NIS2 · Cyberbeveiligingswet

The Cyberbeveiligingswet: three duties, set up and maintained

The Cyberbeveiligingswet (Cbw), the Dutch implementation of NIS2, entered into force on 15 August 2026. There is no statutory transition period. We establish what applies to you, implement the duty of care and keep the evidence current.

Updated 25 September 2026

10
elements in the statutory duty of care
24 hrs
early warning after a significant incident
3
duties: registration, duty of care, reporting

Whether the Cbw applies to you is your own call

There is no list of covered organisations and no letter from the regulator. The RDI states plainly that organisations are themselves responsible for determining whether they fall under the Cbw. Three tests settle it, and an organisation near the line cannot settle them from a web page.

01

Size

Medium-sized means 50 FTE or more, or fewer than 50 with both annual turnover and balance sheet total above EUR 10 million. Partner and linked enterprises are counted together. The figures are indicative; the RDI self-assessment is the official test.

02

Sector

Eighteen sectors are listed, eleven in Annex 1 and seven in Annex 2. An Annex 1 entity above the medium ceiling is an essential entity. An Annex 2 entity is an important entity however large it becomes.

03

In scope regardless of size

Qualified trust service providers, TLD name registries, DNS service providers, government bodies and entities designated under the Wwke are essential entities whatever their size. A ministerial designation can bring an entity into scope on qualitative grounds.

Annex 1 sectors (essential or important)

  • Energy
  • Transport
  • Banking
  • Financial market infrastructure
  • Healthcare
  • Drinking water
  • Waste water
  • Digital infrastructure
  • ICT service management (B2B)
  • Government
  • Space

Annex 2 sectors (important only)

  • Postal and courier services
  • Waste management
  • Chemicals
  • Food
  • Manufacturing
  • Digital providers
  • Research

Both classes carry the same substantive obligations. The difference is supervision. Essential entities are checked proactively, whether or not anything has gone wrong; important entities are checked mainly after the fact.

The ten duty-of-care elements

Article 21 of the Cyberbeveiligingswet sets out ten elements. Below is what each one requires and what we deliver for it. The M1 to M10 numbering is ours, so the dossiers can be referenced; the Act numbers them as elements (a) to (j).

M1

Risk Analysis & Information Security Policy

Requires an up-to-date information security policy based on periodic risk analysis. Risks are identified, assessed and controlled.

What we deliver

  • Risk analysis framework (periodic)
  • Formalised security policy
  • Risk management register
M2

Incident Management & Notification Obligation

Documented procedures for detection, analysis, notification and recovery. Three stages under articles 26 to 29 Cbw: an early warning within 24 hours, a full notification within 72 hours and a final report within one month of the notification, all through mijn.ncsc.nl.

What we deliver

  • Incident Response Plan (IRP)
  • 24/7 monitoring and alerting
  • Notification protocol via mijn.ncsc.nl
M3

Business Continuity & Crisis Management

Backup management, disaster recovery and procedures for crises and major disruptions. Organisations must demonstrate that they can restore critical processes.

What we deliver

  • Business Continuity Plan (BCP)
  • Disaster Recovery Plan (DRP)
  • Crisis and recovery exercises
M4

Supply Chain Security

Managing security risks through the supply chain. Suppliers and service providers with access to your systems fall under your NIS2 responsibility.

What we deliver

  • Supplier assessment & register
  • Security annexes in contracts
  • Supply chain risk matrix
M5

System Acquisition, Development & Maintenance

Security in the procurement, development and maintenance of network and information systems. Including patch management and vulnerability management.

What we deliver

  • Patch management policy and process
  • Vulnerability management
  • Secure procurement guidelines
M6

Cryptography & Encryption

Mandatory policy for the use of cryptography and encryption to protect information in transit and at rest. Key management must be documented.

What we deliver

  • Cryptography policy
  • Encryption implementation & verification
  • Key management protocol
M7

Personnel Security & Access Management

Screening of employees, access control on a need-to-know basis, management of privileged accounts (PAM) and a clear offboarding process.

