1. Introduction
Like many other countries, the Netherlands lags behind in implementing European Directive 2022/2555 (“NIS2”). The deadline expired in October 2024, but it was not until June 2025 that the Lower House of Parliament received a proposal for a Cybersecurity Act (Cyberbeveiligingswet, “Cbw”). This act and the underlying regulations are now expected to enter into force only in quarter 2 of 2026. For companies not yet familiar with this legislation, or that have postponed measures pending the legislative process, the time for action has now come. It will take some time for companies that are subject to the act to assess whether their existing security is sufficient, whether additional measures are necessary, and whether existing contracts with customers and suppliers need amending. Companies that are not subject to the Cbw but are indirectly involved as suppliers of a regulated company must also take action now.
Below, we will discuss two of the most relevant obligations from NIS2 law, namely the obligation to take cybersecurity risk-management measures, including corporate governance measures (the “duty of care”), and the obligation to report significant cyber incidents both to the competent authority and to the Cyber Security Incident Response Team (CSIRT) (the double “reporting obligation”). We do this in light of the scope of application and the jurisdiction under NIS2.
2. Scope of application and jurisdiction
NIS2 distinguishes between essential and important entities, but the significance of this distinction is relatively small and concerns mainly supervision and enforcement. The sector in which an enterprise operates is more decisive to the substance of the obligations. For entities within the digital infrastructure sector, ICT service management (business-to-business) or digital providers, the duty of care and the reporting obligation are partly defined by an implementing regulation (the “Implementing Regulation”). As far as essential and important entities are beyond the scope of the Implementing Regulation, (solely) the duty of care and the reporting obligation as transposed from NIS2 into national law apply. In the Netherlands, this is the Cybersecurity Act, the Cybersecurity Decree and ministerial regulations derived from these. These regulations are adopted by the various ministries that have been designated as competent authorities for the sectors within their policy responsibility.
It must be noted here that an entity may fall within several sectors, and must consequently take into account the effect of the duty of care and the reporting obligation under both the Implementation Regulation and the full-scale Dutch implementation. An example of this is an entity that is both a cloud computing services provider and a provider of internet exchange points. This entity has specific duties of care and reporting duties both under the Implementing Regulation – in its capacity of cloud computing services provider – and under the underlying Cyber Security Decree (“Cbb”) – in its capacity of internet exchange point.
The same goes for the jurisdiction of the Dutch competent authority, as set out in Section 4 of the Cbw. For example, an electricity company domiciled in the Netherlands that simultaneously offers managed services with a head office in Germany, will be under the scope of application of the Cbw. The same goes for a cloud computing services provider that has its head office in France and provides public telecommunications networks or services in the Netherlands.
From a broader perspective, there are still many questions as to how NIS2 and the implementation legislation will be applied in practice to a complex corporate structure, especially if a company is operating internationally. In any case, within a group of companies several entities may qualify as an essential or important entity, and must therefore comply with the obligations from the Cbw.
3. Duty of care and governance
A regulated entity has to take the risk-management measures as described in Section 21 Cbw: “take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services”, and “measures to prevent or minimise the impact of incidents on recipients of their services and on other services.” It is important that entities are aware that the elaboration of these measures in Section 21 lid 3 Cbw, which is a verbatim transposition of the list of measures from Article 21 (2) NIS2, still offers a general framework. In any case, the entities must take the measures as described in Sections 6 through 19 Cbb, but in addition, Sections 21 (5) Cbw and 20 Cbb provide a ground for more specific rules on a sectoral level. At present, the substance of these more specific rules is not yet clear. It is understandable and indeed desirable that each (sub)sector will be subject to different rules. The management system standard NEN7510 is a good example. This standard will play a big role in the elaboration of the duty of care within the health care sector, but has no relevance to other sectors.
