Netherlands NIS2 2026: The Cbw Is Live, No Grace Period

CT
CyberOrbit Team
19 min read
Share

The Dutch Cyberbeveiligingswet has been in force since 15 August 2026, and unlike most transpositions of Directive (EU) 2022/2555 in the EU, it arrived without a general transition period. If you are in scope, your obligations are not approaching. They are already overdue.

Netherlands NIS2 Arrived Without a Runway

The asymmetry is the story. In July 2026 the European Commission referred the Netherlands, alongside Ireland, Spain and France, to the Court of Justice for failing to notify full transposition of NIS2. The Senate had adopted the Cyberbeveiligingswet on 7 July, days before that referral landed, and the law entered into force on 15 August 2026. Six weeks from adoption to obligation.

8,000+
Dutch organisations now subject to the Cyberbeveiligingswet
Registration, duty of care, incident reporting, and board governance obligations all went live on 15 August 2026, with no phased rollout.
⚠️No transition period
Unlike Italy (18-month runway for listed entities) and Austria (NISG 2026, 1 October 2026), the Netherlands transposed with no general grace period. Germany did the same in December 2025, so the pattern is now established: the later a member state transposes, the less runway it hands you. If the Netherlands is your supervising state, your obligations were live on 15 August. Higher education is the one carve-out, and it is dealt with separately below.

Most compliance calendars are built around a date you work towards. This one has no runway to plan against, which changes what "getting started" means: you are not preparing for a deadline, you are closing a gap that is already open. Clyde & Co's read on the Dutch text confirms there was no general transition period attached to any of the four obligation streams.

Four Cyberbeveiligingswet Obligations That Went Live at Once

Four obligations landed on the same morning, and only one of them is quick. The other three run on entirely different clocks: a quarter of work for the duty of care, a 24-hour clock for reporting, a board cycle for governance. That is why treating 15 August as a single deadline misreads the problem. They are four separate programmes that happened to start on the same day.

Register in the entity register via Mijn.NCSC.nl. Required of all in-scope entities from 15 August. Registration is how your supervisor identifies you and how the CSIRT reaches you, and failing to register is itself a breach rather than a delay. It does not put you beyond supervision: an unregistered entity that is in scope is simply a non-compliant one.

The trap is that registration feels like compliance. It is an address record. Nobody has assessed anything about you when you finish it, and the thing that will be assessed is not written into the Act you just registered under.

Where the Cyberbeveiligingswet Hides the Testing Requirement

The Cyberbeveiligingswet is a framework act. The substance of the zorgplicht is delegated downward to the Cyberbeveiligingsbesluit, the general administrative order beneath it, with ministerial regulations adding sector-specific detail below that. If you read the Act looking for what to actually do, you will not find it there. This is the single most common reason Dutch entities conclude, wrongly, that the Cbw asks little of them.

ℹ️What the decree requires
The Cyberbeveiligingsbesluit (Stb. 2026, 189) requires essential and important entities to periodically evaluate the effectiveness of the measures they have taken and their effects in practice, to record the result in writing, and to adjust the measures where the evaluation shows adjustment is needed. Neither the Act nor the decree uses the phrase "penetration test", but a policy document alone does not evidence that anything was evaluated.

The word doing the work is evaluate. An evaluation has to describe something that was actually run, against named systems, on a known date, by someone identifiable. The mechanics of how Article 21(2)(f) of the directive produces that obligation are covered in our guide to NIS2 penetration testing requirements. The Dutch point is narrower: the evaluation record is what your supervisor reads first, so it is worth being blunt about which artefacts survive that reading and which do not.

Pros
  • Dated third-party external assessment with named scope and signatory
  • Documented findings with reproduction detail
  • Retest confirmation showing remediation
  • Board minute recording review of results
Cons
  • A policy document or security framework attestation
  • A vulnerability scanner dashboard screenshot
  • An undated, unattributed internal spreadsheet
  • Statements such as "we use a WAF"

Nothing in that second list is worthless, and a supervisor may well want to see your policies. Those artefacts just answer a different question. Each describes an intention or a tool rather than an evaluation of whether the measure works, which is the thing the decree asks you to record.

How strictly that line gets drawn depends on which supervisor is reading your file, and in the Netherlands that is not one authority.

See what your external surface exposes, mapped to the controls it touches.

