Checked on September 27, 2026

NIS2 in Netherlands

How Netherlands applies the NIS2 cybersecurity directive: the national law, who supervises, and how to register and report incidents.

Transposition status
In force
National law
Cybersecurity Act (Cbw) · Cyberbeveiligingswet (Cbw) · from August 15, 2026
National CSIRT
NCSC-NL
Registration
Required · Portal

Mandatory from 15 Aug 2026 via MijnNCSC (eHerkenning EH2+); changes reported within 14 days.

Incident reporting
Significant incidents reported to the central reporting point on MijnNCSC: early warning within 24h, then 72h notification and final report per the Directive.
National specifics
  • Adopted by the Senate on 7 July 2026 together with the Critical Entities Resilience Act (Wwke).
  • Supervision is sectoral (e.g. RDI for digital infrastructure); about 8,000 organisations in 18 sectors in scope.

Where does your company stand?

The free assessment applies these national rules to your answers and scores every area of the law.

Sources

National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.

NIS2 in other countries

NIS2 in Netherlands: national law, authority and registration | Parendum