NIS2 · National implementation

NIS2 in Netherlands

The Netherlands transposes NIS2 through the Cyberbeveiligingswet (Cbw). The law has been adopted but is not yet in force. The Netherlands was among the member states referred to the CJEU for the delay.

National law
Cyberbeveiligingswet (Cbw)
Cybersecurity Act
Status
Adopted, not yet in force
In force
Adopted, expected in force during 2026
Authority
RDI and sector regulators; NCSC-NL as CSIRT

Supervision

The Dutch model splits roles: the NCSC-NL acts as national CSIRT, while supervision is distributed across sector regulators, with the RDI (Rijksinspectie Digitale Infrastructuur) covering digital infrastructure and several other sectors.

What is specific to the Netherlands

Dutch communication is organised around two duties: the zorgplicht (duty of care, the Article 21 measures) and the meldplicht (duty to report). Government guidance and the official regelhulp (self-assessment tool) use this framing, and Dutch entities should too. The Cbw is accompanied by a separate implementation of CER (Wet weerbaarheid kritieke entiteiten), and the two share supervision infrastructure. Registration will run through the designated portal once the law commences.

Official sources

Primary references: the national statute book at wetten.overheid.nl and the national cybersecurity authority at www.ncsc.nl.

NIS2 in Netherlands: frequently asked questions

Last reviewed:

Related reading

All 27 EU member states