The Netherlands Dutch Cybersecurity Act (Cyberbeveiligingswet) (Cbw) entered into force on 15 August 2026. Organisations that are subject to the law as an essential or important entity have since been subject to the obligation to register, to take care, to notify and to assume board-level responsibilities. Supervisors may impose measures and board-level penalties where an organisation does not comply with its obligations.
What's the Dutch Cybersecurity Act on?
The Dutch Cybersecurity Act transposes the European NIS2 Directive into Dutch law and has replaced the Wbni. The law imposes requirements for risk management, incident reporting, chain security and board-level involvement. Organisations should assess for themselves whether they are covered by the law and which supervisor and CSIRT are relevant to their sector.
Status and timeline in the Netherlands
- 14 December 2022: the European NIS2 Directive was adopted.
- 17 October 2024: the European transposition deadline expired.
- 7 July 2026: The First Chamber agreed to the Dutch Cybersecurity Act and the Act of Resilience Critical Entities.
- 15 August 2026: Both laws came into force.
The current public sector information is available at the NCTV.
Which NIS2 fines are possible?
The NIS2 Directive sets maximum board-level fines per entity type. For essential entities, this represents up to €10 million or 2% of the global annual turnover. For major entities, this represents up to €7 million or 1.4% of the global annual turnover. The amount is higher. The concrete enforcement depends on the infringement, circumstances and assessment by the competent supervisor.
A supervisor also has other powers. Think of information requests, binding instructions, audits and measures to remedy shortcomings. A fine is therefore only one part of the oversight.
What does this mean for board members?
Board members must approve cyber-risk management measures, oversee their implementation and maintain appropriate knowledge and skills. The governance challenge therefore centres on demonstrable decisions, sufficient resources, periodic reporting and follow-up of shortcomings. Personal consequences always require an assessment of the specific legal and factual circumstances.
What should your organisation do now?
- On the basis of legal entities, activities, size and special designation grounds, determine whether the organisation is covered by the Dutch Cybersecurity Act.
- Register the organisation in good time when the registration requirement applies.
- Perform an NIS2 GAP analysis on duty of care, reporting obligations, governance and chain risks.
- Capture improvement actions with a owner, time limit, evidence and board-level follow-up.
- Practice incident reporting, crisis decision making and recovery before a serious incident occurs.
- Review critical suppliers and digital links on continuity, access and incident arrangements.
Fines are rarely the largest business risk
The maximum fine attracts attention, but business stop, chain damage, repair costs and loss of trust can weigh more heavily on an organisation. Therefore, use the Dutch Cybersecurity Act as a framework to demonstrate the control of actual digital risks.
Read on
- Dutch Cybersecurity Act and NIS2 in practice
- NIS2 checklist Dutch Cybersecurity Act
- NIS2 board member liability
- NIS2 advice and implementation
Please note: This explanation is general in nature and does not replace a legal assessment of the applicability, obligations or possible sanctions in a concrete situation.


