Netherlands Cyberbeveiligingswet Enters Into Force, Closing One of the Four Transposition Gaps
The Cyberbeveiligingswet, the Dutch law implementing NIS2, entered into force on 15 August 2026. Organisations in scope are legally required to register in the entiteitenregister, which in the Netherlands is held by the Nationaal Cyber Security Centrum, and the registration duty applies from the date the law took effect.
Key Analytics
Impact Analysis
The Netherlands was one of the four member states the European Commission referred to the Court of Justice on 8 July 2026 over incomplete NIS2 transposition, and its law took effect roughly five weeks later. For anyone with Dutch operations the practical position changed overnight from watching a legislative process to carrying live duties. Three of them are stated by the NCSC directly: a duty of care requiring a risk analysis and appropriate, proportionate measures taken on the basis of it; an incident reporting duty requiring notification to the CSIRT as soon as possible and in any event within 24 hours; and the registration duty in the entiteitenregister. Note what the NCSC does NOT publish: its registration pages give no closing date and no grace period for the registration window, only that the obligation runs from 15 August 2026. That absence is the answer rather than a gap in it, so treat registration as due now instead of planning against a deadline that has not been set.
Recommended Actions
- Test each Dutch entity against the Cbw's scope and decide whether it is an essentiele or a belangrijke entiteit, since the two classes carry different supervision even where the substantive duties overlap.
- Register in scope entities in the entiteitenregister at the NCSC now: the duty runs from 15 August 2026 and no closing date for the window has been published.
- Document the risk analysis the duty of care is built on, because the measures are required to be appropriate and proportionate on the basis of that analysis, which makes the analysis itself the evidence.
- Wire Dutch incidents into a reporting path that can reach the CSIRT within 24 hours, and test it, since the clock is stated as as soon as possible and in any event within 24 hours.
- Reconcile the Dutch duties against the German ones if you operate in both, because each transposing law adds its own scoping, registration mechanics and supervision on top of the directive's baseline.
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Gap assessment against current controls
- ›Applicability analysis
- ›Control mapping and implementation
- ›Evidence and audit preparation
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 70 to 305 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.