Duty of care
Organisations subject to the Cyberbeveiligingswet (Cbw) (Dutch) have a duty of care. They must take appropriate measures to ensure the continuity of their services as far as possible and to protect the information they use. Organisations determine these measures based on a risk assessment. The Cyberbeveiligingswet and its secondary legislation set out the duty of care in more detail. This includes the Cyberbeveiligingsbesluit (the General Administrative Order under the Cyberbeveiligingswet) and ministerial regulations issued by the relevant ministries for their sectors. For the government sector, the Baseline Informatiebeveiliging Overheid (BIO)2 provides further detail on the duty of care.
Registration requirement
The Cyberbeveiligingswet requires organisations covered by the Act to register (Dutch). This is known as the registration requirement. These organisations must provide information for the register of entities. Registered organisations receive information about cyber threats.
Organisations register through a portal operated by the National Cyber Security Centre (NCSC). By registering, an organisation indicates that it falls under the Cyberbeveiligingswet. Since 17 October 2024, critical entities, important entities and entities providing domain name registration services have been able to register voluntarily with the NCSC. Registration became mandatory only when the Cyberbeveiligingswet entered into force.
Many government organisations have also registered with the Register voor Overheidsorganisaties (ROO). Some of the information they have provided there is also required for registration under the Cyberbeveiligingswet. Work is therefore under way to link the ROO to the NCSC portal. This will allow information already available in the ROO to be loaded into the NCSC portal. Government organisations are responsible for keeping their information in the ROO up to date.
The registration requirement also covers all internet domains for which a government organisation is responsible. Organisations are advised to check which internet domains are already listed in the register for digital accessibility to prevent discrepancies between the 2 registrations. Government organisations can manage their own internet domains through the Register voor Internetdomeinen (RIO). Work is underway to determine how information from the RIO can also be loaded into the NCSC portal (Dutch).
Incident reporting requirement
The Cyberbeveiligingswet requires entities to report significant cyber incidents to their Computer Security Incident Response Team (CSIRT) and to their supervisory authority. To avoid duplicate reporting, entities can submit incidents via the NCSC portal. The portal automatically forwards the report to both the CSIRT and the supervisory authority. The incident reporting requirement consists of several steps:
- Early warning: the first step is to submit an early warning within 24 hours.
- Follow-up notification: the second step is to submit a follow-up notification within 72 hours. This update provides additional information about the incident, based on the initial report.
- Final report: the final step is to submit a final report no later than 1 month after the initial report. This report provides a detailed description of the incident, including its severity and consequences.
The incident reporting requirement applies to significant incidents that significantly disrupt, or could significantly disrupt, the continuity of an entity’s services. Factors that may make an incident reportable include:
- the number of people affected by the disruption;
- the duration of the disruption;
- the potential financial loss.
The ministerial regulations set out the specific thresholds for determining whether an incident qualifies as significant.
Voluntary reporting
In addition to mandatory reports of significant incidents, organisations can submit voluntary reports through the NCSC portal (Dutch). This also applies, for example, to organisations that do not fall under the Cyberbeveiligingswet. Voluntary reports help monitor sectors’ cyber resilience. The supervisory authority does not receive voluntary reports.
Management liability and training
Management liability
The NIS2 Directive includes a provision on the liability of management bodies when they fail to meet obligations under the directive. This provision does not apply to government bodies. For government leaders, neither NIS2 nor the Cyberbeveiligingswet introduces any new liability beyond what already existed. Management can be held liable for gross negligence. This means that a member of a management body may be prosecuted and convicted or fined, and may have to compensate another party for any resulting damage.
Liability is sometimes confused with responsibility, but the 2 are distinct; responsibility means being accountable for carrying out a task, achieving a result, or safeguarding something. The Cyberbeveiligingswet places responsibility for making an organisation resilient with its management. Management is responsible for decisions on network and information security and must have sufficient knowledge to make informed decisions.
Under the Cyberbeveiligingswet, the political leadership of government organisations is designated as the management body. This decision followed a proposal from the umbrella organisations during the public consultation on the Cyberbeveiligingswet. Designating political rather than administrative leadership better reflects the Municipalities Act, known as Gemeentewet in Dutch, and other relevant legislation.
Management training
The Cyberbeveiligingswet requires members of management bodies to complete training. The training helps them:
- Identify security risks to network and information systems.
- Assess risk management measures.
- Assess the consequences of those risks and measures.
The Cyberbeveiligingsbesluit (Cbb), the General Administrative Order (AMvB) under the Cyberbeveiligingswet, sets out further rules on this training. These include the subjects to be covered and the certification requirements. The rules aim to help organisations provide appropriate training in ways that suit their circumstances.
Organisations can either purchase this training from an external provider or deliver it themselves. Different levels of government are collaborating to develop an appropriate approach to training for government leaders. From 15 August 2026, the date the Cyberbeveiligingswet entered into force, management bodies have 2 years to meet this requirement.
Supervision
Organisations covered by the Cyberbeveiligingswet are subject to mandatory supervision. The Cyberbeveiligingswet requires an independent supervisory authority to monitor compliance with the directive’s obligations, including the duty of care and incident-reporting requirements.
For the government sector, except for water authorities, the Dutch Authority for Digital Infrastructure (RDI) is the designated supervisory authority. For water authorities, the Human Environment and Transport Inspectorate (ILT) is the designated supervisory authority.
To supervise the Cyberbeveiligingswet in the government sector, the RDI uses existing accountability structures. These include the ENSIA methodology (Eenduidige Normatiek Single Information Audit) for municipalities and information security assessments for central government organisations. This approach aims to minimise the administrative burden of supervision.




