Dutch Cybersecurity Act enters into force on 15 August 2026: what organisations should do now : Clyde & Co | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


On 15 August 2026, the Dutch Cybersecurity Act (Cyberbeveiligingswet, hereafter: “Cbw”) will enter into force. For organisations that fall within scope, this is not a soft launch. From that date, the Dutch NIS2 regime will apply, including the registration obligation, the duty of care, incident reporting obligations and board-level governance obligations.

The Act implements the European NIS2 Directive and was adopted by the Dutch Senate on 7 July 2026. It will replace the current Security of Network and Information Systems Act (Wet beveiliging netwerk- en informatiesystemen). In parallel, the Dutch Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten) will enter into force, implementing the CER Directive and addressing the physical resilience of critical entities.

No general transition or grace period

Dutch law does not provide for a general transition or grace period comparable to the approach taken in some other jurisdictions. Organisations falling within the scope of the Cbw must register in the national entity register via the Dutch National Cyber Security Centre (hereafter: “NCSC”) as from 15 August 2026.

If an entity is in scope and has not registered by 15 August 2026, it would in principle be non-compliant with the registration obligation from that date. That does not mean that sanctions will automatically be imposed on day one. The relevant competent authority will still need to decide whether and how to enforce in the circumstances of the case. However, failure to register, or incorrect registration, may be subject to enforcement and may lead to measures such as an administrative fine or an order subject to periodic penalty payments (last onder dwangsom).

Scope: must be assessed at entity level

The Cbw applies to organisations active in designated essential and important sectors. These include, among others, energy, transport, banking, healthcare, drinking water, wastewater, digital infrastructure, ICT service management, food production, chemicals, manufacturing, digital providers and research.

However, scope is not determined by sector alone. In most cases, the relevant legal entity must also meet size thresholds. Certain entities may fall within scope regardless of size, and smaller entities may be designated as essential or important if disruption of their services could have significant consequences for public safety, public security or public health, or if they are the sole provider of an essential service.

For international groups, this is an important point. A Dutch subsidiary should not simply be assessed by reference to the group’s global activities. The analysis should focus on the actual role of the Dutch legal entity: is it merely a sales office, or does it perform or support activities relating to distribution, manufacturing, regulatory responsibility, IT services, logistics or other functions relevant to the Cbw?

Supervisory framework

In the Netherlands, a supervisory framework has been set up with multiple competent authorities, such as the Dutch Authority for the Financial Markets (AFM), the Dutch Central Bank (DNB) and the Dutch Authority for Digital Infrastructure (RDI). The authorities are responsible for supervising entities within their respective sectors. They will work closely together and coordinate their activities.

Core obligations

For in-scope entities, the Cbw introduces four main obligations.

First, in-scope entities must register via a web portal of the NCSC. The registration requires eHerkenning, the Dutch electronic identification tool for companies and organisations, or, for certain public bodies, SSOnRijk. The NCSC indicates that organisations should collect all relevant organisational, contact and network information before starting the registration process.

Second, entities must comply with a duty of care. They must take appropriate and proportionate technical, operational and organisational measures to manage cybersecurity risks, prevent incidents and limit their consequences. These measures must be based on a risk assessment and will be further specified in lower legislation, including the Cybersecurity Decree and sector-specific rules.

Third, significant incidents must be reported to both the relevant Computer Security Incident Response Team (hereafter: CSIRT) and the competent supervisory authority. The CSIRT is the technical incident response body designated for the relevant sector or type of entity. A significant incident is an incident that causes, or is capable of causing, severe operational disruption of the services provided or financial loss for the organisation concerned. An incident may also be considered significant where it has affected, or is capable of affecting, other organisations by causing considerable material or non-material damage. These general criteria will be further specified in ministerial regulations, which will establish specific threshold values for determining whether an incident qualifies as significant.

The Cbw introduces a phased reporting regime: an early warning without undue delay and, where immediate reporting is not possible, within 24 hours after becoming aware of the incident; a further notification within 72 hours after becoming aware of the incident; and a final report must be submitted no later than one month after the 72-hour incident notification. If the incident is still ongoing at that time, a progress report must be submitted instead, followed by a final report within one month after the incident has been resolved.

Fourth, cybersecurity becomes a board-level responsibility. The management body must approve cybersecurity risk-management measures and supervise their implementation. Board members must have sufficient knowledge and skills to identify cybersecurity risks and assess appropriate measures. Board members are required to follow cybersecurity training and must be able to provide proof of their participation. The Act provides for a two-year period for board members to meet these knowledge and skills requirements after the relevant provision enters into force.

Administrative fines

Supervisory authorities may impose an administrative fine of up to EUR 10 million or 2% of the total worldwide annual turnover in the preceding financial year (whichever is higher) with regard to essential entities and EUR 7 million or 1.4% of the total worldwide annual turnover (whichever is higher) with regard to important entities. These administrative fine tiers are in line with the regime established by the NIS2 Directive and apply to breaches of some substantive requirements under the Cbw, such as the obligation to take appropriate and proportionate technical, operational and organisational measures (duty of care) and incident reporting obligations.

For other infringements under the Cbw, the maximum administrative fine is EUR 1 million. In addition to the administrative fines that may be imposed on entities, under the Cbw board members may also be fined for failing to comply with the requirements relating to adequate knowledge and skills in the field of information security. The maximum fine in this regard is EUR 25,000.

The Cbw also sets out factors for supervisory authorities to take into consideration when applying enforcement measures, including the seriousness and duration of the infringement, any material or non-material damage caused and whether the entity involved acted with intent or negligence.

A periodic penalty payment (last onder dwangsom) does not have the same fixed statutory maximum as an administrative fine. The amount would be set by the competent supervisory authority in the circumstances of the case, subject to proportionality requirements and the authority must also determine a maximum amount above which no further penalty payments are forfeited.

What to do now

Organisations operating in the Netherlands should use the short period before 15 August 2026 to answer a limited number of practical questions:

  • Which Dutch legal entities may be relevant under the Cbw?
  • For those entities, is the scope and classification analysis clear by reference to their activities, sector and size?
  • Has registration via the NCSC been prepared, including access to the web portal of the NCSC and the information required for registration?
  • Have existing cybersecurity measures and incident response procedures been mapped against the Dutch requirements?
  • Can the organisation meet the 24-hour and 72-hour incident reporting timelines in practice?
  • Is board-level ownership of cybersecurity risk management sufficiently clear and documented?
  • Have key supply chain dependencies, contractual notification obligations and relevant cyber/D&O insurance arrangements been considered in light of the new regime?

The key message is straightforward: 15 August 2026 is not only the formal commencement date of the Cbw. For in-scope entities, it is the date from which entities are required to comply with the Cbw.

——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW