On 15 August 2026, the Cyberbeveiligingswet (Cbw) entered into force, including for the public sector. Art de Blaauw, Director of CIO Rijk and Digitalisation Policy, is pleased with this milestone: “It’s remarkable that we’ve reached this point, after years of hard work and intensive consultations.” He is clear that the Cyberbeveiligingswet is much needed because it ends the voluntary approach to digital security.
And that is crucial. According to De Blaauw, if there’s one thing we’ve learned in recent years, it’s that cybersecurity is not a luxury but a ‘lifeline for our society’. “We still see too many situations and incidents that make it painfully clear we need to do more. Think of ransomware attacks on local authorities, the Public Prosecution Service going offline, or disruptions to critical infrastructure that threaten our economy and security. As a government, we have to set an example, and we do not always do that as well as we should. With the Cyberbeveiligingswet, the ‘voluntary’ approach is over.”
The urgency of proactive action
De Blaauw believes the Cyberbeveiligingswet is long overdue: “We find ourselves in a new geopolitical landscape where attacks by state actors as part of hybrid warfare are a reality. Moreover, cybercrime costs the Dutch economy billions of euros every year.”
To illustrate, he cites the Log4j vulnerability in 2021, which had major consequences, including for government organisations. “This case demonstrated how important it is to be able to respond quickly. And how crucial it is for organisations to know what they have in place, who is responsible, and where they depend on other parties. The Cyberbeveiligingswet forces us to answer these questions in advance, rather than afterwards.” With the rise of AI, this is becoming even more urgent. “Attackers can use AI to carry out their cyberattacks faster, more efficiently, and on a larger scale.”
A higher level of maturity
The law also calls for greater digital security maturity. According to De Blaauw, this inevitably brings uncertainty. “We were used to clear checklists with measures. Done! But the Cyberbeveiligingswet goes further. It requires us to continuously adapt our measures through our management systems and risk-based approach. It’s not just about complying with the rules; we need to feel intrinsically responsible for being genuinely secure.”
In his view, this means learning to deal with complexity and accepting that there is no ready-made answer for every situation. “We need to become more flexible and better able to respond to new threats. Cybersecurity is a dynamic process in which we have to continually adjust our approach.”
Take responsibility
Turning to the law itself, organisations, including government bodies, are subject to an explicit duty of care under the Cyberbeveiligingswet, as well as incident reporting and registration requirements. Board members must also undergo training and play a key role in ensuring successful implementation.
But De Blaauw is clear: the Act is no magic bullet. “It’s a framework that forces us to think about security in a structured way and to take responsibility. To make it a success, we need to work together. Cybersecurity is not the responsibility of 1 department or 1 person. It involves every level of our organisations.” From procurement to archiving, from support staff to directors and suppliers. He singles out 1 role in particular: “The CISO has an advisory role in this transition. I expect boards to make effective use of the CISO’s expertise.”
4 tips for implementing the Cyberbeveiligingswet
For this kind of structural collaboration, De Blaauw sees the Cyberbeveiligingswet as “a solid foundation that we can build on across government to make the public sector more digitally resilient. The Act is not an endpoint but a wake-up call. Digital security should really be just as much a matter of course as the physical security measures we put in place. You wouldn’t build a bridge without making sure its supporting structure is sound.” He offers professionals 4 tips:
- Take responsibility, whether you are a board member, line manager or CISO. Make sure cybersecurity is high on the agenda.
- Invest in collaboration with colleagues, suppliers and supervisory authorities.
- Use the available support, such as from the NCSC.
- Keep learning and improving. Cybersecurity is not a destination but an ongoing journey.
A digitally resilient government
De Blaauw looks ahead with determination: “I see a government that is more digitally resilient and handles citizens’ data responsibly. A government that inspires trust. One that is ready for tomorrow’s challenges. And that starts now, with the Cyberbeveiligingswet entering into force. It also rests on the commitment of all government professionals who work daily to achieve this. We truly can’t wait any longer, because the future of our digital security is in our hands.”
Symposium
More information
Now that the Cyberbeveiligingswet is officially in force, we’re also looking ahead. For more information, keep an eye on the Digital Government file regularly. If you’re looking for tips and support, explore the Cbw tools and resources page.