Run a free External Security Check →

Who Supervises Netherlands NIS2 Compliance

There is no single NIS2 regulator in the Netherlands. Sector determines supervisor, and sector also determines which CSIRT receives your incident report: the NCSC is the national CSIRT, but the Act designates sectoral CSIRTs too, and you file through one portal that routes the report to the right one alongside your supervisor. The practical consequence: your supervisor's inspection style, not the statute, decides what "documented" means in your case. Read their published guidance before you design the evidence file, not after.

Who supervises digital infrastructure, managed service providers and trust services?
The Rijksinspectie Digitale Infrastructuur (RDI), which covers digital infrastructure (including DNS providers, TLD registries, trust service providers, IXPs, cloud, data centres and CDNs) and ICT service management (managed service providers and managed security service providers). First step: check rdi.nl for the registration pathway for your sector.
Who supervises energy entities under the Cyberbeveiligingswet?
The RDI, covering electricity, district heating and cooling, gas, oil and hydrogen. This surprises people who expect the ACM, which regulates the energy market but is not the Cbw supervisor for it. First step: confirm which energy sub-sector your entity sits in, because the annex entry drives your classification.
Who supervises transport entities under the Cyberbeveiligingswet?
The Human Environment and Transport Inspectorate (ILT), covering aviation, maritime, rail and road. ILT also supervises the water boards. First step: verify whether you meet the threshold as an essential or important entity.
Who supervises health sector entities under the Cyberbeveiligingswet?
The Healthcare and Youth Inspectorate (IGJ). Note the split between supervisor and CSIRT here: incident reports route to Z-CERT, the designated CSIRT for Dutch healthcare, while IGJ supervises compliance. First step: determine whether you are in scope as a care provider, a reference laboratory, a pharmaceutical manufacturer or a medical device manufacturer, because the decision tree differs.
Who supervises banking and financial market infrastructure?
De Nederlandsche Bank (DNB) and the Authority for the Financial Markets (AFM). First step: establish what DORA leaves for the Cbw to govern. DORA is lex specialis under Article 4 of NIS2, so for financial entities its ICT risk-management and testing requirements displace the equivalent Cbw duties rather than stacking on top of them. See the DORA penetration testing guide, then confirm the residual position with DNB or the AFM.
Who supervises public administration entities?
The RDI, for central, provincial and municipal government alike. BZK is the policy department for the sector, which is a different thing from being its supervisor, and the Interprovinciaal Overleg is a coordinating body rather than a regulator. First step: check the NCSC decision tree (doorverwijsboom) for your sector at ncsc.nl.

Whichever authority you answer to, they will apply one of two supervision models, and the difference is not the one most people assume.

Essential or Important: Same Duty, Different Enforcement

Both classes owe the same duty of care. The measures do not differ. What differs is supervision and cost of failure. Essential entities face ex ante supervision, so an inspection can arrive without an incident preceding it. Important entities face ex post supervision, which is reactive. Fine ceilings run to €10 million or 2% of worldwide annual turnover for essential entities, and €7 million or 1.4% for important ones, whichever is higher.

🎯Key Takeaway
Important entities are supervised reactively. That is not leniency: it means your evidence file gets requested on your worst week, after an incident rather than before one.

The reconstruction problem is what turns that into real exposure. Assembling a year of evidence is a two-week job when nothing is on fire and an impossible one during incident response. Financial entities run their testing programme under DORA rather than the Cbw, since DORA is lex specialis, and connected-product makers answer to the Cyber Resilience Act as well, so for some organisations the same evidence has to satisfy more than one reader. All of which argues for building the file on a quiet week.

What to Do in the Next 30 Days

Two of these are fast, four are not, and the ordering matters more than the speed. The sequence below front-loads the cheap items so that the expensive one, evidence, starts its clock on day one rather than day twenty.