What we deliver

  • Access management policy (RBAC/PAM)
  • Employee screening protocol
  • Offboarding and review procedures
M8

Multi-factor Authentication (MFA)

Where appropriate, multi-factor or continuous authentication, secured voice, video and text communications and secured emergency communication systems within the entity. This is statutory element (j) in full, including remote access and management systems.

What we deliver

  • MFA rollout and management
  • Authentication policy
  • Managed identity solution
M9

Awareness & Training

Basic cyber hygiene practices and cybersecurity training, the two halves of statutory element (g), elaborated in article 12 of the Cyberbeveiligingsbesluit. Regular awareness programmes on cyber threats, social engineering and safe behaviour.

What we deliver

  • Annual training programme
  • Phishing simulations
  • Awareness policy and registration
M10

Effectiveness Assessment

Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures. Statutory element (f), elaborated in article 18 of the Cyberbeveiligingsbesluit. Without it, the other nine are asserted rather than demonstrated.

What we deliver

  • Measurement plan with indicators per duty-of-care element
  • Periodic effectiveness review and internal audit
  • Management report with corrective actions and follow-up

What the Cbw requires

The duty of care sits in article 21 and is worked out in the Cyberbeveiligingsbesluit, articles 5 to 19. The obligations have been enforceable since 15 August 2026.

Duty of care, article 21
Ten elements, lettered a to j: risk analysis policy, incident handling, business continuity, supply chain, secure acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, personnel and access, and authentication.
Notification duty, articles 25 to 29
An early warning within 24 hours, a full notification within 72 hours and a final report within one month of the notification. One portal, mijn.ncsc.nl, reaches the sectoral CSIRT and the supervisor at the same time.
Registration, articles 43 and 44
Registration in the national entity register at the NCSC, via mijn.ncsc.nl with eHerkenning. It asks for sector, contact details, public IP ranges, domain names and AS numbers. Every change is reported within two weeks.
Management body, article 24
The board approves the measures. Every board member must be able to identify and assess cybersecurity risks and must hold a training certificate, by 15 August 2028. A supervisor can fine an individual board member up to EUR 25,000.
Supply chain, article 21(3)(d)
Direct suppliers and service providers sit inside your own duty of care. You weigh each supplier's specific vulnerabilities, the overall quality of its products and its secure development practices. Suppliers below the threshold are reached by contract.
Sanctions, articles 80, 87 and 93
For an essential entity, at most EUR 10,000,000 or 2% of the total worldwide annual turnover of the undertaking it belongs to, whichever is higher. For an important entity, EUR 7,000,000 or 1.4%. The toolkit also holds security audits and binding instructions.

Who supervises you

Under article 15 the competent authority is the responsible Minister per sector. Supervision is exercised in practice by the sectoral inspectorates: the RDI for energy, digital infrastructure, ICT service management, government, space, postal and courier services, manufacturing and research; the ILT for transport, drinking water, waste water, waste management, chemicals and the water authorities; DNB for banking; the AFM for financial market infrastructure; the IGJ for healthcare and medical device manufacture; the NVWA for food. Incident notifications go to a CSIRT, which is the NCSC generally, Z-CERT for healthcare, CERT-WM for the water authorities and waste water, and the IBD for municipalities. Knowing which regime you actually sit in is part of the work.

Every measure demonstrably documented

For each duty-of-care element we deliver a file populated from your own environment: the policy, the procedure, the evidence that the measure works and the date it was last tested. That last item is element (f) of Article 21. Without an effectiveness assessment, the other nine elements are asserted rather than demonstrated.

What is known about you outside your network, every day

An audit is a snapshot. Both frameworks ask for more than that: NIS2 requires policies to assess the effectiveness of measures, and ISO 27001 makes threat intelligence a control in its own right. That is why we continuously search the dark web, criminal chat channels, ransomware leak sites, paste sites and public code repositories for what has surfaced about your organisation.

