• Jump to main content
  • Jump to main navigation
  • Jump to widget bar
  • Jump to footer
  • Newsletter
  • About us
  • Contact
  • Nederlands

Digital Government

For Caribbean and international professionals working on government digitalisation

Logo Rijksoverheid, to the homepage

Digital Government

  • Home
  • Topics
  • All News
  • Caribbean News
Home› TopicsNIS2 Directive (Cyberbeveiligingswet, Cbw)

NIS2 Directive (Cyberbeveiligingswet, Cbw)

How did the Cyberbeveiligingswet come about?

Which government organisations are subject to the Cyberbeveiligingswet?

How can (government) organisations prepare for the Cyberbeveiligingswet?

What are the obligations under the Cyberbeveiligingswet?

Where can organisations turn for sector-specific queries, reports, or incidents?

The Cyberbeveiligingswet (Cbw) transposes the EU’s Network and Information Security Directive (NIS2) into Dutch law. The NIS2 Directive seeks to strengthen cybersecurity and resilience across critical sectors in EU member states. This improvement is necessary due to growing digital dependence and rising threats.

On 7 July, the Dutch Senate approved the Cyberbeveiligingswet (Cbw) and the Critical Entities Resilience Act (Wwke), which implements the European Critical Entities Resilience (CER) Directive. Both laws will enter into force on 15 August 2026. From then on, more than 8,000 organisations across the Netherlands, including ministries, municipalities, water authorities, provinces, independent administrative bodies and inter-municipal partnerships, will be required to comply with the new cybersecurity standards.

Although the NIS2 directive has been in force for EU member states since 16 January 2023, it does not apply directly to individual organisations in each country, as directives must first be transposed into national legislation. Accordingly, the directive is being transposed into Dutch law through the Cyberbeveiligingswet. Once adopted, the Cyberbeveiligingswet will replace the current ‘Wet beveiliging netwerk- en informatiesystemen (Wbni)’.

The Cyberbeveiligingswet imposes various obligations on organisations, subject to independent oversight. Read more about these requirements.

The legislation transposing the NIS2 directive into the Cyberbeveiligingswet consists of 3 components:

  • The Cyberbeveiligingswet bill and its accompanying Explanatory Memorandum (Memorie van Toelichting).
  • The Cyberbeveiligingsbesluit (Cbb), a general administrative order under the Cyberbeveiligingswet known as Algemene Maatregel van Bestuur (AMvB), along with its explanatory notes. The Cbb sets out further details of the Cyberbeveiligingswet, including the duty of care, registration requirements, and mandatory training for administrators. The Cbb applies to all sectors covered by the Cyberbeveiligingswet.
  • Sector-specific ministerial regulations, which provide further detail on certain obligations outlined in the Cbb. For example, the Baseline Information Security for Government (BIO) specifies the duty of care for the government sector.

Cyberbeveiligingswet (Cbw): national legislation

On 7 July 2026, the Senate approved the Cyberbeveiligingswet. This transposes the NIS2 Directive into Dutch national law. Earlier drafts of the Bill were published for public consultation, and the Council of State was consulted for its advice.

The bill and accompanying documents are available in Dutch on the House of Representatives’ website (Dutch).

Cyberbeveiligingsbesluit (AMvB Cbw)

The General Administrative Order (Algemene Maatregel van Bestuur, AMvB) under the Cyberbeveiligingswet was also published in the Government Gazette (Staatscourant) in early July 2026.

It is available here: Cyberbeveiligingsbesluit (Cbb) (Dutch). The Cbb, short for Cybersecurity Decree in Dutch, sets out further details on several of the obligations established under the Cyberbeveiligingswet.

The draft General Administrative Order (AMvB) on the bill for the Cbb was open for public consultation from 28 February to 30 March 2025. Following feedback received during the consultation, the draft text of the Cbb was revised. The updated draft was submitted to both the House of Representatives and the Senate as part of their consideration of the Bill, and was subsequently referred to the Council of State for advice.

View the draft AMvB: Cyberbeveiligingsbesluit (Cbb).

Ministerial Regulation for the Cyberbeveiligingswet (Government Sector)

Government departments are currently preparing the ministerial regulations to be made under the Cybersecurity Act. These regulations will specify the duty-of-care requirements and the threshold criteria for the incident-reporting obligation.

For the government sector, the duty of care will be based on the Baseline Information Security for Government (BIO) 2 framework.

The ministerial regulations are expected to be published shortly. They are intended to enter into force at the same time as the Cyberbeveiligingswet (Cbw) and the Cyberbeveiligingsbesluit (Cbb).

More information

Read about the origins of the Cyberbeveiligingswet, its obligations, or visit the FAQ section. If this doesn’t answer your question, please email cyberbeveiligingswet@minbzk.nl.

Tooling for the Cyberbeveiligingswet

On this page, you will find various tools to help your organisation prepare for the Cyberbeveiligingswet (Cbw), listed alphabetically.

How can organisations prepare for the Cyberbeveiligingswet?

For government organisations, compliance with the Baseline Information Security for Government (BIO) is already mandatory. Its revised version, BIO2, largely fulfils the duty of care under the Cyberbeveiligingswet (the Dutch implementation of the NIS2 Directive) Read more about 'How can organisations prepare for the Cyberbeveiligingswet?'

Which government organisations are subject to the Cyberbeveiligingswet?

Under the NIS2 directive and the Cyberbeveiligingswet, the government sector is treated as a distinct category. The following government organisations fall under the Cyberbeveiligingswet: Ministries, including their agencies and services Provinces Municipalities Water authorities, via Read more about 'Which government organisations are subject to the Cyberbeveiligingswet?'

How did the Cyberbeveiligingswet come about?

The European Union has been working on the NIS2 directive since 2020, in response to developments such as the COVID-19 pandemic, the war in Ukraine and cyber threats. 

Share this post
  •  Share via email
  •  Share on X
  •  Share on LinkedIn

Widgetruimte algemeen

NIS2 Directive (Cyberbeveiligingswet, Cbw)

  • Tooling for the Cyberbeveiligingswet
  • How did the Cyberbeveiligingswet come about?
  • Which government organisations are subject to the Cyberbeveiligingswet?
  • How can organisations prepare for the Cyberbeveiligingswet?

Last modified on: 14 July 2026.

Got a query, thought, comment, or suggestion?

If you're working on digitalising the government and got something on your mind, please share your thoughts with us.

  • Link DigiD Help Desk digid.nl/en/help
  • Link MijnOverheid / Message Box mijn.overheid.nl/about-mijnoverheid
  • Link eHerkenning Help Desk eherkenning.nl/en/contact
  • Link Message Box for Businesses english.rvo.nl/topics/contact/form

Digital Government

For Caribbean and international professionals working on government digitalisation

Stay Connected

  • Follow us on LinkedIn
  • Follow us on Mastodon
  • Follow us on X (Twitter)
  • Sign up to our Newsletter
  • Activate our RSS Feed

Nederlands

  • Deze site in het Nederlands

About this Website

  • About us
  • Contact
  • Archive
  • Copyright
  • Privacy Statement
  • Accessibility Statement
  • Report a Vulnerability
  • Sitemap