1
Determine your scope and entity class. Two tests apply together: which annex your sector sits in, and your size. Broadly, medium-sized entities (from 50 staff, or turnover and balance sheet above €10M) are in scope, and large entities (from 250 staff, or turnover above €50M and balance sheet above €43M) in a highly critical sector are essential rather than important. Size alone does not decide it, the annex does, and some entities are caught by designation regardless of size. Jurisdiction is its own question: for cloud, data centre, CDN, DNS, TLD, managed service and managed security providers, NIS2 Article 26 points to the member state of your main EU establishment rather than to every country you sell into, so confirm whether the Netherlands is actually your supervising state before you register here.
2
Register via Mijn.NCSC.nl. Registration is mandatory and is the fastest of the four obligations. It puts you on your supervisor's list and gives the CSIRT a route to you, so do it first, and note that not registering does not make you invisible to supervision.
3
Stand up the 24-hour reporting runbook. Name the on-call owners, define what constitutes a significant incident in your context, and document the Mijn.NCSC.nl notification path, including who has portal access out of hours. An undocumented process is not a process.
4
Run an external assessment of your internet-facing estate. Establish a dated baseline of what is visible and reachable from outside your network. On its own this is one input rather than the whole evaluation, but it is the input most entities are missing, and it is the part that dates fastest.
5
File the written effectiveness evaluation. Scope, date, method, named assessor, findings with severity, remediation record. This document is what a supervisor asks for, so build it now rather than when the letter arrives.
6
Get board sign-off. This is where personal liability attaches, so it is not a formality. The management body must formally review and approve the measures and the effectiveness evaluation. A signed board minute is the record.

One thing that list cannot enforce for you: name individual on-call owners in step three, not a team mailbox. A clock that starts the moment someone in your organisation becomes aware of the incident does not wait for a shared inbox to be opened on Monday morning.

Steps four through six all produce the same deliverable, which is a single file you can hand over. A free external security check is the cheapest way to see what step four will be pointed at, though reconnaissance is not the evidence itself. Here is what the file needs to contain before it is worth filing.

Scope statement naming systems and boundaries tested
Date and duration of the assessment
Named third-party assessor (company and individual signatory)
Findings with severity ratings and reproduction detail
Remediation record for critical and high findings
Retest confirmation showing findings are closed
Board minute recording review and sign-off

Three of those seven lines depend on someone outside your organisation putting their name to a document, which raises a fair question about what that document can honestly claim.

Where an Independent Signed Report Fits

What the report gives you

An independent, dated, signed external assessment can serve as underlying evidence for a written effectiveness evaluation, for the part of your estate it actually covers. Be precise about what that means. It is one exhibit in the evaluation, not the evaluation itself, and it evidences the systems named in its scope statement and nothing outside them. The evaluation is still yours to write, and it has to speak to the measures you implemented under the decree, most of which no external test touches.

What the report does supply is the set of properties that make an exhibit readable as evidence rather than as an assertion: a named scope, a date, a stated method, and an identifiable assessor who can be asked about it. The decree does not enumerate those four. They are what a supervisor looks for when deciding whether the record in front of them describes something that was genuinely run.

What the report does not give you

The limits deserve equal plainness. It is external-surface testing, not an internal network engagement, so it says nothing about lateral movement once someone is inside, about your identity estate, or about the OT and back-office systems a supervisor may care about most. It covers the classes that reward systematic breadth across everything internet-facing, and not the novel business-logic abuse that still needs a human sitting with your application for a week. It is also not a legal opinion on whether you are an essential or an important entity, and that classification drives your supervision model, so take it to counsel rather than to a testing vendor. There is also a Dutch-specific limit that matters more here than in any other member state.

📝CCV Keurmerk Pentesten
The Netherlands has its own pentest quality mark, the CCV Keurmerk Pentesten, whose version 2.0 certification scheme took effect on 1 April 2024 with a one-year transition for existing certificate holders. It certifies the testing provider, not your compliance, and it is named often enough in Dutch public-sector and regulated-sector tenders that you should assume procurement will ask. A CyberOrbit external assessment does not carry CCV Keurmerk certification, and it is better that you read that here than discover it at contract stage.

Where the Keurmerk applies, it generally reaches you through a tender requirement or a sector procurement policy rather than through the duty of care itself, so settle which of the two you are answering to before you shortlist anyone. If it is a tender that names the Keurmerk, engage a certified provider. If it is the zorgplicht, what the evaluation record has to show is a named scope, a date, a method, an identifiable signatory and reproduction detail, and an independent signed report carries those.

