Checked on September 27, 2026
NIS2 in Netherlands
How Netherlands applies the NIS2 cybersecurity directive: the national law, who supervises, and how to register and report incidents.
- Transposition status
- In force
- National law
- Cybersecurity Act (Cbw) · Cyberbeveiligingswet (Cbw) · from August 15, 2026
- Competent authority
- National Cyber Security Centre (NCSC) - registration and central reporting point (Nationaal Cyber Security Centrum)
- National CSIRT
- NCSC-NL
- Registration
- Required · Portal
Mandatory from 15 Aug 2026 via MijnNCSC (eHerkenning EH2+); changes reported within 14 days.
- Incident reporting
- Significant incidents reported to the central reporting point on MijnNCSC: early warning within 24h, then 72h notification and final report per the Directive.
- National specifics
- Adopted by the Senate on 7 July 2026 together with the Critical Entities Resilience Act (Wwke).
- Supervision is sectoral (e.g. RDI for digital infrastructure); about 8,000 organisations in 18 sectors in scope.
Where does your company stand?
The free assessment applies these national rules to your answers and scores every area of the law.
Sources
- www.rijksoverheid.nl/actueel/nieuws/2026/08/15/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-vandaag-van-kracht
- www.ncsc.nl/nieuws/cbw-en-wwke-nu-van-kracht
- www.ncsc.nl/cyberbeveiligingswet-nis2/registreren
- www.ncsc.nl/cyberbeveiligingswet-nis2/meldplicht
- www.rdi.nl/onderwerpen/digitale-weerbaarheid/cyberbeveiligingswet/registratieplicht
National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.