In recent years, developments such as the COVID-19 pandemic, the war in Ukraine, cyber threats, and the impacts of climate change have increasingly strained society’s and the economy’s security. In response, the European Union has been working on the NIS2 directive since 2020. The directive aims to enhance the digital and economic resilience of EU member states.
The NIS2 directive focuses on risks to network and information systems, including cybersecurity risks. It aims to promote greater harmonisation across Europe and raise cybersecurity standards among businesses and organisations. The NIS2 directive succeeds the first NIS directive, which was transposed into Dutch law in 2016 as the ‘Wet beveiliging netwerk- en informatiesystemen (Wbni)’.
The NIS2 directive is transposed into Dutch legislation through the Cyberbeveiligingswet (Cbw). Now in force, the Cyberbeveiligingswet replaces the Wbni, which implemented the first NIS directive.
At the same time as work was underway to implement the NIS2 Directive, the Critical Entities Resilience (CER) Directive was also being implemented. The CER Directive focuses on protecting organisations against physical risks, such as the effects of (terrorist) crimes, sabotage and natural disasters.
In the Netherlands, the CER Directive has been implemented through the Wet weerbaarheid kritieke entiteiten (Wwke) (Dutch). This is supplemented by a General Administrative Order, the Besluit weerbaarheid kritieke entiteiten (Dutch).