Frequently Asked Questions

When did the Dutch Cybersecurity Act (Cyberbeveiligingswet) enter into force?
15 August 2026. The Senate adopted it on 7 July 2026 and it took effect roughly six weeks later, replacing the Wbni as the Dutch implementation of the NIS2 directive.
Is there a grace period or transition period for NIS2 in the Netherlands?
No general one. Obligations applied in full from 15 August 2026, unlike Italy's 18-month runway for listed entities. Higher education is the exception, and it works differently from a grace period: the sector is brought into scope through a separate ministerial regulation with a later start date (March 2027 as intended at the time of writing), from which registration and incident reporting apply, while the duty of care follows three years after that, in 2029. If you are a Dutch university or university of applied sciences, confirm the current dates with your ministry rather than relying on this paragraph, because that instrument is still moving.
Does the Cyberbeveiligingswet require penetration testing?
Not by name, and neither the Act nor the decree names a test type or a cadence. The Cyberbeveiligingsbesluit requires you to periodically evaluate whether your measures are effective in practice and to record the result in writing. Choosing the method is yours, but the evaluation has to describe something that was actually performed and that could have returned a negative result, which is why document review alone does not carry it and why most entities land on some form of security testing.
Who supervises NIS2 compliance in the Netherlands?
Your sector decides. The RDI has the widest remit, covering digital infrastructure, ICT service management (MSPs and MSSPs), energy, post and courier, space and government bodies at central, provincial and municipal level. ILT covers transport and the water boards, IGJ covers health, DNB and the AFM cover the financial sector, and the NVWA covers food. Incident reporting is a separate axis: the NCSC is the national CSIRT and runs the single reporting portal, but sectoral CSIRTs are designated too, such as Z-CERT for healthcare, and your report is routed to the CSIRT for your sector and to your supervisor.
What are the NIS2 fines in the Netherlands for essential and important entities?
Essential entities face up to €10 million or 2% of worldwide annual turnover, whichever is higher. Important entities face up to €7 million or 1.4%. Management can also be held personally liable.
How do I register my organisation under the Cyberbeveiligingswet?
Registration runs through the entity register at Mijn.NCSC.nl: your details, your sector, and your contact points. It is mandatory for all in-scope entities and has applied since 15 August 2026. The same portal is where you file incident reports, so getting an account and named portal users in place is also step one of your reporting runbook. Not registering is a breach in its own right, and it does not exempt you from the duty of care or from supervision.
What is the difference between the Cyberbeveiligingswet and the Cyberbeveiligingsbesluit?
The Cyberbeveiligingswet is the framework act: it establishes who is in scope, who supervises, and what the obligation categories are. The Cyberbeveiligingsbesluit is the general administrative order beneath it, and it specifies the actual security measures, including the requirement to periodically evaluate their effectiveness and record the result in writing. Ministerial regulations add sector-specific detail below that.
What evidence does a Dutch supervisor expect for the NIS2 duty of care?
The decree requires a written record of a periodic effectiveness evaluation and does not prescribe its contents, so supervisory expectations will develop through published guidance rather than through the text. What makes such a record readable as evidence is consistent across regimes: scope, date, method, who performed it, findings with severity, a remediation record, and documented review by the management body. A policy document, a framework attestation, or a scanner dashboard screenshot does not carry it on its own, because none of them evidence that anything was evaluated. Check your own supervisor's guidance, since they are the ones who will read the file.

Build the Cbw Evidence File Before You Are Asked for It

The Cyberbeveiligingswet gave you no runway, but it also gave you no prescribed test, no named methodology, and no fixed cadence. What it gave you is an outcome and an expectation that you can show your working. For most entities in scope, the honest gap is not that the wrong test was run. It is that no dated, signed, independent record exists at all, so there is nothing for a written effectiveness evaluation to point at.

That record takes weeks to assemble and minutes to be asked for. Start with the free external check to see what is reachable from outside your network today, then scope the signed work against the systems that actually carry your essential or important service.

An independent, signed, audit-ready penetration test in 48 hours. You set the targets, our platform scopes and runs the assessment, and you select which completed assessment goes for certified sign-off, reviewed and signed by a certified security professional. The report is structured so a Dutch sector supervisor can consume it: named scope, methodology, severity ratings, reproduction detail and retest confirmation. Pricing is published, so the board sees a number rather than a quote cycle.
Scope your Cbw effectiveness evaluation

Sources

Last verified: 26 August 2026. Dutch implementation is still moving, particularly the sector-specific ministerial regulations. If something here has changed, tell us and we will correct it and credit the correction.

This post is general information about Dutch cybersecurity regulation and security testing. It is not legal, audit, or compliance advice, and it is not a substitute for the current text of the Cyberbeveiligingswet or the Cyberbeveiligingsbesluit. Confirm your entity classification, your sector supervisor, and your obligations with that supervisor and with qualified legal counsel. Dates and figures describe the position as at the date above.

The security writing, weekly

New posts as they land: findings from real assessments, what the regulatory changes actually mean, and the occasional teardown.

Privacy