The Netherlands turns NIS2 on: what changed
· Cryptaguard · 6 min read
The Cyberbeveiligingswet took effect on 15 August 2026. Eight thousand entities moved from preparing to being supervised, registration stopped being voluntary, and a Court of Justice case that was filed a month earlier is still running.
On Saturday 15 August 2026 the Dutch Cyberbeveiligingswet — the Cbw — took effect. It is worth being precise about what that sentence means, because for the previous four months the Netherlands was in the awkward category of a member state whose transposition was finished but not yet law.
What actually changed on the day
Three things, and only the third is a surprise to anyone who had been reading the parliamentary papers.
- The duty of care and the incident reporting obligations became enforceable rather than prospective.
- Registration in the entiteitenregister stopped being voluntary. Entities that had already registered during the voluntary window did not have to do anything; entities that had not are now late, not early.
- Supervision by the RDI became real, and the RDI is not the body you registered with.
Two bodies, not one
Supervision sits with the Rijksinspectie Digitale Infrastructuur. Registration sits with NCSC-NL. Two bodies, two channels, and no automatic traffic between them from your point of view — you deal with both. This split catches out organisations that assume the register is the regulator.
The act is not where the obligations are
The Cbw is the frame. The Cyberbeveiligingsbesluit — the Cbb — is the implementing decree, and it is where the duty of care is specified, where the registration mechanics live, and where the management training requirement is given content. Reading the act without the decree gives you the architecture and none of the rooms.
There is a third layer, and it is the one still moving. Ministerial regulations, issued per ministry or per sector, further specify parts of the Cbb. Not all of them are published. Entry into force is expected to be spread across the second half of 2026. So an entity in a sector whose regulation has not appeared is subject to the act and the decree today, and to a specification that does not exist yet.
That is uncomfortable but it is not an excuse to wait. The duty of care in the Cbb is the obligation; the ministerial regulation refines how it is read in your sector. Building against the decree now and adjusting later is the only sequence that ends on time.
Why the Court of Justice case is still live
On 8 July 2026 the European Commission referred the Netherlands to the Court of Justice of the European Union for failing to notify complete transposition of NIS2, asking the Court to impose a lump sum and daily penalty payments. The Senate had voted the day before. The timing looks absurd, and the reflex is to assume the case evaporated when the law took effect.
It did not, for a reason worth understanding because it applies to Ireland, Spain and France too. What ends an infringement referral is the member state NOTIFYING the Commission of complete transposition measures — not the national law entering into force. The two usually coincide. Here they do not, because the outstanding ministerial regulations are part of what has to be notified. Until the Commission is satisfied and withdraws, the case runs.
None of this creates or removes an obligation for an entity operating in the Netherlands. The penalties in an article 260(3) case are owed by the member state, not by companies. But it does tell you something useful: the Commission does not yet consider Dutch transposition finished, and the parts it is waiting on are the sectoral parts.
What you can be assessed against, and what you cannot
For public sector bodies there is a framework: BIO2, the Baseline Informatiebeveiliging Overheid, built on NEN-EN-ISO/IEC 27001:2023 and 27002:2022. It binds the Rijk, the provinces, the water boards and the municipalities, and the ministerial regulation for the government sector makes applying its overheidsmaatregelen a legal obligation rather than a matter of self-regulation. Public administration is an Annex I sector, so this is squarely NIS2 territory.
For private entities there is nothing equivalent, and the RDI has been unusually direct about it: meeting your own normenkader does not mean you meet the duty of care. ISO/IEC 27001 and 27002 are guidance in the Dutch reading, not a route to compliance. There is no Dutch label to hold up, which means the evidence you produce has to be argued against the Cbb rather than against a certificate.
If you have done nothing yet
The order that wastes the least time: establish whether you are in scope at all, register, then work on the duty of care. Registration is administrative and quick; scope is the part people get wrong, usually by reasoning from their own sector rather than from Annexes I and II and the size cap.
One detail specific to the Netherlands: the roughly 8,000 entities the Dutch government expects in scope is a larger number than the country's NIS1 population by an order of magnitude. If your organisation concluded years ago that it was not covered, that conclusion was reached under a different law and does not transfer.
- Register with NCSC-NL now if you have not — the voluntary window closed on 15 August 2026.
- Work from the Cyberbeveiligingsbesluit, not from the Cbw alone; the obligations are in the decree.
- Check whether your sector's ministerial regulation has been published, and build against the decree meanwhile.
- Do not treat the Court of Justice referral as resolved. It ends on notification, not on entry into force.
- If you are a private entity, stop looking for a Dutch certificate to hold up. There is not one.