NIS2 and the Cybersecurity Act (Cbw) in the Netherlands: What Do Organizations Need to Do Now?

NIS2 and the Cybersecurity Act (Cbw) in the Netherlands: What Do Organizations Need to Do Now?

Introduction 

NIS2 is no longer a future concern in the Netherlands. Since 15 August 2026, the Cybersecurity Act (Cyberbeveiligingswet, Cbw) and the accompanying Cybersecurity Decree (Cyberbeveiligingsbesluit, Cbb) have been in force. This has translated the European NIS2 requirements into concrete Dutch rules for cybersecurity, risk management, and business continuity. 

The Cbw replaces the former Network and Information Systems Security Act (Wbni) and affects more than 8,000 Dutch organizations. For these organizations, NIS2 is no longer simply about preparing for future requirements: they must now be able to demonstrate that they manage cyber risks, report incidents on time, and systematically organize their digital resilience. 

But what does this mean in practice for your organization? 

We spoke with Nico Joos, trainer at NIS Institute and cybersecurity specialist. He explains what NIS2 and the Cbw entail and which steps organizations need to take to comply with the new requirements. 

What is NIS2 and why is the Directive so important? 

NIS2 is a European directive designed to increase the digital resilience of essential and important service providers. Organizations operating in sectors including healthcare, energy, digital infrastructure, government, transport, and manufacturing must implement stricter measures relating to: 

  • security measures; 
  • risk management; 
  • business continuity; 
  • incident reporting; 
  • supplier management; 
  • awareness and training; 
  • governance and management-level responsibility. 

According to Nico, the objective is clear: 

“Europe wants to increase the maturity of essential services. We need to gain better insight into risks and help organizations take the next step forward in information security.” 

The European foundation is the same for all Member States. However, because NIS2 is a directive, each Member State must transpose its requirements into national legislation. As a result, relevant differences can arise between countries. 

The Cybersecurity Act in the Netherlands is now in force 

The Cybersecurity Act (Cbw) applies to essential and important entities across 18 sectors. Organizations must assess for themselves whether they fall within its scope. This assessment depends not only on the organization’s sector and size, but also on the specific services it provides and the legal entity through which those services are delivered. 

Organizations that fall within the scope of the Cbw are subject to requirements including: 

  • registration in the national entity register; 
  • a duty of care requiring appropriate technical, operational, and organizational measures; 
  • mandatory reporting of significant incidents; 
  • management-level responsibility and training; 
  • supervision and potential enforcement. 

The accompanying Cybersecurity Decree (Cbb) further specifies the duty of care. Organizations must, for example, establish written security and risk management policies and be able to demonstrate that these policies are applied in practice. They must also maintain an up-to-date asset inventory, establish supplier security policies and incident response processes, and have tested plans for business continuity, recovery, and crisis management. 

Management responsibility has also been made more concrete. The management body must approve the cybersecurity measures. Members of management must have sufficient knowledge to assess cyber risks and cybersecurity measures and must be able to demonstrate this through a certificate of participation in appropriate training. In principle, they have two years from the date the requirement enters into force or from the date of their appointment to meet this requirement. 

The Netherlands and Belgium: the same Directive, some differences 

Belgium and the Netherlands are implementing the same NIS2 Directive. The core requirements are therefore largely comparable: risk management, incident reporting, supplier security, business continuity, and management-level responsibility. Belgium introduced its NIS2 legislation on 18 October 2024, while the Dutch Cbw has been in force since 15 August 2026. 

One important difference concerns the assessment of compliance. In Belgium, essential entities must periodically undergo a conformity assessment based on the Belgian CyberFundamentals (CyFun®) Framework or ISO/IEC 27001. For important entities, this assessment is voluntary. The Netherlands does not have a comparable general certification or conformity assessment requirement, although Dutch supervisory authorities can require security scans and independent audits. Organizations operating in both countries must therefore take different supervisory models into account. 

A standardized management system such as ISO/IEC 27001 or a practical framework such as the CyberFundamentals Framework (CyFun®) can help organizations manage risks, measures, and evidence in a structured manner. In Belgium, CyFun® can be used as a reference framework for the NIS2 conformity assessment. In the Netherlands, the framework can support implementation, but the Cbw and Cbb remain the legal framework against which compliance is assessed. 

The key steps towards NIS2 compliance 

  1. Analyze the impact on your organization

Start by determining whether your organization falls within the scope of NIS2 and document this assessment in writing. Then map the context of your organization: 

  • Which services and systems are critical? 
  • Which processes need to be adapted or documented? 
  • Where are measures still missing? 
  • What is the organization’s current maturity level? 
  • Which legal entities and suppliers are involved? 
  • Where could incidents seriously disrupt service delivery? 

This forms the basis for analyzing the gap between the current and desired situation: where does the organization stand today, and what steps are required to comply with NIS2? 

  1. Start with a roadmap or implementation plan

Organizations need a clear plan that identifies: 

  • what needs to be protected; 
  • which measures are necessary; 
  • who is responsible; 
  • which actions have priority; 
  • how the operation and effectiveness of measures will be demonstrated. 

A roadmap is therefore not a way to postpone legal obligations, but a means of addressing risks and shortcomings in a controlled manner. Critical deficiencies and obligations such as registration, incident reporting, and management responsibility require immediate attention. 

A good roadmap prevents compliance from becoming a disconnected collection of documents and technical measures. The aim is to build a coherent management system in which policies, risks, measures, responsibilities, and evaluations are interconnected. 

