Dutch Cybersecurity Act (Cbw)/NIS2

During this practical training, the Dutch Cybersecurity Act and its implementing Decree into clear responsibilities, cybersecurity measures, documentation and an actionable implementation roadmap will be explained. 

Overview

Dutch Cybersecurity Act (Cbw)/NIS2. A Practical Implementation 

The Dutch Cybersecurity Act is now in force. Does your organization know whether it qualifies as an essential or important entity and what this means for governance, risk management, incident reporting and demonstrable compliance? 

During this practical training, the Dutch Cybersecurity Act and its implementing Decree into clear responsibilities, cybersecurity measures, documentation and an actionable implementation roadmap will be explained. 

From NIS2 to demonstrable compliance with the Dutch Cybersecurity Act 

NIS2 is no longer only a European directive in the Netherlands. Since 15 August 2026, the Dutch Cybersecurity Act Cyberbeveiligingswet (Cbw) and its implementing Cyberbeveiligingsbesluit (Cbb) have been in force. 

The legislation introduces concrete obligations for essential and important entities in relation to cybersecurity risk management, governance, incident reporting, registration, business continuity, supply-chain security and the demonstrable implementation of cybersecurity measures. 

This training will help you move beyond understanding the legislation and start applying it in practice. You will learn how to translate the legal requirements into effective governance, technical and organizational measures, incident-reporting processes, appropriate evidence and a realistic implementation roadmap. 

The course combines legal and regulatory explanations with practical examples, exercises and an implementation workshop. Participants will assess the potential scope of the legislation for their organization and translate the principal obligations into responsibilities, actions, documentation and priorities. 

Learning Objectives

  • Understand the relationship between NIS2, the Dutch Cybersecurity Act, the implementing Cbb and directly applicable European implementing rules. 
  • Determine whether an organization may qualify as an essential entity or an important entity, taking into account its sector, size, services, establishment and possible designation by a competent minister. 
  • Translate the statutory duty of care into appropriate and proportionate technical, operational and organizational measures. 
  • Apply the principal risk-management areas, including risk analysis, incident handling, business continuity, crisismanagement, supply-chain security, vulnerability management, cyber hygiene, training, cryptography, access control and asset management. 
  • Understand the responsibilities of the management body, including approval of cybersecurity measures and the obligation for board members to possess and maintain demonstrable knowledge and skills. 
  • Understand the registration requirements and determine which organizational and contact information must be maintained for the national register. 
  • Establish a practical reporting process for significant incidents, including an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. 
  • Understand the respective roles of the CSIRT, the competent authority and other relevant public authorities. 
  • Identify the policies, procedures, registers, test results and other evidence required to demonstrate the implementation and effectiveness of cybersecurity measures. 
  • Prepare for regulatory supervision, security scans, audits, binding instructions and other potential enforcement measures. 
  • Develop a prioritized and actionable Cbw implementation roadmap. 
  • Practical and interactive approach 

The training includes: 

  • a practical scope assessment; 
  • an essential-versus-important entity classification exercise; 
  • translation of the duty of care into concrete risk-management measures;