Registering with the NCSC under the Cyberbeveiligingswet: step by step

Published · Updated

Every organisation that falls under the Cyberbeveiligingswet (Cbw), the Dutch NIS2 act, has to register in the national register of essential and important entities. You do this yourself, online at mijn.ncsc.nl. The duty is set out in articles 43 and 44 of the Act and in article 27 of the Cyberbeveiligingsbesluit, and has applied since 15 August 2026, with no transition period.

Two misunderstandings come up often. Registration does not go through your sector supervisor but through the NCSC, which runs the register on behalf of the Minister of Justice and Security. And it is not a one-off form: you report changes within two weeks. This article covers what to arrange beforehand, the steps the portal takes you through and what is expected of you afterwards.

Who has to register?

Every essential and important entity, and in addition organisations that provide domain name registration services. Nobody invites you to do so: you determine yourself whether the Act applies to you. If you are unsure, read Does the Cyberbeveiligingswet apply to your organisation? first. The NCSC also points to the RDI's NIS2 self-assessment.

If you also operate in other EU member states, bear in mind that, according to the NCSC, the directive does not provide for registering in all member states at once.

What to arrange beforehand

Most of the work comes before you log in. Arrange these four things first.

  • Login with eHerkenning at level EH2+, with an authorisation to register on behalf of your organisation. That authorisation is linked to the Chamber of Commerce (KvK) number of the registering organisation and is granted by someone listed as an authorised signatory in the Trade Register. According to the NCSC, applying takes a few days, so do not start on the day itself.
  • Government organisations log in through SSOnRijk, which has to be enabled once in advance.
  • The data on your organisation, your contacts and your network, gathered before you start. For the network data you will usually need your CISO or network administrator.
  • The right person to fill it in. The NCSC advises someone with decision-making authority, preferably with knowledge of cybersecurity.

The steps in mijn.ncsc.nl

After you log in, the portal takes you through five parts.

  • Organisation data. This is taken over automatically from the KvK Trade Register or, for government bodies, from the Register of Government Organisations. If something is wrong, correct it at the source, not in the portal.
  • Additional data. Your sector, the type of service, the member states where you operate and your main establishment, whether you register as an essential or an important entity, any designation by a minister, and your participation in information-sharing arrangements. The sector is pre-filled from your SBI codes. Choose your own sector, not that of your clients. The questions about your size are optional.
  • Contact details. Name, telephone number, email address and job title of someone who can be reached during an incident.
  • Network data. Your IP addresses or IP ranges, your domain names and your network's AS number (ASN).
  • Summary and submit. You declare that the data are correct and that you will report changes within fourteen days. Once you submit, you are registered.

What the law asks and what the NCSC asks

The portal asks for slightly more than the law itself. The distinction helps when you have to explain internally why certain data are supplied.

  • Article 44 Cbw: name, address and current contact details, including email addresses, IP ranges and telephone numbers, the sectors and subsectors, the member states where you provide services, and your participation in or withdrawal from an information-sharing arrangement.
  • Article 27 Cyberbeveiligingsbesluit: whether you register as an essential or an important entity, your KvK number, the type of entity and your domain names.
  • Only the NCSC: your network's AS number. It is not in the Act or the decree, but the portal asks for it.

Extra data for digital service providers

For a number of digital categories, article 47 Cbw applies as well. These are DNS service providers, TLD name registries, providers of cloud computing, data centre and content delivery network services, managed service providers, managed security service providers, online marketplaces, online search engines and social networking platforms, in so far as they are an essential or important entity. Providers of domain name registration services are covered too.

They also supply the central point of contact with, among other things, the type of entity, the address of their main establishment and of their other legal establishments in the European Union, and their IP ranges. The deadline was one month after the Act entered into force on 15 August 2026; if this has not been done yet, that deadline has passed. Changes to these data are reported without delay and in any case within three months.

After registration

Once you submit, you are registered and, according to the NCSC, you can connect to the services of your sector CSIRT. You will also report incidents in the same portal later. Who has access there must therefore be settled in advance: during an incident there is no time to apply for an authorisation.

That does not finish the registration. You report any change, such as a new contact person or a new IP range, without delay and in any case within two weeks (article 44, second paragraph). The register is evaluated at least every two years, and a registration can be amended, refused or ended if its ground changes or lapses (article 43). So settle who keeps the registration up to date.

  • One owner of the registration, with a deputy, both holding a valid authorisation.
  • A link to your change management: whoever changes an IP range, domain or contact person makes sure the registration is updated.
  • A fixed moment, for example every quarter, at which you check the registered data.

What is at stake

Failing to register or to report changes is a breach of the Act. It does not fall in the highest fine category, which applies to the duty of care and the notification duty, but counts as another breach. For that, the supervisor can impose an administrative fine of at most EUR 1 million, together with or after a warning, the same for essential and important entities (article 80 and article 87).

The practical consequence often weighs more. With outdated contact details, the CSIRT may reach the wrong person during an incident, exactly when the reporting deadlines are running.

Read alsoDoes the Cyberbeveiligingswet apply to your organisation?

Registration is the first of three duties

After registration come the duty of care and the notification duty. See how we set them up and keep the evidence current.

See how we set up the Cbw duties