The Dutch House of Representatives approved the Cybersecurity Act (Cyberbeveiligingswet), advancing the Netherlands’ implementation of the EU NIS2 Directive. The act will replace the existing Network and Information Systems Security Act (Wbni) and impose statutory cybersecurity due-care, incident-reporting, and registration obligations on thousands of essential and important organizations. The National Cyber Security Centre’s remit is expected to expand to more than 8,000 organizations.
The bill now proceeds to the Senate, while the government continues preparing the Cybersecurity Decree and sector-specific ministerial rules, including incident-reporting thresholds. The government has sought to align commencement of the act, its implementing measures, and the related Critical Entities Resilience Act—implementing the EU CER Directive—with a target effective date in the second quarter of 2026, subject to completion of the legislative process. Organizations likely to fall within scope have been urged to prepare controls, governance, supply-chain safeguards, and reporting processes ahead of enforcement.

See the reporting duties and controls this puts on the clock.
16 events from the most recent confirmed update back to the earliest known activity.
Six ministries opened consultation on draft sector-specific ministerial regulations under the Cybersecurity Act, while regulations under the Critical Entities Resilience Act were also made available by relevant ministries. The drafts include sectoral incident-reporting thresholds and duty-of-care requirements.
Minister of Justice and Security D.M. van Weel voluntarily submitted the draft Cybersecurity Decree and draft Critical Entities Resilience Decree to the House so they could be considered alongside the underlying bills.
The Dutch government submitted the Cyberbeveiligingswet and Wet weerbaarheid kritieke entiteiten bills to the House of Representatives. The bills respectively implement the EU NIS2 and CER directives.
The consultation period for the draft Cybersecurity Decree and Critical Entities Resilience Decree ended, after which the government began assessing responses and considering amendments.
The Dutch government consulted on the draft Cybersecurity Decree, Critical Entities Resilience Decree, and draft duty-of-care ministerial regulations. The decrees further specify obligations under the proposed NIS2 and CER implementing laws.
The Council of State issued advice on the proposed Cybersecurity Act and Critical Entities Resilience Act before their submission to the House of Representatives.
The public consultation on the Cyberbeveiligingswet closed after receiving 111 responses. The government planned to assess feedback, develop implementing measures, obtain Council of State advice, and submit the proposal to Parliament.
The Dutch government opened public consultation on the proposed Cyberbeveiligingswet, its national implementation of NIS2, including proposed duties of care, incident reporting, and compliance oversight.
The Rijksinspectie Digitale Infrastructuur released the NIS2 Quickscan to help organizations assess their preparedness for the forthcoming NIS2-based requirements.
The Dutch House of Representatives approved the Cybersecurity Act proposal, which implements NIS2 and replaces the Wbni. The legislative proposals were then sent to the Senate for consideration.
Members of the Dutch House of Representatives held a legislative consultation on the Cybersecurity Act and Critical Entities Resilience Act, discussing scope, duty of care, incident reporting, implementation, oversight, and overlap.
The Digital Trust Center was incorporated into the National Cyber Security Centre.
From the NIS2 transposition deadline, the NCSC provided certain CSIRT activities and voluntary incident-reporting services during the transition period, including risk-based support for organizations expected to enter the Cyberbeveiligingswet's scope.
The Netherlands did not transpose NIS2 into national law by the EU deadline, citing the size and complexity of the Cyberbeveiligingswet legislative process. NIS2-covered entities generally were not yet subject to its obligations, although some provisions had direct effect.
The Digital Trust Center and the Ministry of Economic Affairs and Climate Policy held a webinar on NIS2 implementation, covering duty-of-care, incident-reporting, registration, supervision, and preparatory security measures.
EU ministers agreed to the European Commission proposal to revise the Network and Information Security Directive, creating the proposed NIS2 framework with expanded sector coverage, incident reporting, and security requirements.
See what this changes for your reporting obligations and which controls it puts on the clock.
21 references tracked. Mallory keeps watching after this page renders.
ncsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcetweedekamer.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.