On this page, you will find the answers to frequently asked questions on provisional Computer Security and Incident Response Team (CSIRT) services for municipalities and joint municipal arrangements.
Why is the decision taking longer than expected?
Assigning a formal legal task, such as CSIRT responsibilities, to an entity outside the national government entails complex considerations. Key factors include ensuring ministerial oversight of task execution and meeting financial accountability requirements under the Government Accounting Act (Comptabiliteitswet). There are also questions about whether a new legal entity needs to be established or whether adjustments to existing structures will suffice.
Additionally, a formal advisory process with the Netherlands Court of Audit (Algemene Rekenkamer) is required to ensure proper control, accountability, and oversight of task execution and finances.
The process prioritises thoroughness over speed to ensure responsibilities and tasks are well organised. The National Cyber Security Centre’s (NCSC) provisional role until at least the end of 2026 provides the necessary time to finalise these safeguards and make a decision.
How long will the NCSC provide CSIRT services?
The NCSC will provide CSIRT services to municipalities and joint municipal arrangements (Dutch) from 15 August 2026 until at least the end of 2026. This aligns with its existing services for other government bodies under the Cyberbeveiligingswet (Cbw), the Dutch implementation of the NIS2 Directive, including ministries, independent administrative bodies, and provinces. Efforts are underway to designate a permanent CSIRT for municipalities and joint municipal arrangements for 2027 and beyond.
Which organisations are affected?
The Cbw applies to 342 municipalities and approximately 200 joint municipal arrangements; collaborations involving at least 1 municipality.
What changes for municipalities and joint municipal arrangements?
Under the Cbw, these organisations must register and report significant incidents via the NCSC portal. The NCSC will now provide CSIRT support instead of the Dutch Government Information Security Service (IBD) during this period. It’s important to note that the IBD will not have access to incident reports submitted under the Cbw. However, efforts are being made to ensure the IBD retains visibility into vulnerabilities and threats, in collaboration with the NCSC.
What services does the NCSC provide to municipalities and joint municipal arrangements?
Through the NCSC portal, municipalities and joint municipal arrangements can access a range of products and services (English), including knowledge and advisory resources. Some of these may overlap with the offerings of the IBD, though the IBD’s products often address the municipal context in greater detail. Both sets of resources will continue to coexist.
For more information about the NCSC’s services, contact the NCSC Customer and Contact Centre (English).
How will municipalities and joint municipal arrangements receive information about threats and vulnerabilities?
Municipalities and joint municipal arrangements will have access to the NCSC portal, where they can report incidents, upload network data, and access current information, analyses, and advice. The full range of NCSC services is available to this group.
What can municipalities and joint municipal arrangements expect from the IBD during this period?
The IBD continues to advise municipalities on information security and privacy, including questions about the Baseline Information Security Government (BIO), the General Data Protection Regulation (GDPR), and the requirements of the Cyber Security Act (Cbw). The IBD also assists with conducting risk assessments.
Municipalities can still contact the IBD for support during business hours (Monday to Friday, 9:00–17:00) at 070 – 204 55 11 or at info@ibdgemeenten.nl.




