Under the NIS2 directive and the Cyberbeveiligingswet, the government sector is treated as a distinct category. The following government organisations fall under the Cyberbeveiligingswet:
- Ministries, including their agencies and services
- Provinces
- Municipalities
- Water authorities, via the Ministry of Infrastructure and Water Management (IenW)
The following government bodies are subject to the Cyberbeveiligingswet only if they meet all 4 criteria for government institutions. This is assessed on a case-by-case basis:
- Independent administrative bodies (for example, independent Dutch regulators, set up by law to oversee sectors impartially)
- Joint arrangements (formal arrangements between public authorities)
Unlike other sectors, the size criterion does not apply to the government sector. Instead, specific criteria determine whether an organisation qualifies as a government institution. These criteria automatically apply to all ministries, provinces, and municipalities. For independent administrative bodies and joint (municipal) arrangements, it must be determined on an individual basis whether the criteria are met.
The criteria for government institutions and their interpretation can be found in the Explanatory Memorandum to the Cyberbeveiligingswet, Section 5.1.2 (Dutch).
Which joint municipal arrangements and independent administrative bodies does the Cbw apply to?
To determine whether joint municipal arrangements and independent administrative bodies (zbo’s) are subject to the Cyber Security Act (Cbw), the criteria set by the NIS2 Directive must be assessed. The extent to which organisations meet these criteria varies. Those that satisfy the government body criteria must comply with the Act. As part of the Cbw, they must register on the NCSC registration portal by 15 August 2026 at the latest. This means they must also verify whether their organisation meets the government criteria before that date.
Last year, the Ministry of the Interior and Kingdom Relations (BZK) made an initial estimate, based on public information, of which zbo’s and joint municipal arrangements would meet the government body criteria. In December 2025, the State Secretary for the Interior and Kingdom Relations wrote to over 220 joint municipal arrangements and around 50 zbo’s, asking them to confirm whether they met the government body criteria and to share their findings with the ministry. Not all organisations that were contacted have responded yet.
In August 2026, the ministry will send a letter to the directors of all government organisations that may be subject to the Cbw. The letter will highlight the Act’s entry into force and the associated obligations, including the registration requirement. For joint municipal arrangements and zbo’s, this also includes verifying the government criteria. The letter will be sent to all joint municipal arrangements and zbo’s to reduce the likelihood of any such organisations failing to determine whether they fall under the Cbw.
A joint municipal arrangement that meets the Cbw’s government criteria is independently subject to the Act. Municipalities connected to the arrangement are not responsible for ensuring it complies with its obligations. However, the connection remains, so it is important to always make appropriate agreements on risks, incidents, and continuity, even if a joint municipal arrangement does not fall under the Cbw.
What defines an organisation as a government institution?
Organisations are considered government institutions if they meet the following 4 criteria:
- Established to meet the needs of the general interest and not to serve an industrial or commercial purpose.
- Have legal personality or are legally authorised to act on behalf of another legal entity.
- Primarily financed by the state, regional authorities, or other public law bodies; subject to management supervision by these authorities or bodies; or have a governing, executive, or supervisory body whose members are appointed by the state, regional authorities, or other public law bodies in more than 50% of cases.
- Duty to issue administrative or regulatory decisions that affect the rights of natural or legal persons in relation to the cross-border movement of persons, goods, services, or capital (e.g., decisions under the General Administrative Law Act)?
Exceptions for government organisations
The Cyberbeveiligingswet excludes government institutions whose primary activities involve:
- National security
- Public safety
- Defence
- Law enforcement (including the prevention, investigation, and prosecution of criminal offences)
This means the following are exempt from the NIS2 directive:
- Ministry of Defence
- Military Intelligence and Security Service (MIVD)
- General Intelligence and Security Service (AIVD)
- Public Prosecution Service
- Police
- Safety regions
However, the NIS2 directive does require that even exempt organisations aim for an equivalent level of resilience.
Organisations whose activities are incidentally related to national security, public safety, defence, or law enforcement fall under the directive.
Are you subject to the Cyberbeveiligingswet?
Organisations are responsible for determining whether they are covered by the Cyberbeveiligingswet. Based on interdepartmental coordination, a questionnaire has been developed to help organisations assess whether they fall under the Cyberbeveiligingswet (NIS2 directive) and whether they are classified as essential or important.
- Cbw (NIS2) Self-Assessment (Dutch)
- Or consult the Registration Obligation Flowchart (Dutch), created by the NCSC.




