Dutch Cybersecurity Act (Cbw)/NIS2

During this practical training, the Dutch Cybersecurity Act and its implementing Decree into clear responsibilities, cybersecurity measures, documentation and an actionable implementation roadmap will be explained. 

Overview

Dutch Cybersecurity Act (Cbw)/NIS2. A Practical Implementation 

The Dutch Cybersecurity Act is now in force. Does your organization know whether it qualifies as an essential or important entity and what this means for governance, risk management, incident reporting and demonstrable compliance? 

During this practical training, the Dutch Cybersecurity Act and its implementing Decree into clear responsibilities, cybersecurity measures, documentation and an actionable implementation roadmap will be explained. 

From NIS2 to demonstrable compliance with the Dutch Cybersecurity Act 

NIS2 is no longer only a European directive in the Netherlands. Since 15 August 2026, the Dutch Cybersecurity Act Cyberbeveiligingswet (Cbw) and its implementing Cyberbeveiligingsbesluit (Cbb) have been in force. 

The legislation introduces concrete obligations for essential and important entities in relation to cybersecurity risk management, governance, incident reporting, registration, business continuity, supply-chain security and the demonstrable implementation of cybersecurity measures. 

This training will help you move beyond understanding the legislation and start applying it in practice. You will learn how to translate the legal requirements into effective governance, technical and organizational measures, incident-reporting processes, appropriate evidence and a realistic implementation roadmap. 

The course combines legal and regulatory explanations with practical examples, exercises and an implementation workshop. Participants will assess the potential scope of the legislation for their organization and translate the principal obligations into responsibilities, actions, documentation and priorities. 

Learning Objectives

  • Understand the relationship between NIS2, the Dutch Cybersecurity Act, the implementing Cbb and directly applicable European implementing rules. 
  • Determine whether an organization may qualify as an essential entity or an important entity, taking into account its sector, size, services, establishment and possible designation by a competent minister. 
  • Translate the statutory duty of care into appropriate and proportionate technical, operational and organizational measures. 
  • Apply the principal risk-management areas, including risk analysis, incident handling, business continuity, crisismanagement, supply-chain security, vulnerability management, cyber hygiene, training, cryptography, access control and asset management. 
  • Understand the responsibilities of the management body, including approval of cybersecurity measures and the obligation for board members to possess and maintain demonstrable knowledge and skills. 
  • Understand the registration requirements and determine which organizational and contact information must be maintained for the national register. 
  • Establish a practical reporting process for significant incidents, including an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. 
  • Understand the respective roles of the CSIRT, the competent authority and other relevant public authorities. 
  • Identify the policies, procedures, registers, test results and other evidence required to demonstrate the implementation and effectiveness of cybersecurity measures. 
  • Prepare for regulatory supervision, security scans, audits, binding instructions and other potential enforcement measures. 
  • Develop a prioritized and actionable Cbw implementation roadmap. 
  • Practical and interactive approach 

The training includes: 

  • a practical scope assessment; 
  • an essential-versus-important entity classification exercise; 
  • translation of the duty of care into concrete risk-management measures; 
  • an incident-reporting exercise based on the 24- and 72-hour deadlines; 
  • an analysis of management-body responsibilities; 
  • an implementation-roadmap workshop. 
  • A basic understanding of NIS2, cybersecurity, risk management or governance is useful but not required. 

What you will gain from this course 

  • The ability to assess the potential applicability of the Dutch Cybersecurity Act to your organization. 
  • A clear understanding of the principal obligations under the Cbw and Cbb. 
  • A practical approach to conducting a readiness assessment or gap analysis. 
  • A clearer governance and accountability model for the board, executive management, cybersecurity, IT, risk and compliance functions. 
  • A practical process for assessing, escalating and reporting significant incidents. 
  • A structured approach to documentation, evidence collection and regulatory readiness. 
  • A prioritized roadmap for the further implementation of the Dutch Cybersecurity Act. 
  • A certificate of attendance confirming participation in the training on the practical application of the Cbw and Cbb. 
  • An optional pack including PECB NIS 2 Directive Foundation or Lead Implementer self-study materials, access to the PECB exam and one free retake. 

Program

The training includes: 

  • a practical scope assessment; 
  • an essential-versus-important entity classification exercise; 
  • translation of the duty of care into concrete risk-management measures; 
  • an incident-reporting exercise based on the 24- and 72-hour deadlines; 
  • an analysis of management-body responsibilities; 
  • an implementation-roadmap workshop. 
  • A basic understanding of NIS2, cybersecurity, risk management or governance is useful but not required. 

This training course is intended for

This course is intended for professionals involved in the interpretation, governance or implementation of the Dutch Cybersecurity Act, including: 

board members and executives, CISOs, information security officers, risk and compliance managers, legal professionals, internal auditors, IT and OT managers, business continuity professionals, consultants and NIS2 implementation leads. 

Turn the Dutch Cybersecurity Act into an actionable plan 

Understand which obligations apply to your organization, identify your priorities and develop a practical roadmap towards demonstrable compliance with the Cbw. 

Exam & Certificate

  • A certificate of attendance confirming participation in the training on the practical application of the Cbw and Cbb. 
  • An optional PECB package with self-study materials for PECB NIS 2 Directive Foundation, PECB NIST Cybersecurity Framework Foundation, PECB ISO/IEC 27001 Foundation, or PECB Cybersecurity Foundation, including access to the corresponding PECB exam and one free exam retake.

Make your choice

Training Calendar