, alongside the Wet weerbaarheid kritieke entiteiten that transposes the CER Directive. It replaces the Wet beveiliging netwerk- en informatiesystemen (Wbni) and brings roughly 8,000 organizations across 18 sectors into scope — most of them for the first time.
There is no transition period. The duty of care, the registration duty and the incident-reporting duty all apply from 15 August 2026 and are enforceable from that date. For organizations that waited for the law to be final before starting, the final law arrived with the obligations already running.
Who it applies to
Essential and important entities across the 18 sectors of the directive, established in the Netherlands or offering services there. The Dutch model spreads supervision across sectoral toezichthouders — the Rijksinspectie Digitale Infrastructuur (RDI) for digital infrastructure and central government, the Inspectie Leefomgeving en Transport for the water boards, and sector regulators elsewhere — while the Nationaal Cyber Security Centrum (NCSC) runs the national entity register and the incident portal. Essential entities face proactive and reactive supervision; important entities are supervised reactively. Which inspector you answer to depends on which sector you are in, and the answer is not always obvious for a group with several activities.
The clock
Competent authority: sectoral supervisors under the Cyberbeveiligingswet — RDI for digital infrastructure and central government, ILT for the water boards, sector regulators elsewhere — with NCSC-NL as national CSIRT and registrar. Transposition: Cyberbeveiligingswet (Cbw).
| When | What happens |
|---|---|
| 7 July 2026 | Eerste Kamer adopts the Cyberbeveiligingswet and the Wet weerbaarheid kritieke entiteiten |
| 15 August 2026 | Both laws enter into force · Wbni replaced · no transition period |
| 15 August 2026 | Duty of care, registration duty (Mijn NCSC) and reporting duty apply and are enforceable |
One register, many supervisors
The Cbw separates the two things most organizations expect to find in one place. Registration and incident reporting go to the NCSC, which acts as national CSIRT and operates the entiteitenregister and the notification portal. Supervision and enforcement sit with the sectoral toezichthouder for your activity, and a group operating in two sectors can have two. The public sector additionally carries the BIO2 baseline as its measure of the duty of care. TruSecure holds the classification — sector, entity class, supervisor, CSIRT — as a record on the entity rather than as tribal knowledge, so an incident is routed to the right portal and the right inspector on the first attempt, and the evidence an RDI inspector asks for is the same evidence a health or finance supervisor would read in their own shape.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Netherlands transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register in the national entity register via Mijn NCSC | Entity profile · classification, sector and supervisor held as records |
| Meet the duty of care, with measures you can show | Control library · continuously monitored, evidence attached |
| Report significant incidents within the statutory timelines | Incident workflow · clocked from awareness, routed to CSIRT and supervisor |
| Show the management body approved and was trained | Governance workspace · approvals and training records, dated |
| Answer the sectoral inspector — proactively if essential | Supervisor export · per control, sealed |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Classification
- important · digital infrastructure · supervisor RDI
- Registration
- Mijn NCSC · completed
- Controls evidenced
- 54/61 · 7 open, each with an owner and a date
- Incident routing
- NCSC portal + RDI · tested
- Export
- sealed · sha256:b1f4...08d7
Where teams usually start
With a demo walked through by TruSecure — your classification under the Cbw, the supervisor and CSIRT that follow from it, the controls you already operate mapped against the duty of care, and a sample incident routed through the NCSC portal. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Netherlands by sectoral supervisors under the Cyberbeveiligingswet — RDI for digital infrastructure and central government, ILT for the water boards, sector regulators elsewhere — with NCSC-NL as national CSIRT and registrar. TruSecure determines applicability against Netherlands's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.