Skip to content

NIS 2 IN NETHERLANDS

Cyberbeveiligingswet (Cbw) — the national act transposing Directive (EU) 2022/2555 in Netherlands. Supervised by Nationaal Cyber Security Centrum (NCSC-NL).

DRAFT PUBLISHED

Key facts

In force
Not yet in force
National law
Cyberbeveiligingswet (Cbw)
Primary supervisor
Nationaal Cyber Security Centrum (NCSC-NL)
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Covered entities must register through the relevant sector supervisor; the central registration mechanism is being operationalised in line with NCSC-NL guidance.

Scope and national nuance

The Cyberbeveiligingswet replaces the Wbni (Wet beveiliging netwerk- en informatiesystemen) and assigns supervisory powers across multiple sector inspectorates. NCSC-NL remains the national CSIRT and CSIRT of reference for many sectors.

Sector supervisors

SectorAuthorityAcronym
EnergyRijksinspectie Digitale InfrastructuurRDI
Digital infrastructure and ICT service managementRijksinspectie Digitale InfrastructuurRDI
Drinking waterInspectie Leefomgeving en TransportILT
HealthInspectie Gezondheidszorg en JeugdIGJ
Financial servicesDe Nederlandsche BankDNB

What is specific to Netherlands

DSI Advisory — NIS 2 Programme

Move from reading the law to evidencing compliance

Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to NCSC-NL’s supervisory expectations.

NIS 2 Scorecard →Scope & gap assessment →NIS 2 reference page →