This page answers frequently asked questions about provisional Computer Security and Incident Response Team (CSIRT) services for municipalities and intergovernmental arrangements.
Why is the decision taking longer than expected?
Assigning a formal legal task, such as CSIRT responsibilities, to an entity outside the national government entails complex considerations. Key factors include ensuring ministerial oversight of task execution and meeting financial accountability requirements under the Government Accounting Act (Comptabiliteitswet).
There are also questions about whether a new legal entity needs to be established or whether adjustments to existing structures will suffice. Additionally, a formal advisory process with the Netherlands Court of Audit (Algemene Rekenkamer) is required to ensure proper control, accountability, and oversight of task execution and financial management.
The process prioritises thoroughness over speed to ensure responsibilities and tasks are well organised. The National Cyber Security Centre’s (NCSC) provisional role until at least the end of 2026 provides sufficient time to finalise these safeguards and make a decision.
How long will the NCSC provide CSIRT services?
The NCSC will provide CSIRT services to municipalities and intergovernmental arrangements (Dutch) from 15 August 2026 until at least the end of 2026. This aligns with its existing services for other government bodies under the Cyberbeveiligingswet (Cbw), the Dutch implementation of the NIS2 Directive, including ministries, independent administrative bodies, and provinces. Efforts are underway to designate a permanent CSIRT for municipalities and intergovernmental arrangements from 2027 onward.
Which organisations are affected?
The Cbw applies to 342 municipalities and approximately 200 intergovernmental arrangements, including collaborations involving at least 1 municipality.
What changes for municipalities and intergovernmental arrangements?
Under the Cbw, these organisations must register and report significant incidents via the NCSC portal. During this period, the NCSC will provide CSIRT support instead of the Dutch Government Information Security Service (IBD). The IBD will not have access to incident reports submitted under the Cbw. However, efforts are being made to ensure the IBD retains visibility into vulnerabilities and threats, in collaboration with the NCSC.
What services does the NCSC provide to municipalities and intergovernmental arrangements?
Through the NCSC portal, municipalities and intergovernmental arrangements can access a range of products and services (English), including knowledge and advisory resources. Some of these may overlap with the IBD’s offerings, though the IBD’s products often address the municipal context in greater detail. Both sets of resources will continue to coexist.
For more information about the NCSC’s services, contact the NCSC Customer and Contact Centre (English).
How will municipalities and intergovernmental arrangements receive information about threats and vulnerabilities?
Municipalities and intergovernmental arrangements will have access to the NCSC portal, where they can report incidents, upload network data, and access current information, analyses, and advice. The full range of NCSC services is available to this group.
What can municipalities and intergovernmental arrangements expect from the IBD during this period?
The IBD continues to advise municipalities on information security and privacy, including questions about the Baseline Information Security Government (BIO), the General Data Protection Regulation (GDPR), and the requirements of the Cyber Security Act (Cbw). The IBD also assists with conducting risk assessments.
Municipalities can still contact the IBD for support during business hours (Monday to Friday, 9:00–17:00) at 070-204 55 11 or info@ibdgemeenten.nl.