What is watched

Leaked credentials
Passwords and session cookies of your staff harvested by infostealer malware and traded in criminal channels, validated against your identity provider.
Leak sites and criminal forums
Mentions of your organisation, your domains and your suppliers on ransomware leak sites, in dark web forums and in criminal chat channels.
Secrets in public code
API keys, tokens and passwords that ended up by accident in public repositories, package registries or container images.
Lookalike domains
Newly registered domains that resemble yours, and previously flagged domains that suddenly become active.
Exposure in the supply chain
Known suppliers appearing in ransomware data leaks, as continuous evidence for the supplier assessment.

What we do with it

Our monitoring collects and alerts in near real time. We assess every alert, rate its severity and turn it into the action the framework requires: a password reset, revoking sessions, a notification within the deadline or a correction in the file. Every finding and every follow-up is recorded with a date, so the effectiveness review is not a once-a-year exercise but is substantiated continuously.

Where it lands in the framework

  • NIS2Art. 21(2)(a), (b), (d) and (f)

    Risk analysis, incident handling, supply chain security and the assessment of the effectiveness of measures.

  • ISO 27001Annex A 5.7, 5.19 to 5.22 and 8.16

    Threat intelligence, supplier relationships and monitoring activities.

What it is not

This monitoring is not a security operations centre. It looks at what has leaked about you outside your network, not at the traffic inside it. Detection in your own environment and incident response are a separate agreement.

NIS2 and ISO 27001 compared

Two frameworks that are regularly confused. One is law, the other a standard you choose. This table sets out what each one is, who it binds, and what it asks you to be able to demonstrate.

  • What it is

    NIS2
    EU directive, implemented in Dutch law as the Cyberbeveiligingswet (Cbw).
    ISO 27001
    A standard for an information security management system, an ISMS.
  • Who it applies to

    NIS2
    Essential and important entities in 18 sectors. More than 8,000 Dutch organisations.
    ISO 27001
    Any organisation, of any type or size, that chooses to adopt it.
  • Mandatory or voluntary

    NIS2
    Mandatory. Registration, duty of care and incident reporting, all from day one.
    ISO 27001
    Voluntary. One exception: essential entities in the government sector must apply it.
  • Applies since

    NIS2
    15 August 2026, when the Cyberbeveiligingswet entered into force.
    ISO 27001
    Current edition published 25 October 2022, with a climate amendment added in 2024.
  • Supervisor or issuing body

    NIS2
    Sector inspectorates: RDI, ILT, DNB, AFM, IGJ, NVWA. The NCSC runs the reporting portal.
    ISO 27001
    An accredited certification body, in the Netherlands accredited by the RvA.
  • What you must be able to show

    NIS2
    Ten duty of care elements, lettered a to j, and a management system on a PDCA cycle.
    ISO 27001
    A documented ISMS: scope, risk method, Statement of Applicability, audit and review records.
  • Consequence of non-compliance

    NIS2
    Essential entities: up to EUR 10 million or 2% of group turnover, whichever is higher.
    ISO 27001
    No fine. The certificate is suspended or withdrawn, which customers and tenders notice.
  • Certification available

    NIS2
    No. There is no NIS2 certificate and the Cbw does not require one.
    ISO 27001
    Yes, by an accredited certification body.

Position as at September 2026. The Cyberbeveiligingswet entered into force on 15 August 2026 and the sector thresholds that define a reportable incident are still being completed in ministerial regulations. Determining which framework applies to your organisation remains your own legal responsibility, and this table is a summary rather than advice.

Build the evidence once

The Cyberbeveiligingsbesluit requires a documented management system on a Plan-Do-Check-Act basis. It prescribes no standard and requires no certificate, and names the ISO 27000 series as an example. An organisation that runs two separate programmes pays twice for the same evidence.

Compare frameworks

What clients ask us

Three tests decide it: your sector, your size, and whether you are in scope regardless of size. Eighteen sectors are designated. Medium-sized means 50 FTE or more, or annual turnover and balance sheet both above EUR 10 million, counting partner and linked enterprises. No letter will arrive: the RDI states that you determine this yourself. The RDI self-assessment is the official test; our free check explains the outcome for you.

Start with the applicability check

Fill in the form. Within 24 hours you receive a written analysis: does your organisation fall under this framework, and which steps are immediately required.