NIS 2 — Netherlands
NIS 2 IN NETHERLANDS
Cyberbeveiligingswet (Cbw) — the national act transposing Directive (EU) 2022/2555 in Netherlands. Supervised by Nationaal Cyber Security Centrum (NCSC-NL).
DRAFT PUBLISHED
Key facts
In force
Not yet in force
National law
Primary supervisor
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Covered entities must register through the relevant sector supervisor; the central registration mechanism is being operationalised in line with NCSC-NL guidance.
Scope and national nuance
The Cyberbeveiligingswet replaces the Wbni (Wet beveiliging netwerk- en informatiesystemen) and assigns supervisory powers across multiple sector inspectorates. NCSC-NL remains the national CSIRT and CSIRT of reference for many sectors.
Sector supervisors
| Sector | Authority | Acronym |
|---|---|---|
| Energy | Rijksinspectie Digitale Infrastructuur | RDI |
| Digital infrastructure and ICT service management | Rijksinspectie Digitale Infrastructuur | RDI |
| Drinking water | Inspectie Leefomgeving en Transport | ILT |
| Health | Inspectie Gezondheidszorg en Jeugd | IGJ |
| Financial services | De Nederlandsche Bank | DNB |
What is specific to Netherlands
- The Netherlands distributes supervisory authority across multiple inspectorates — RDI for digital infrastructure and energy, ILT for drinking water and transport, IGJ for healthcare, DNB for financial — so a covered entity's regulator depends entirely on sector.
- NCSC-NL changes role: under the new law it becomes the CSIRT of reference and shares information widely with covered entities, rather than the narrower role it had under the Wbni.
- The new law merges the NCSC and the Digital Trust Center (DTC) functions into one extended NCSC, giving small and medium-sized covered entities a single information source.
- The CSIRT for digital service providers (CSIRT-DSP) function is consolidated into NCSC-NL rather than sitting separately.
DSI Advisory — NIS 2 Programme
Move from reading the law to evidencing compliance
Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to NCSC-NL’s supervisory expectations.