The Netherlands and the NIS2 Directive: A Delayed Transposition, but a Clear Path Forward

Legislative Framework and the Delay

The NIS2 Directive entered into force at the European level in early 2023 and imposed a firm deadline on Member States at 17 October 2024, to incorporate its provisions into national law. The Netherlands failed to meet that obligation and currently remains in breach of European law. The draft legislation, known as the Cyberbeveiligingswet (abbreviated Cbw), or Cybersecurity Act, is still being considered by the Dutch Parliament and has not yet entered into force. A plenary debate in the House of Representatives is scheduled for 23 March 2026, and even if proceedings go smoothly, the adoption of the Act will require additional procedural time.

The latest guidance from the Dutch competent authorities points to the second quarter of 2026 as a realistic date for the Cbw to take effect. This indicative date is useful for planning purposes, but should not be treated as definitive. Legislative processes in the Netherlands have historically been prone to fluidity and unforeseen delays. A further complication for forecasting is that the Explanatory Memorandum to the Cbw explicitly provides for different provisions of the Act to enter into force on different dates; phased application is therefore a real and anticipated scenario rather than a theoretical one.

Until the new Act is formally adopted, the existing Network and Information Systems Security Act (Wet beveiliging netwerk- en informatiesystemen, Wbni), the Dutch transposition of the predecessor NIS1 Directive, continues to apply. Оrganisations subject to it retain their existing obligations and rights under the current regime. Notwithstanding the delay, the content and logic of the forthcoming new regime are sufficiently clear for organisations to begin structured preparation now.

A Two-Tier Regulatory Structure: Act and Decree

Alongside the Cbw, a Cyberbeveiligingsbesluit (Cbb) - a subordinate government decree that elaborates and specifies the obligations set out in the Act has been developed and submitted to Parliament in parallel. This two-tier structure (Act plus decree) is of practical significance: while the Cbw establishes the general obligations and institutional framework, the specific technical and organisational requirements will derive primarily from the Cbb. Organisations monitoring only the draft Act risk overlooking material details of the forthcoming obligations. It is therefore advisable to review both instruments together when conducting any compliance readiness analysis.

An Expanded Scope, New Governance Requirements and Personal Liability

One of the defining features of the change that the Cbw introduces is the dramatic expansion of the scope of regulated entities compared to the regime under the Wbni. Where legislative attention has to date been concentrated primarily on operators of essential services in traditional critical sectors, the new Act brings in a broad range of digital and infrastructure actors - cloud service providers, data centre operators, managed service providers (MSPs), managed security service providers (MSSPs), online platforms and others.

The Netherlands has also chosen to exercise the options available under NIS2 for national expansion of scope. The Cbw expressly includes higher education institutions like universities and universities of applied sciences. This is not a mandatory requirement under the European Directive. Local and regional government bodies are likewise included, again going beyond the minimum prescribed by the Directive. These decisions make the Dutch implementation broader in coverage than the average across the EU, and require many public sector organisations to comply with requirements they have not previously encountered.

As a result of these expansions, thousands of medium-sized and large Dutch enterprises and institutions that were previously outside the regulatory scope of the Wbni will need to comply with the Cbw once it takes effect. The classification thresholds follow those of the Directive:

  • for "important" entities - more than 50 employees or turnover/balance sheet above EUR 10 million
  • for "essential" entities - more than 250 employees or turnover above EUR 50 million.
  • Micro and small enterprises are in principle excluded, but may be brought within scope by a decision of the authorities if their activities are of critical importance.

In addition to the widening of scope, the new Act imposes significantly more demanding governance requirements. Management bodies like boards of directors, supervisory boards and equivalent structures - will bear direct responsibility for approving and overseeing cybersecurity risk management measures. A notable development is that the Cbw also introduces genuine personal liability for members of management bodies, including the possibility of disqualification from holding leadership positions in cases of systematic non-compliance. Failure to discharge oversight obligations is therefore no longer merely a matter of corporate sanction - it constitutes a personal legal risk for each individual director. Organisations will need to demonstrate that risk assessments, risk mitigation strategies and risk acceptance decisions are properly documented and subject to appropriate scrutiny at board level.

Enforcement and Sanctions

The Cbw introduces a progressive enforcement mechanism structured across three tiers. At the first level, supervisory authorities may issue binding corrective orders. If these are not complied with, financial penalties follow: for "essential" entities these may reach EUR 10 million or 2% of total global annual turnover - whichever is higher. For "important" entities the maximum threshold is EUR 7 million or 1.4% of turnover. At the third and most serious level, the disqualification of personally responsible individuals from management functions becomes available. This escalating logic mirrors NIS2 and is designed not only to penalise non-compliance but to incentivise prevention through personal accountability.

