As of today, 15 August 2026, the Cyberbeveiligingswet (Cbw) and the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten, Wwke) are in force. These laws strengthen organisations’ digital and physical resilience in the Netherlands and help ensure the continuity of essential services. For thousands of organisations, this means complying with new legal obligations.
David van Weel, Minister of Justice and Security: “Digital attacks, sabotage and other disruptions can have serious consequences for our society. The entry into force of these laws is an important step towards making organisations and the Netherlands more resilient. I urge organisations covered by these laws to take responsibility, register where required and take the necessary measures to strengthen their digital and physical resilience. This is the only way to make the Netherlands more resilient.”
Cyberbeveiligingswet
The Cyberbeveiligingswet (Cbw) implements the EU’s NIS2 Directive in the Netherlands and replaces the Network and Information Systems Security Act (Wbni). It applies to organisations providing essential or important services across 18 sectors, including energy, drinking water, digital infrastructure, healthcare, government, and transport. Organisations must determine whether they fall within the scope of the Cbw (Dutch).
Organisations covered by the Cyberbeveiligingswet (Cbw) will, among other things, be subject to:
- Registration requirement: Organisations must register (Dutch) with the National Register of Entities, managed by the National Cyber Security Centre (NCSC). Once registered, organisations can access services provided by the NCSC or the CSIRT designated for their sector. These services include receiving information from the relevant CSIRT on cyber threats and assistance with cyber incidents.
- Duty of care: Organisations must take appropriate and proportionate measures (Dutch) to manage risks to the security of their networks and information systems. They must also take measures to prevent incidents or to limit their impact.
- Incident reporting requirement: Organisations must report (Dutch) significant incidents to their CSIRT and the competent authority within the statutory deadlines. They can do so via the NCSC reporting portal. Ministerial regulations for the relevant sectors set thresholds for determining when an incident is considered significant. These thresholds may vary by sector, so organisations should consult the applicable ministerial regulation (Dutch).
- Governance responsibility: The organisation’s management board must approve measures taken under the duty of care and oversee their implementation. Board members must have sufficient knowledge to assess risks and security measures and must undertake appropriate training (Dutch).
- Supervision and enforcement: Supervisory authorities will monitor whether organisations comply with their obligations under the Cbw (Dutch). For more information on supervision, you can register for the webinar on 3 September via the registration page for webinar 6, ‘Supervision of the Cyberbeveiligingswet’ (Dutch).
Critical Entities Resilience Act
The Critical Entities Resilience Act, known in Dutch as Wet weerbaarheid kritieke entiteiten (Wwke), implements the EU’s Critical Entities Resilience (CER) Directive in the Netherlands. It aims to strengthen the resilience of critical entities against threats such as sabotage, terrorist offences, extreme weather, and other disruptions.
The Act applies to around 500 organisations in sectors including energy, transport, drinking water, healthcare, government, digital infrastructure, banking, chemicals, financial market infrastructure, wastewater, space, nuclear, flood defence and water management, meteorology, and the production, processing and distribution of food. The responsible ministry will designate organisations covered by the Wwke as critical entities.
Organisations covered by the Critical Entities Resilience Act (Wwke) will, among other things, be subject to:
- Risk assessment: Within 9 months of being designated, organisations must carry out their own risk assessment. This enables an organisation to identify risks that could disrupt the continuity of its essential services and to assess the potential impact of those risks.
- Duty of care: Within 10 months of designation, organisations must implement appropriate technical, organisational and physical measures to enhance the resilience of their essential services.
- Incident reporting requirement: Organisations must report, within 24 hours, any incident that causes or could cause a significant disruption to their essential services. The purpose of reporting is to enable the competent authority, comprising the responsible ministry and the supervisory authority, to respond to incidents and, if necessary and possible, provide support to the organisation.
- Supervision and enforcement: The competent authority monitors compliance with the Wwke.
More information
Read more about the Cyberbeveiligingswet (Dutch), the Critical Entities Resilience Act (Dutch), the obligations arising from these laws, and available resources.