  1. Map risks, assets, and suppliers

NIS2 requires an all-hazards, risk-based approach. Organizations must take into account not only cyberattacks, but also human error, technical failures, supplier outages, and physical events that could affect network and information systems. 

According to Nico, this often proves challenging in practice: 

“When we ask for a list of suppliers, assets, or data flows, it turns out to be a major and difficult exercise for many companies. But you need this information to manage risks properly.” 

Among other requirements, NIS2 requires organizations to maintain a complete and up-to-date asset inventory. They must also establish supply chain security policies and periodically verify whether their direct suppliers and service providers comply with the established security requirements. 

  1. Organize incident reporting and incident response

Significant incidents must be reported to the competent CSIRT and competent authority. In most cases, the reporting procedure consists of: 

  • an early warning within 24 hours; 
  • a more detailed notification within 72 hours; 
  • a final report no later than one month after the incident notification. 

Organizations should therefore determine in advance who assesses an incident, who decides whether it is subject to mandatory reporting, and who prepares the different notifications. 

NIS2 looks beyond malicious cyberattacks alone. A technical failure, human error, or physical event can also be relevant when it affects network and information systems and the delivery of services. However, this does not mean that every physical incident or every issue involving paper documents automatically falls under the NIS2 reporting obligation. 

It is also important to distinguish between significant incidents and near misses. Reporting significant incidents is mandatory. Incidents that are not significant, cyber threats, and near misses may be reported voluntarily. The purpose of these requirements is also to enable other organizations to learn from such situations through information sharing. 

  1. Organize vulnerability management and Responsible Disclosure

NIS2 requires organizations to take vulnerabilities into account when acquiring, developing, and maintaining network and information systems. This includes responding to and disclosing vulnerabilities. 

Organizations should therefore have a process for receiving, assessing, prioritizing, resolving, and, where necessary, coordinating the disclosure of vulnerabilities. A public Coordinated Vulnerability Disclosure policy is a useful way to explain how security researchers can safely report vulnerabilities and how the organization handles these reports. 

Why NIS2 is more than a compliance obligation 

Many organizations initially focus on the legal requirements. However, the primary objective remains improving cyber resilience. A management system such as ISO/IEC 27001 or an appropriate CyberFundamentals framework can help organizations manage risks, responsibilities, and measures in a structured manner. 

Having a certificate does not automatically mean that an organization fully complies with the Cbw, but a properly implemented framework can help demonstrate compliance. No organization is completely immune to cyber incidents. 

As Nico explains: 

“The damage caused by an incident is almost always greater than the investment in preventive controls. NIS2 strengthens your organization structurally.” 

This is particularly true when implementation is approached using a standardized management system such as ISO/IEC 27001, which is internationally recognized, or the CyberFundamentals (CyFun®) Framework, which is increasingly recognized by countries across Europe as a NIS2 framework and combines components from ISO/IEC 27001, NIST, and IEC 62443. This can strengthen the confidence of customers, suppliers, and authorities, even when an incident does occur. 

As Nico puts it: 

“The question is not whether you will be attacked, but when. What matters is whether you are prepared.” 

A robust management system, clear processes, and trained employees enable an organization to respond more quickly and in a more controlled manner during an incident. The objective is not perfect security, but limiting damage and restoring critical services. 

NIS2 requires clear choices, risk-driven processes, and demonstrable measures. Now that the legislation is also in force in the Netherlands, organizations must not only make plans but also be able to demonstrate that policies are being applied, plans are being tested, and improvements are being followed up. 

Nico summarizes it as follows: 

“Only when you have carefully thought through your processes and know how to respond when something happens are you truly resilient. NIS2 helps organizations reach that level.” 

Build your own NIS2 expertise 

At NIS Institute, you can follow practical NIS2 training courses in a range of formats. Our primary format is the two-day online fast-track training: a compact and interactive course that provides you with the essential knowledge and prepares you specifically for the exam, without requiring you to set aside several full weeks for training. 

Explore our training courses and choose the format that suits you: 

  • ISO/IEC 27001 Lead Implementer: for professionals who want to plan, implement, manage, and continually improve an ISMS based on ISO/IEC 27001 within their organization. 
  • ISO/IEC 27001 Lead Auditor: for professionals who want to prepare, conduct, report on, and follow up internal or external ISMS audits based on ISO/IEC 27001. 

In addition to the two-day online fast-track format, NIS Institute also offers classroom, in-company, and customized training. 

NIS2 compliance requires more than knowledge of the Directive alone. You can therefore expand your learning path with training in areas including ISO/IEC 27001, incident management, business continuity, supply chain security, implementation, and auditing. This enables you to gradually build the knowledge required to manage risks, implement measures, and demonstrate that those measures are operating effectively. 

Tailored to organizations in the Netherlands 

Cbw Management Training 

For management board members who need to meet the knowledge requirements of the Cbw and for supervisory board members who want to strengthen their oversight of cyber risks. The training covers cyber risks, risk management processes, risk assessment, legally required security measures, and decision-making during serious incidents. 

The training can be delivered online, in-company, or customized for the entire management board. 

Need NIS2 or ISO implementation coaching? 

Training provides you with the necessary knowledge. For organizations that also need support with practical implementation, CyberMinute provides guidance from experienced specialists with hands-on expertise. 

The emphasis is on knowledge transfer. The objective is not to take over the entire implementation process, but to give your organization the knowledge and structure it needs to manage its information security independently and sustainably. 

Contact us 

NIS Institute: Training 

Website | LinkedIn 

CyberMinute: Implementation Coaching 

Website | LinkedIn 

Table of Contents