How did the Cyberbeveiligingswet come about?
Which government organisations are subject to the Cyberbeveiligingswet?
How can (government) organisations prepare for the Cyberbeveiligingswet?
What obligations does the Cyberbeveiligingswet impose?
Where can organisations turn for sector-specific queries, reports, or incidents?
The Cyberbeveiligingswet (Cbw) transposes the EU’s Network and Information Security Directive (NIS2) into Dutch law. The NIS2 Directive aims to improve cybersecurity and resilience across critical sectors in EU Member States. This is necessary because of growing reliance on digital technologies and increasing cyber threats.
Although the NIS2 Directive has been in force for EU Member States since 16 January 2023, it does not apply directly to individual organisations in those countries. EU directives must be transposed into national law. The Netherlands has therefore transposed the directive into Dutch law through the Cyberbeveiligingswet (Cbw).
The Cbw and the Critical Entities Resilience Act (Wwke) entered into force on 15 August 2026. From that date, more than 8,000 organisations in the Netherlands became subject to new cybersecurity obligations. The Cbw replaces the Network and Information Systems Security Act (Wbni).
The legislative process involved several steps. View the timeline of its development (Dutch).
Components of the Cbw
The Cbw consists of 3 components:
- The Cyberbeveiligingswet (Dutch) and its accompanying Explanatory Memorandum (Dutch).
- The Cybersecurity Decree (Cbb), the General Administrative Order (AMvB) under the Cbw, along with its Explanatory Notes. The Cbb provides further detail on provisions of the Cbw, including the duty of care, registration requirement and training requirement for board members. The Cbb applies to all sectors covered by the Cbw.
- Sector-specific ministerial regulations (Dutch), which provide further details on certain obligations under the Cbb. For the government sector, for example, Baseline Information Security for Government (BIO)2 provides further detail on the duty of care.
Cyberbeveiligingswet requirements at a glance
- Organisations covered by the Cybersecurity Act (Cbw) have a duty of care. This means they must take appropriate measures to ensure the continuity of their services as far as possible and protect the information they use. Read more about the duty of care.
- The Cybersecurity Act requires organisations covered by the Act to register. This is known as the registration requirement. Read more about the registration requirement.
- The Act requires entities to report significant cyber incidents to their Computer Security Incident Response Team (CSIRT) and their supervisory authority. Read more about the incident reporting requirement.
Find out more
Read more about the origins of the Cyberbeveiligingswet, the obligations imposed by the Cyberbeveiligingswet or visit the frequently asked questions.
Can’t find the answer to your question? Please email cyberbeveiligingswet@minbzk.nl.




