Cyberbeveiligingswet (Cbw)

The Cyberbeveiligingswet (Cbw) is the Dutch law implementing NIS2, requiring organisations to manage cyber risk and report incidents.

The Cyberbeveiligingswet (Cbw) is the Dutch law, in force since 15 August 2026, that transposes the EU NIS2 directive into national law. It replaced the Wet beveiliging netwerk- en informatiesystemen (Wbni), which implemented the earlier NIS Directive, and extends cybersecurity obligations to a much wider range of sectors - energy, transport, banking, health, digital infrastructure, public administration and more.

Organisations that fall in scope are classified as an essential entity or an important entity, depending on sector and size, and must meet a duty of care (zorgplicht) for managing cybersecurity risk, a duty to report (meldplicht) significant incidents to a competent authority and the national CSIRT, and a duty to register (registratieplicht) with the NCSC for the national entity register. Digital infrastructure providers named in the directive - including trust service providers such as QTSPs - fall within scope alongside cloud, DNS, data centre and telecom providers; supervision remains split across sectoral regulators, with the Rijksinspectie Digitale Infrastructuur (RDI) confirmed as the supervisor for digital infrastructure and trust services. The Cyberbeveiligingsbesluit, which fills in much of the practical detail, entered into force alongside the Cbw on 15 August 2026; various sector-specific ministeriele regelingen are still being finalised, so exactly how some obligations apply per sector may still change.

Frequently asked questions

Back to glossary