Dutch Cybersecurity Act (Cbw)/NIS2
Location: Live online
Duration: 1 day, from 9:00 to 17:00
Language: Dutch
Certification: Certificate of attendance + Optional PECB Pack PECB NIS 2 Foundation or PECB NIS2 Lead Implementer
Master the Practical Implementation of the Dutch Cybersecurity Act (Cbw)
This training will enable you to understand and apply the Dutch Cybersecurity Act (Cyberbeveiligingswet – Cbw) and its implementing Decree (Cbb), translating NIS2 obligations into concrete governance responsibilities, cybersecurity measures, incident-reporting processes, evidence requirements, and implementation activities.
You will learn how to determine whether the Cbw applies to your organization, assess whether you qualify as an essential or important entity, translate the statutory duty of care into practical measures, and develop a structured roadmap towards demonstrable compliance.
What you’ll learn:
- Understand the relationship between NIS2, the Dutch Cybersecurity Act (Cbw), the Cybersecurity Decree (Cbb), and applicable European implementing rules
- Determine whether your organization falls within the scope of the Cbw and whether it qualifies as an essential or important entity
- Translate the statutory duty of care into appropriate and proportionate technical, operational, and organizational cybersecurity measures
- Apply key risk-management requirements relating to incident handling, business continuity, crisis management, supply-chain security, vulnerability management, cyber hygiene, cryptography, access control, and asset management
- Understand the responsibilities of the management body, including approval of cybersecurity measures and requirements relating to cybersecurity knowledge and skills
- Understand the registration requirements and the organizational and contact information that must be maintained
- Establish a practical incident-reporting process based on the 24-hour early warning, 72-hour incident notification, and final reporting requirements
- Identify and prepare the policies, procedures, registers, test results, and other evidence required to demonstrate implementation and effectiveness
- Prepare for regulatory supervision, security scans, audits, binding instructions, and other potential enforcement measures
- Develop a prioritized and actionable Cbw implementation roadmap
- A practical and interactive course featuring explanations, exercises, a scope and classification assessment, an incident-reporting exercise, and an implementation workshop. Participants will translate legal obligations into responsibilities, measures, evidence, priorities, and a concrete roadmap.
A basic understanding of NIS2, cybersecurity, risk management, or governance is useful but not required.
What you will gain from this course:
- The ability to assess the applicability of the Dutch Cybersecurity Act to your organization
- A clear understanding of the principal obligations under the Cbw and Cbb
- A practical approach to conducting a Cbw readiness assessment or gap analysis
- A clearer governance and accountability model for the board, executive management, cybersecurity, IT, risk, and compliance functions
- A practical process for assessing, escalating, and reporting significant cybersecurity incidents
- A structured approach to documentation, evidence collection, and regulatory readiness
- A prioritized roadmap for the further implementation of the Dutch Cybersecurity Act
- A certificate of attendance confirming your participation in the training on the practical application of the Cbw and Cbb
- An optional pack including the PECB NIS 2 Directive Foundation or Lead Implementer self-study materials, access to the PECB exam, and one free retake
