Dutch Cybersecurity Act (Cbw)/NIS2. A Practical Implementation
The Dutch Cybersecurity Act is now in force. Does your organization know whether it qualifies as an essential or important entity and what this means for governance, risk management, incident reporting and demonstrable compliance?
During this practical training, the Dutch Cybersecurity Act and its implementing Decree into clear responsibilities, cybersecurity measures, documentation and an actionable implementation roadmap will be explained.
From NIS2 to demonstrable compliance with the Dutch Cybersecurity Act
NIS2 is no longer only a European directive in the Netherlands. Since 15 August 2026, the Dutch Cybersecurity Act Cyberbeveiligingswet (Cbw) and its implementing Cyberbeveiligingsbesluit (Cbb) have been in force.
The legislation introduces concrete obligations for essential and important entities in relation to cybersecurity risk management, governance, incident reporting, registration, business continuity, supply-chain security and the demonstrable implementation of cybersecurity measures.
This training will help you move beyond understanding the legislation and start applying it in practice. You will learn how to translate the legal requirements into effective governance, technical and organizational measures, incident-reporting processes, appropriate evidence and a realistic implementation roadmap.
The course combines legal and regulatory explanations with practical examples, exercises and an implementation workshop. Participants will assess the potential scope of the legislation for their organization and translate the principal obligations into responsibilities, actions, documentation and priorities.