• Jump to main content
  • Jump to main navigation
  • Jump to footer
  • Newsletter
  • About us
  • Contact
  • Nederlands

Digital Government

For Caribbean and international professionals working on government digitalisation

Logo Rijksoverheid, to the homepage

Digital Government

  • Home
  • Topics
  • All News
  • Caribbean News
Home›News›Cybersecurity Regulation for public sector in Government Gazette

Cybersecurity Regulation for public sector in Government Gazette

NIS2 Directive (Cyberbeveiligingswet, Cbw) 7 August 2026

The Cybersecurity Regulation for the public sector (Dutch) has been published in the Dutch Government Gazette (Staatscourant). This marks the final step before the Cyberbeveiligingswet (Cbw), the Dutch implementation of the NIS2 Directive, takes effect on 15 August 2026. The regulation sets out the duty of care and reporting thresholds for government organisations.

This ministerial regulation applies to all government bodies subject to the Cbw. Following a public consultation in late 2025, stakeholder input has been incorporated into the final version. With its publication in the Staatscourant, the regulation will become legally binding for government institutions from 15 August 2026.

Duty of care and reporting obligations under the Cbw

The regulation further elaborates on the duty of care, making the Baseline Information Security for Government (BIO2) mandatory. It also requires government organisations to apply ISO information security standards (27001 and 27002). Additionally, the regulation sets out the criteria for reporting obligations, clarifying when an incident is considered significant. Under the Cbw, government organisations must report such incidents.

Final step before Cbw takes effect

With this publication, the final step has been taken to bring the Cbw and its underlying regulations into force on 15 August. From that date, organisations in the Netherlands, including government bodies, must comply with new obligations to strengthen cybersecurity. These include a legal duty of care, a reporting obligation, and a registration requirement, all subject to independent supervision. Given the growing threats to digital security, these measures are urgently needed.

Regarding the registration obligation, it is crucial that government organisations register as soon as possible (Dutch), and no later than 15 August. The Ministry of the Interior and Kingdom Relations (BZK) urges any organisation that has not yet registered to do so immediately.

Related links

  • NIS2 Directive (Cyberbeveiligingswet, Cbw)
This field is for validation purposes and should be left unchanged.
Was this page helpful?
Your feedback is greatly appreciated.

Share this post
  •  Share via email
  •  Share on X
  •  Share on LinkedIn

Sign up for our newsletter

Got a query, thought, comment, or suggestion?

If you're working on digitalising the government and got something on your mind, please share your thoughts with us.

  • Link DigiD Help Desk digid.nl/en/help
  • Link MijnOverheid / Message Box mijn.overheid.nl/about-mijnoverheid
  • Link eHerkenning Help Desk eherkenning.nl/en/contact
  • Link Message Box for Businesses english.rvo.nl/topics/contact/form

Digital Government

For Caribbean and international professionals working on government digitalisation

Stay Connected

  • Follow us on LinkedIn
  • Follow us on Mastodon
  • Follow us on X (Twitter)
  • Sign up to our Newsletter
  • Activate our RSS Feed

Nederlands

  • Deze site in het Nederlands

About this Website

  • About us
  • Contact
  • Archive
  • Copyright
  • Privacy Statement
  • Accessibility Statement
  • Report a Vulnerability
  • Sitemap