Cyberbeveiligingsbesluit

The Dutch decree under the Cyberbeveiligingswet: the duty of care worked out per measure, board training and what an incident report must contain.

The decree under the Cyberbeveiligingswet that turns that act's open duty of care into concrete requirements. It applies from 15 August 2026, the same day as the act itself, and it is the document to read when you want to know what supervision will actually ask you for.

Its chapters follow the work: the designation of the CSIRTs and the coordinator for vulnerability disclosure, the scope in relation to the European implementing regulation for the digital sectors, and then the duty of care worked out per measure - security policy, risk management, incident handling, business continuity and crisis management, supply chain security, secure acquisition and development, cyber hygiene and training, a policy on the use of cryptography, personnel security, access control and asset management. Separate chapters cover the training that board members have to follow and the data that a report of a significant incident must contain.

For a QTSP the decree mostly confirms what eIDAS already demands, but not always in the same words or on the same clock: the same incident can trigger a report to the RDI as trust service supervisor and one to the CSIRT under this decree. Map the two duties onto one process before you need them.

Frequently asked questions

Back to glossary