As far as entities are within the scope of the Implementing Regulation, the annex mentions which risk-management measures must be taken. The Implementing Regulation often uses the principle of comply or explain: if an entity believes a risk-management measure not to be appropriate, applicable or feasible, the entity has to document this in a comprehensible manner. To provide more explanation, the EU Agency for Cybersecurity ENISA has published a Technical Implementation Guidance, which can be found here: https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance. Here too, the provisions on the duty of care in the Cbw remain relevant to the entities to which the Implementing Regulation applies. Although the measures from the Implementing Regulation supersede Articles 6 through 17 and 19 of the Cbb, they must be read in coherence with the Cbw. The rules still to be determined under Section 21 (5) Cbw and Section 20 Cbb may also apply for these entities.
A remarkable addition to the Cbw and the Cbb compared to the previous consultation versions published is the option for a specialist minister to make entities keep out parts of network and information systems, products or services of specific suppliers, if the minister considers this necessary for managing security risks. Section 18 Cbb offers a specific regulation for this, but Section 21 (5) Cbw has the same purpose, according to the Explanatory Memorandum. Such a regulation can be explained by the strong growth of the number of countries that develop and deploy offensive cyber programs to pursue their political targets. However, the regulation is formulated in general terms, which allows ministers much room to give it substance. Due to its drastic nature, it is doubtful whether the eventual versions of the Cbw and Cbb will include this option.
Entities also have to take measures at governance level as part of their duty of care. These measures are elaborated in Section 24 Cbw. Among other things, the board must approve the risk management measures taken in the scope of the duty of care, must have and keep up to date specific knowledge and skills, and must follow trainings and obtain the associated certificates (as elaborated in Sections 21-23 Cbb). A useful improvement compared to the consultation version of the Cbw is a sharper definition of the term “board” regarding these obligations. This term refers to the board that is charged with the management of the legal entity, as set out in Sections 2:129 DCC (for the public limited company) and 2:239 DCC (for the private company). In the event that an essential entity or important entity has both a board and a supervisory board, the governance obligations (at least those pursuant to the Cbw) are only incumbent on the board.
4. Reporting obligation
Besides the duty of care, the reporting obligation is the main obligation under NIS2. It is essential that entities report significant incidents to both the CSIRT and the competent authority. The Ministry of Justice and Security is designated as CSIRT, and in practice this role will be fulfilled by the National Cyber Security Centre (NCSC). On a sectoral level, a different CSIRT may be designated. At present, it is expected that a separate CSIRT will be designated for the health care sector (Z-CERT), municipalities (IBD) and water boards (CERT-Watermanagement).
The text of NIS2 only determines in general terms when an incident is significant: it concerns an incident that either “has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned”, or “has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage”. As far as entities are within the scope of the Implementation Regulation, these thresholds are specified in Articles 3 through 14 of the Regulation. An incident is significant, for example, if trade secrets leak out or may leak out, or if it may cause a “direct financial loss” of the lesser of more than EUR 500,000 or more than 5% of the total annual turnover of the relevant entity in the preceding financial year. For the other sectors, Section 24 (1) Cbb provides that the threshold values at sectoral levels will be determined in ministerial regulations. As opposed to the duty of care, the specialist ministers do not establish additional threshold values for the reporting obligation.
The report must be made in phases to a reporting centre. The entity must first give an early warning and follow this up with updates. The Cbb foresees that more information will be given in the early warning than prescribed under Article 23 (3) NIS2. For example, the presumed time of commencement of the significant incident must also be reported, and if possible a description must be given of the nature and the appreciable effects of the incident at that time, a prognosis of the recovery time, and the measures intended or taken by the entity to limit the consequences of the significant incident or to prevent its repetition. With this information, the CSIRT and the competent authority can estimate better whether they wish to respond and how they can respond. In addition, this information allows a better estimate of potential cascading effects to other entities, for example.
Given the various options that the NIS2, Cbw and Cbb offer to elaborate the duty of care and reporting obligation in more detail, it is recommended to keep abreast of regulatory developments.