Under the Cyberbeveiligingswet, the government sector is treated as a distinct category. The following government organisations are subject to the Cyberbeveiligingswet:
- Ministries, including their agencies and services
- Provinces
- Municipalities
- Water authorities, via the Ministry of Infrastructure and Water Management (IenW)
The following government bodies are subject to the Cyberbeveiligingswet only if they meet all 4 criteria for government institutions. This is assessed on a case-by-case basis:
- Independent administrative bodies (for example, independent Dutch regulators, set up by law to oversee sectors impartially), known in Dutch as Zelfstandige bestuursorganen, abbreviated as Zbo’s.
- Intergovernmental arrangements (formal arrangements between various public authorities)
Unlike other sectors, the size criterion does not apply to the government sector. Instead, specific criteria determine whether an organisation qualifies as a government institution. These criteria automatically apply to all ministries, provinces, and municipalities. For independent administrative bodies and intergovernmental arrangements, the criteria must be assessed on an individual basis.
The criteria for government institutions and their interpretation are set out in the Explanatory Memorandum to the Cyberbeveiligingswet, Section 5.1.2 (Dutch).
Which intergovernmental arrangements and independent administrative bodies does the Cbw apply to?
To determine whether intergovernmental arrangements and independent administrative bodies (Zbo’s) fall under the Cyber Security Act (Cbw), the NIS2 Directive sets out the criteria. The extent to which organisations meet these criteria varies. Those that satisfy the government body’s criteria must comply with the Act. As part of the Cbw, they should have registered on the NCSC registration portal by 15 August 2026 at the latest. This means they should also have verified whether their organisation meets the government criteria before that date.
Last year, the Ministry of the Interior and Kingdom Relations (BZK) issued an initial estimate, based on public information, identifying which Zbo’s and intergovernmental arrangements would meet the government body criteria. In December 2025, the State Secretary for the Interior and Kingdom Relations wrote to more than 220 intergovernmental arrangements and about 50 Zbo’s, asking them to confirm whether they met the government body criteria and to share their findings with the ministry. Not all organisations contacted have yet responded.
In August 2026, the Ministry sent a letter to all government organisations that fall, or may fall, under the Cbw. The letter is addressed to the organisations’ governing bodies. It highlights the law coming into force and the obligations it entails. These include the registration requirement and, for intergovernmental arrangements and Zbo’s, verification against the government criteria.
The Ministry is sending this letter to all intergovernmental arrangements and Zbo’s. With this letter, the Ministry aims to reduce the risk that any intergovernmental arrangements or Zbo’s have not assessed whether they fall under the Cbw.
An intergovernmental arrangement that meets the Cbw’s government criteria is independently subject to the Act. Municipalities connected to the arrangement are not responsible for ensuring it complies with its obligations. However, the connection remains, so it is important to always make appropriate agreements on risks, incidents, and continuity, even if an intergovernmental arrangement does not fall under the Cbw.
Criteria for government bodies
An organisation is considered a government body if it:
- Is established to meet the needs of the general interest, not to serve an industrial or commercial purpose.
- Has legal personality or is legally authorised to act on behalf of another legal entity.
- Is primarily financed by the state, regional authorities, or other public law bodies; subject to management supervision by these authorities or bodies; or has an administrative, management or supervisory body whose members are appointed by the state, regional authorities or other bodies governed by public law, with more than half of its members appointed in this way.
- Has the power to adopt administrative or regulatory decisions that affect the rights of natural or legal persons in relation to the cross-border movement of persons, goods, services or capital. This includes decisions within the meaning of the General Administrative Law Act.
For more information on how to interpret these criteria, see section 5.1.2 of the Explanatory Memorandum to the Cybersecurity Act.
Exceptions for government organisations
The Cyberbeveiligingswet excludes government institutions whose primary activities involve:
- National security
- Public safety
- Defence
- Law enforcement (including the prevention, investigation, and prosecution of criminal offences)
This means the following are exempt from the Cbw:
- Ministry of Defence
- Military Intelligence and Security Service (MIVD)
- General Intelligence and Security Service (AIVD)
- Public Prosecution Service
- Police
- Safety regions
However, the NIS2 directive requires even exempt organisations to aim for an equivalent level of resilience.
Organisations whose activities are incidentally related to national security, public safety, defence, or law enforcement fall under the directive.
Are you subject to the Cyberbeveiligingswet?
Organisations are responsible for determining whether they fall under the Cyberbeveiligingswet. Through interdepartmental coordination, a questionnaire has been developed to help organisations assess whether they fall under the Cyberbeveiligingswet (NIS2 directive) and whether they are classified as essential or important.
- Cbw (NIS2) Self-Assessment (Dutch)
- Or consult the Doorverwijsboom Cbw-organisaties (Dutch). This referral guide, created by the NCSC, provides a sector-by-sector overview of which authorities organisations can contact with questions, notifications, or incidents.




