On 15 August 2026, the day had come for the Cybersecurity Act (Cyberbeveiligingswet, “Cbw”) to enter into force. After a long run-up, the Netherlands has implemented the NIS2 Directive (“NIS2”), which aims to realize a high common level of cybersecurity across the European internal market. The Cbw will definitely impact the Dutch corporate sector, as it applies to an estimated 8,100 Dutch organisations, plus government bodies. This group is larger than under the former Security of Network and Information Systems Act (“Wbni”), which was an implementation of the EU NIS1 Directive and has now been repealed. The Cbw sets stricter requirements on this group and introduces stricter supervisory and enforcement powers, including a more severe penalty regime for breaches. Cybersecurity is an increasingly non-committal matter and is treated as a strategic entrepreneurial risk, as well as being a public responsibility besides a private one.
Applicability of the Cybersecurity Act
The substance of the Cybersecurity Act has hardly changed since the bill was submitted to the Dutch Lower House of Parliament. First and foremost, the Act requires organisations to assess whether they are subject to it because they qualify as an essential or important entity. They may qualify by operation of law (see Articles 8 and 12 Cbw), often when they carry out activities within one of the sectors listed in the two annexes to the Cybersecurity Act, and reach the relevant threshold of size. Entities may also fall under the Act based on certain criteria (see Articles 9, 10, 11 and 13 Cbw), in which case they will be identified as such by the various ministries designated as competent authorities for the sectors within their policy responsibility. This will happen, for example, if the entity is the sole provider in the Netherlands of a service that is essential for the maintenance of critical societal or economic activities, or if disruption of the service provided by the entity could have a significant impact on public safety, public security or public health. Entities have to be assessed individually, which may be challenging if organisations consist of multiple entities of various sizes, located across countries. Helpful resources are available: the Manual for Complex Business Models of the National Cyber Security Centre (“NCSC”) and the User Guide to the SME Definition of the European Commission.
Main obligations
If entities fall under the Cbw, they have several obligations. First of all, they have to register themselves. This has been the main focus of entities in the run-up to the entry into force. Registrations should be made on the NCSC’s central registration portal via mijn.ncsc.nl. Organisations that have not yet registered themselves are urged to do so as soon as possible, because this obligation to register has existed since 15 August and there is no official grace period for late applications.
The NCSC is also the central recipient of the mandatory reports of significant security incidents. The sectoral competent authorities are also informed of these reports. It is determined at a sectoral level which incidents are ‘significant’. The thresholds for entities in the digital sectors are specified in a European implementing regulation (the “Implementing Regulation”). ‘Significant’ may mean that a service is unavailable during a certain period (20 or 30 minutes), or that the integrity, confidentiality or authenticity of data is compromised by a suspected malicious act. The threshold values for the other sectors will be determined in ministerial regulations (the “Ministerial Regulations”). Several of these threshold values have been published and have entered into force together with the Cybersecurity Act and the underlying Cybersecurity Decree (in Dutch: “Cbb”) . See the regulations for, inter alia, economic affairs and climate (Regeling cyberbeveiliging EZK) , infrastructure and water management (Cyberbeveiligingsregeling IenW) , agriculture, fisheries, food security and nature (Regeling cyberbeveiliging LVVN) , and resilience of critical entities in the energy sector (Weerbaarheid kritieke entiteiten energiesector) . Ministerial Regulations are expected to follow for the remaining sectors too.
At the heart of the Cybersecurity Act and underlying regulations lies the duty of care: to take appropriate and proportionate technical, operational and organisational measures to (i) manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services; (ii) to prevent incidents; and (iii) to prevent or minimise the impact of incidents on recipients of their services and on other services. Section 21 subsections 1-3 of the Cybersecurity Act sets out the minimum these measures should entail, and Sections 5-19 of the Cybersecurity Decree and the Ministerial Regulations elaborate this in more detail. The digital sectors are governed by the Implementing Regulation.
Contracting about supply chain security
In the coming period, company lawyers will be confronted with several elements of this duty of care, including the security of the entity’s supply chain. Section 10 (2) Cbb requires entities to assess and to check periodically whether their direct suppliers (including service providers) meet certain security requirements. Entities may assess this, for example, on the basis of certification of their suppliers or via clauses in supply agreements. An entity will have to assess periodically whether its direct supplier still meets its cybersecurity requirements. If it does not, the entity will have to decide whether additional measures can be taken to mitigate the risks. Such measures may include the renegotiating of contracts, concluding a supplementary contract, or switching suppliers.
There are a few steps that precede the conclusion of contracts. The security requirements that the entity passes on to its supplier originate from Section 7 Cbb, which stipulates that the mandatory risk management policy for the security of the entity’s network and information systems must be applied demonstrably. This policy must include at least a method for risk management methodology and risk acceptance criteria. Based on this policy, processes and procedures will be determined and applied demonstrably for risk analysis, risk assessment, and risk treatment. Based on the risk analysis, the entity will prepare an overview of risks, leading to security requirements and measures to secure its systems structurally and demonstrably.
It is these last-mentioned security requirements the supplier should be checked by the entity to meet, which are not to be confused with the security requirements a supplier itself has to meet under NIS2, as implemented in one of the Member States. Since IT services are often contracted and provided internationally, it is good to be aware that suppliers under the jurisdiction of certain countries are not yet obliged to take the measures from NIS2, and that this impacts the risk profile of those suppliers. While the Netherlands implemented NIS2 rather late, countries like France and Spain – and even Ireland, which houses many European headquarters of global IT suppliers – have not adopted an implementation act yet.
Entities should also make arrangements within their supply chain in case the scenario unfolds that the government demands them to keep out elements of network and information systems, products or services of specific suppliers. Ministers have the room to do this if they consider this necessary to control security risks. The statutory basis for this is a Dutch regulation contained in Section 21a Cbw, supplementary to NIS2. However, fending off products and services for cybersecurity reasons is not unique. A case is currently pending before the European Court of Justice about the refusal of Estonian authorities to permit an Estonian telecom provider to use Huawei equipment. Furthermore, the European Commission proposal for a revised Cybersecurity Act (“CSA2”) contains an EU-wide framework for securing ICT supply chains in sectors covered by the NIS2 Directive. This would allow the European Commission to restrict or prohibit the use, installation or integration of ICT components (including products and services) from suppliers identified as being high-risk.
Governance obligations
Another element of the duty of care that company lawyers will have to deal with – whether or not via the directors whom they advise – is the governance obligations under the Cybersecurity Act. Cybersecurity is not only the job of technical and IT staff. The Cbw requires the involvement of both a cybersecurity expert (such as the CISO) and a director. In the scope of the integral risk management of an organisation, the board approves measures and supervises their performance. The board must have and keep up to date specific knowledge and skills, follow trainings, and obtain the associated certificates.
For company lawyers, these obligations come down to the way in which cybersecurity is embedded within the organisation. The active involvement of directors requires the express determination of roles, responsibilities and powers around cybersecurity, clearly outlined reporting lines between the board, the CISO, risk management and audit staff, and for cyber risks to become a recurring subject the organisation's regular governance and risk management processes. Since the Cybersecurity Act insists on demonstrability, many organisations will not only have to change the substance of their cybersecurity measures, but also their way of internal reporting on, accounting for and supervising those measures. This places the company lawyer at the interface of compliance, corporate law, internal governance and information security. In practice, company lawyers will often help drafting and assessing the documentation that supports this governance. This may be board regulations, mandates of the CISO, internal policy papers, reporting structures, and decision-making processes by which the board can demonstrate that it fulfils its statutory tasks.