Menu
← Blog

The Dutch Cyberbeveiligingswet is in force: what to check now

The Netherlands' NIS2 law applies from 15 August 2026 — who is essential by law, how group size counts, and how registration and reporting actually run.

20 September 2026

Abstract editorial illustration for “The Dutch Cyberbeveiligingswet is in force: what to check now”

One date, and it is not a registration deadline

The Cyberbeveiligingswet — the Cbw — is the Dutch transposition of NIS2, and it is in force from 15 August 2026. That single date carries more weight than it looks, because the law does not pair it with a registration deadline. The duty to register applies from the day the law took effect. There is no grace period written into the statute and no national cut-off date to put in a client's plan.

This is a different shape from the neighbours. A German client gets three months from the moment it first qualifies. An Austrian entity gets until 1 January 2027. A Belgian one had a fixed calendar date. A Dutch client gets a duty that is simply live, with nothing in the law to count down from. If you have been waiting for a deadline to organise the work around, stop waiting: its absence is the reason to move now rather than the reason to wait.

Everything country-specific below comes from our national NIS2 profile for the Netherlands, checked against primary sources on 17 September 2026. Commencement orders, authority guidance and portal mechanics move. Re-check the primary source before any of this goes into a client deliverable with your name on it.

Who is essential by law, whatever the headcount

The usual NIS2 analysis runs sector first, then size. The Cbw short-circuits that for a defined set of bodies: ministries, provinces, municipalities, water boards and critical entities are essential by law (art. 8). Headcount and turnover never enter the conversation for them.

That matters more than the bare list suggests, because of how much Dutch public administration sits in bodies that do not feel large. A water board is not a big employer. A small municipality is not a big employer. Neither gets to run the size test, and neither gets to argue its way out of the essential tier by pointing at a staff list. If your client is one of these bodies, the classification question is closed before you open it, and what remains is registration, reporting readiness and management sign-off.

The mirror of that is the client who assumes the opposite — that being publicly funded or publicly owned pulls them in automatically. Art. 8 names specific bodies. It is not a general rule about the public sector, and a supplier to a municipality is not a municipality. Read the list, not the vibe.

For everyone outside art. 8, the size test applies. Our profile records no Dutch deviation from the directive's own size-cap rule (Recommendation 2003/361/EC); where a national law does deviate, that sits in the profile's notes, and for the Netherlands it does not.

And the class you land on — essential, important, out of scope — is a legal qualification that belongs to the consultant who signs the memo. Treat any tool, ours included, as something that proposes a class and shows you the trigger, never something that assigns one.

Partner and linked enterprises count

The Dutch profile is explicit on the point that most often changes the answer for a mid-sized client: partner and linked enterprises count toward size.

In practice this is the part of the Dutch analysis most likely to be wrong when it arrives on your desk. A client with 40 people in Rotterdam is not a 40-person entity if it is majority-owned by a group, or if it holds a qualifying stake in other companies. The Recommendation 2003/361/EC machinery — autonomous, partner, linked — is what decides whether you add whole headcounts, a proportion of them, or nothing. You need the ownership chart before you need the sector list.

This treatment is not uniform across the region, and the counter-example changes what you ask a Dutch entity's parent for. Austria's NISG 2026 does not add partner and linked enterprise data where the entity's network and information systems are independent (§25(4)), and Belgium's CCB weighs how independent the entity's systems are when it counts partner and linked enterprises (art. 3 §2). Our Dutch profile records no such carve-out. So the "but our IT is entirely separate from the parent's" argument, which is a real argument in Vienna and a factor in Brussels, is not recorded as one in The Hague.

Registration goes through MijnNCSC, and so does the change

Registration runs through the national portal, MijnNCSC. The authority is the Dutch National Cyber Security Centre, and the same portal is the front door for both the registration and the incident reports that follow it. The NCSC publishes the registration route on its Cyberbeveiligingswet pages: https://www.ncsc.nl/cyberbeveiligingswet-nis2/registreren.

Two operational points to put in the client's procedure rather than in your own head.

First, the entry is not a one-off. Changes must be filed within two weeks. A merger, a new establishment, a change of the authorised contact, a change in the services that put the entity in scope — all of it has a two-week clock, and it is the kind of clock a client misses because nobody owns it. Name an owner in the procedure document, not a department.

Second, registration is an administrative act, not a statement that the risk-management measures exist. Registering a client that has nothing in place does not create a problem that was not already there, and delaying registration until the measures are ready does not fix one. Those are two separate workstreams and they should be two separate lines in your plan.

Three clocks, and where the report lands

The reporting clocks are the directive's, unchanged:

  • early warning within 24 hours
  • full notification within 72 hours
  • final report within 30 days — the profile records it as one month after the incident notification

The Dutch specific is the routing rather than the timing. Reports go through MijnNCSC, and from there to the sector CSIRT and to the supervisor. That single fact is worth a paragraph in the client's incident procedure, because it sets expectations about who is on the other end. A Dutch client filing at hour 20 is not filing into one inbox at one agency; the submission reaches the CSIRT that handles its sector and the supervisor that supervises it, and those are different bodies with different follow-up behaviour.

Get the authorised notifiers agreed in advance and written down. Twenty-four hours is short, and it is shorter at 02:00 on a Sunday when the person who knows the portal login is on holiday. Two named people, both enrolled in the portal, is the minimum.

What to do this quarter

In order, for a Dutch client:

  1. Check art. 8 first. If the client is a ministry, province, municipality, water board or critical entity, it is essential by law and the size test is irrelevant.
  2. Get the ownership chart. Partner and linked enterprises count toward size here, so the group structure decides the size answer before the sector list does.
  3. Confirm the class yourself, on the record. Note the trigger and the reasoning, not just the conclusion.
  4. Register through MijnNCSC. The duty has applied since 15 August 2026 and the law sets no date to work back from.
  5. Assign the two-week change owner. Registration data goes stale, and the clock on updating it is short.
  6. Write the incident procedure against the real routing — 24 / 72 / 30, submitted via MijnNCSC, reaching the sector CSIRT and the supervisor — and name the people authorised to file.
  7. Get management to approve the risk-management measures on the record. The directive puts accountability on management personally; a decision with no minute behind it is not much of a decision.

The primary sources behind the Dutch profile are the consolidated law text at https://wetten.overheid.nl/BWBR0052872/2026-08-15/0, the government announcement that the law applies from 15 August 2026 at https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht, and the NCSC's registration page above. All three were checked on 17 September 2026.

If you are running this across a portfolio rather than one client, the per-country profile is the thing to keep as data rather than as memory — clausebench keeps the Dutch authority, portal, registration duty and the three clocks in one profile so the incident procedure a client receives names the right body and the right deadlines. Check it against the primary source before it goes out either way.

See what changed since your clients' policies were written

Enter up to ten client websites. Free, no sign-up, the first report in about a minute.