The Dutch Transposition in Practice

The Cbw follows very closely the structure and minimum harmonisation model of the NIS2 Directive itself. The Netherlands has not indicated any intention to deviate materially from the mandatory European minimum in relation to the core obligations. The distinction between essential and important entities, the risk management measures under Article 21 of NIS2, the multi-stage incident reporting regime - including the early 24-hour notification, the detailed 72-hour report and the final report within 30 days - as well as the differentiated supervisory model, will all be transposed in line with the European requirements.

The distinctive feature of the Dutch approach lies in the institutional architecture of supervision. Rather than establishing a single central cybersecurity authority, the Cbw builds on the Netherlands' existing regulatory ecosystem, distributing supervisory competence among various specialised bodies depending on the sector or activity in question. Digital infrastructure and managed services fall under the supervision of the Rijksinspectie Digitale Infrastructuur (RDI), while the Human Environment and Transport Inspectorate (ILT) will play the leading supervisory role in the transport and water sectors, with sectoral ministries involved in policy coordination. This logic is fully consistent with the Dutch administrative law tradition of distributing regulatory responsibilities among multiple sector-specific bodies.

Particular attention should be paid to the fact that the Dutch authorities have already taken concrete preparatory steps in connection with the registration obligation that the Cbw introduces. In line with Article 27 of NIS2, in-scope entities will be required to register with a dedicated platform. Although the Cbw is not yet in force, the digital registration infrastructure has already been developed and made available in anticipation. The registration portal is operated by the National Cyber Security Centre (NCSC) and requires authentication via the eHerkenning eID system. Organisations that expect to fall within scope are already able - and are encouraged - to begin preparing for registration.

Supply Chain and Indirect Obligations

The forthcoming regulatory regime affects not only organisations that fall directly within the scope of the Cbw. Suppliers of goods and services to regulated entities will be affected indirectly through contractual cybersecurity requirements flowing from their clients' supply chain risk management obligations. There are already signals from the market that critical infrastructure operators are imposing enhanced security requirements on their suppliers, irrespective of when the Act formally enters into force. Organisations that do not meet the thresholds for direct inclusion in the scope, but that occupy key positions in the digital supply chains of regulated entities, would do well not to wait passively, but to assess their position within those chains and prepare proactively.

Practical Tools for Readiness Assessment

The RDI has developed two free self-assessment tools, available online ahead of the Cbw entering into force:

  • NIS2 Zelfevaluatie - an interactive questionnaire through which organisations can determine whether they fall within the scope of the Directive and whether they are likely to be classified as "essential" or "important" entities. The tool was developed in cooperation with the competent ministries and supervisory authorities and has already been used by tens of thousands of organisations across the Netherlands.
  • NIS2 Quickscan - a 40-question diagnostic aimed primarily at IT and cybersecurity specialists. The results provide a concrete picture of the organisation's current level of digital resilience and include recommendations for technical and organisational measures across a number of thematic areas.

In addition, the Auditdienst Rijk (ARD) and NOREA have jointly developed the Cbw (NIS2) Control Framework - a practical framework for assessing the degree of alignment with the forthcoming statutory requirements, which has also been endorsed by the NCSC. Together, these resources enable organisations to identify gaps and prioritise actions without waiting for the Cbw to officially take effect.

What Organisations Can Do Now?

The expected entry into force of the Cybersecurity Act in Q2 2026 provides a planning horizon. Organisations that are likely to fall within scope should use the available time purposefully.

  1. On scope: The priority is to establish whether the organisation meets the criteria for classification as an "essential" or "important" entity under the sectoral and size thresholds. In cross-border corporate structures, it is equally important to determine which Member State has jurisdiction over a particular entity on the basis of its main establishment. Jurisdictional considerations may be of material significance for groups with a presence in multiple Member States.
  2. On governance: Governance arrangements should be reviewed and formalised so that management oversight of cybersecurity risk management is clearly documented and formally embedded in corporate procedures. Given the personal liability framework that the Cbw introduces, members of management bodies must be able to demonstrate active engagement with the subject, rather than merely formal approval of policies.
  3. On operational readiness: Supply chain risk management processes, incident detection mechanisms, and escalation and reporting procedures should be assessed against the requirements of the Directive.
  4. On registration: Although the registration obligation is not yet in force, entities should monitor official communications closely and be ready to register promptly once the Cbw takes effect. Organisations for which it is already clear that they will fall within scope may register in advance through the NCSC portal.

The delay in Dutch transposition affords additional time for preparation, but does not alter in any way the substance of the obligations that will apply. Organisations that have taken a proactive stance aligning governance, documentation and risk management structures now will be significantly better placed when the Cbw formally enters into force, and supervisory authorities begin applying the regime in earnest.