The Cybersecurity Regulation for the public sector (Dutch) has been published in the Dutch Government Gazette (Staatscourant). This marks the final step before the Cyberbeveiligingswet (Cbw), the Dutch implementation of the NIS2 Directive, takes effect on 15 August 2026. The regulation sets out the duty of care and reporting thresholds for government organisations.
This ministerial regulation applies to all government bodies subject to the Cbw. Following a public consultation in late 2025, stakeholder input has been incorporated into the final version. With its publication in the Staatscourant, the regulation will become legally binding for government institutions from 15 August 2026.
Duty of care and reporting obligations under the Cbw
The regulation further elaborates on the duty of care, making the Baseline Information Security for Government (BIO2) mandatory. It also requires government organisations to apply ISO information security standards (27001 and 27002). Additionally, the regulation sets out the criteria for reporting obligations, clarifying when an incident is considered significant. Under the Cbw, government organisations must report such incidents.
Final step before Cbw takes effect
With this publication, the final step has been taken to bring the Cbw and its underlying regulations into force on 15 August. From that date, organisations in the Netherlands, including government bodies, must comply with new obligations to strengthen cybersecurity. These include a legal duty of care, a reporting obligation, and a registration requirement, all subject to independent supervision. Given the growing threats to digital security, these measures are urgently needed.
Regarding the registration obligation, it is crucial that government organisations register as soon as possible (Dutch), and no later than 15 August. The Ministry of the Interior and Kingdom Relations (BZK) urges any organisation that has not yet registered to do so immediately.




