The Dutch Cybersecurity Act, the Cyberbeveiligingswet, implements the European NIS2 Directive. It requires organisations providing an essential or important service in eighteen designated sectors to take appropriate risk management measures, to report significant incidents and to register with the government.
Legal basis
The Act implements Directive (EU) 2022/2555 and entered into force on 15 August 2026, together with the Critical Entities Resilience Act. It affects an estimated eight thousand organisations in sectors including energy, drinking water, digital infrastructure, healthcare, transport and public administration. The directive imposes a tiered reporting duty: an early warning within 24 hours of becoming aware, a fuller incident notification within 72 hours and a final report within one month. Unlike the previous regime there is no longer designation of individual organisations; the sector combined with the size of the undertaking determines whether you are caught. Board members are themselves responsible for approving the measures and must undergo training.
How it works in practice
The first step is self-assessment: does your organisation fall within one of the sectors, and if so, is it essential or important? That distinction chiefly determines supervision, which for essential entities may take place without any particular cause. The duty of care follows: risk analysis, incident handling, business continuity, supply chain, access control and encryption. The supply chain obligation reaches suppliers who are not themselves caught by the Act, because the requirements are passed on through contracts.
Where it goes wrong
Organisations too readily assume they fall outside the scope because they are not critical infrastructure; the sector list is broad and includes waste management, postal services, food and digital providers. A second error is treating the reporting duty as an IT matter, when the 24-hour deadline is only achievable with a decision line agreed in advance up to board level. Third, the pass-through to suppliers is generally not addressed in existing contracts.
Related terms
The reporting duty runs alongside that for a personal data breach, with its own deadline and a different regulator, and feeds into the SaaS agreement and the data processing agreement.
Would you like to know whether the Act applies to you and what that means? Our IT lawyers carry out the assessment with you.

