NIS2 · National implementation
NIS2 in Netherlands
The Netherlands transposes NIS2 through the Cyberbeveiligingswet (Cbw). The law has been adopted but is not yet in force. The Netherlands was among the member states referred to the CJEU for the delay.
- National law
- Cyberbeveiligingswet (Cbw)
- Cybersecurity Act
- Status
- Adopted, not yet in force
- In force
- Adopted, expected in force during 2026
- Authority
- RDI and sector regulators; NCSC-NL as CSIRT
Supervision
The Dutch model splits roles: the NCSC-NL acts as national CSIRT, while supervision is distributed across sector regulators, with the RDI (Rijksinspectie Digitale Infrastructuur) covering digital infrastructure and several other sectors.
What is specific to the Netherlands
Dutch communication is organised around two duties: the zorgplicht (duty of care, the Article 21 measures) and the meldplicht (duty to report). Government guidance and the official regelhulp (self-assessment tool) use this framing, and Dutch entities should too. The Cbw is accompanied by a separate implementation of CER (Wet weerbaarheid kritieke entiteiten), and the two share supervision infrastructure. Registration will run through the designated portal once the law commences.
Official sources
Primary references: the national statute book at wetten.overheid.nl and the national cybersecurity authority at www.ncsc.nl.
NIS2 in Netherlands: frequently asked questions
Last reviewed:
Related reading
Definitions
