NIS2 Update: Dutch Cybersecurity Act enters into force on 15 August 2026

Developments surrounding NIS2 have entered a new phase. In a previous article, we discussed what the European NIS2 Directive and the Dutch Cybersecurity Act (Cyberbeveiligingswet, hereinafter referred to as the "Cbw") could mean for your organisation. Both laws will enter into force on 15 August 2026.

On 7 July 2026, the Dutch Senate approved both the Cbw and the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten, Wwke). The Cbw transposes the European NIS2 Directive into Dutch legislation. It replaces the current Network and Information Systems Security Act and introduces new obligations for organisations providing essential or important services. From 15 August onwards, these obligations will apply to more than 8,000 organisations in the Netherlands. As a result, cybersecurity will become an increasingly integral part of governance, risk management and executive accountability.

What does this mean for organisations?

Organisations falling within the scope of the Cbw will be subject to a range of obligations, including registration requirements, a duty of care, incident reporting obligations, management accountability and supervision by competent authorities. The level of supervision will not be the same for all organisations. Essential entities will generally be subject to stricter and more proactive oversight, whereas supervision of important entities will be primarily reactive. The legislation applies to organisations operating in sectors including energy, drinking water, digital infrastructure, healthcare, government and transport.

The first step is to determine whether your organisation falls within the scope of the Cbw. Organisations are responsible for conducting this assessment themselves. Determining scope is not only legally relevant; it also forms the starting point for a practical approach: which obligations apply, which measures are already in place and where the key areas of attention lie.

Registration, risk analysis and demonstrable compliance

For organisations within scope of the Cbw, registration in the national entity register via the National Cyber Security Centre (NCSC) will become mandatory. In addition, organisations must implement appropriate measures to manage risks affecting network and information systems. Significant incidents must also be reported within the prescribed statutory timeframes.

This marks a shift in focus from general cybersecurity measures to demonstrable control and accountability. Policies and technical safeguards alone are not sufficient. Organisations must be able to demonstrate that risks have been identified, measures have been selected based on risk assessments, responsibilities have been assigned and that follow-up actions are carried out in a structured and ongoing manner.

Cybersecurity as a board-level responsibility

For organisations subject to the Cbw, cybersecurity is not solely an IT responsibility. The board retains ultimate responsibility for cyber risk management and must possess sufficient knowledge and expertise to assess cyber risks and security measures effectively.

This requires close collaboration between senior management, IT, risk, compliance, legal, procurement and operations. Cyber resilience affects not only systems, but also business continuity, service delivery, suppliers, customer confidence and organisational reputation.

What can you do now?

Organisations should now make their preparations concrete. Start with a structured assessment of your current position:

  • Does the organisation fall within the scope of the Cbw?
  • Which obligations are applicable?
  • Which measures are already in place?
  • Where are the most significant gaps?
  • How are incident response and reporting processes organised?
  • Which suppliers are critical to the organisation?
  • What reporting is provided to the board or executive management?
  • What evidence is available to registration, risk analysis, demonstrable control and accountability?

A NIS2 readiness assessment can help organisations answer these questions in a structured manner. Depending on the outcome, follow-up actions may include strengthening governance arrangements, performing technical validations such as penetration testing, enhancing third-party risk management, developing management reporting, or providing awareness programmes and board-level training.

Conclusion

The Cbw is no longer a future development. From 15 August 2026, its obligations will apply to organisations that fall within scope. The key question is therefore no longer whether cybersecurity is important, but whether your organisation can demonstrate that it is in control.

Forvis Mazars supports organisations in assessing the impact of NIS2, conducting readiness assessments, evaluating existing controls and translating regulatory requirements into a practical and manageable action plan.

Meer informatie?