What is the Dutch Cybersecurity Act?
The Cybersecurity Act (Cyberbeveiligingswet) is the Dutch transposition of the European NIS2 directive. It replaces the old Network and Information Systems Security Act (Wbni) and requires essential and important entities to demonstrably manage their cyber risks, report incidents and make the board actively accountable.
The act entered into force on 15 August 2026. From that moment, the duty of care (Art. 21), the governance obligation for directors (Art. 24), the reporting obligation (Art. 25–30) and supervision apply. Non-compliance can lead to fines of up to €10 million or 2% of global annual turnover.
NIS2 across Europe — this page covers the Dutch law
NIS2 is a European directive; each member state transposes it into its own national law. This page describes the Dutch implementation — the Cyberbeveiligingswet. In other EU countries the same core obligations apply through a national law and timeline of their own — in force in Belgium since October 2024, and in Germany through its own NIS2-Umsetzungsgesetz.
Timeline of the act
NIS2 adopted
The EU adopts the NIS2 directive as the successor to NIS (2016).
Act published
The Cybersecurity Act is published in the Dutch Bulletin of Acts (2026, 187).
In force
Duty of care, reporting obligation, governance and enforcement take effect.
Which organizations must comply with NIS2?
NIS2 applies to essential and important entities in the following sectors
Energy
Transport
Banking
Healthcare
Drinking Water
Digital Infrastructure
Public Administration
Space
Criteria: >50 employees OR >€10M revenue. Some organizations fall under NIS2 regardless of size.
Essential or important entity?
The act distinguishes two categories. Your category determines the supervisory regime and the maximum fine.
Essential entities
Large organizations in the most critical sectors (including energy, transport, drinking water, healthcare, digital infrastructure and government) and certain providers regardless of size, such as DNS service providers and top-level domain registries. They are subject to proactive supervision.
Fine up to €10 million or 2% of global annual turnoverImportant entities
Medium and large organizations in the other designated sectors (including postal, waste, chemicals, food, manufacturing and digital providers). They are subject to reactive supervision — after an incident or signal.
Fine up to €7 million or 1.4% of global annual turnoverIn doubt whether you fall under the act? That in itself is a reason to take scoping seriously now. In uComply you determine scope in a structured, demonstrable way.
The obligations: duty of care (Art. 21) and governance (Art. 24)
The act requires appropriate and proportionate measures based on an all-hazards approach — and a demonstrably involved board.
Risk management
Carry out systematic risk analysis and establish information security policy (Art. 21(3)(a)).
Incident handling & reporting
Handle incidents in a structured way and report significant incidents within 24 hours, 72 hours and one month (Art. 25–30).
Supply chain security
Manage the risks of your supply chain and direct suppliers (Art. 21(3)(d)).
Cryptography & encryption
Maintain policy on cryptography and, where appropriate, encryption (Art. 21(3)(h)).
Access & assets
Arrange personnel security, access control and asset management; apply MFA where appropriate (Art. 21(3)(i–j)).
Business continuity
Ensure backup management, recovery plans and crisis management (Art. 21(3)(c)).
Cyber hygiene & training
Secure basic cyber hygiene and cybersecurity training (Art. 21(3)(g)).
Assessing effectiveness
Periodically assess the effectiveness of your control measures (Art. 21(3)(f)).
Governance & board
The board approves the measures, holds demonstrable knowledge and follows appropriate training (Art. 24).
Reporting obligation: strict deadlines
For a significant incident you report without delay to your CSIRT and the competent authority.
Early warning
First signal of the significant incident to the CSIRT and competent authority.
Full notification
Notification with an initial assessment of severity, impact and indicators.
Final report
Detailed report with root cause and the measures taken.
Fines and sanctions for non-compliance
The Cybersecurity Act (NIS2) introduces significant fines for organizations that fail to comply.
Essential Entities
Up to €10 million or 2% of global annual revenue
Important Entities
Up to €7 million or 1.4% of global annual revenue
Additionally, directors can be held personally liable for non-compliance with the directive.
The entire act — integrated in uComply
Since 15 August 2026 the complete Dutch Cybersecurity Act sits in uComply as a working framework — ready to use and linked to your existing standards.
CBW/NIS2 control framework
The NCSC framework ready to use in the platform — not a blank page, but concrete controls.
Linked to your standards
One control counts toward ISO 27001, NEN 7510 and the Cybersecurity Act — the required evidence instantly in order.
Reporting as a workflow
Record incidents and monitor the 24-hour, 72-hour and one-month deadlines.
Board dashboard
With Flightdeck you demonstrably show what Article 24 asks of your board.
How uComply Helps with NIS2 Compliance
From gap analysis to certification: we guide you through the entire NIS2 compliance journey
NIS2 Gap Analysis
Identify where your organization stands against NIS2 requirements with our comprehensive gap analysis tool
AI Compliance Consultant
Our AI Consultant answers all your NIS2 questions and guides you step by step through implementation
Certification Guidance
Achieve the NIS2 Quality Mark with guidance from our certified auditors and consultants

The NIS2 Quality Mark
uComply is affiliated with the official NIS2 Quality Mark program. This quality mark demonstrates that your organization complies with the NIS2 directive and takes cybersecurity seriously.
- Official recognition of NIS2 compliance
- Increased trust from customers and partners
- Demonstrable compliance for regulators
Frequently asked questions about the Cybersecurity Act
What is the Dutch Cybersecurity Act?
The Cybersecurity Act (Cyberbeveiligingswet) is the Dutch transposition of the European NIS2 directive. It replaces the old Network and Information Systems Security Act (Wbni) and requires essential and important entities to observe a duty of care (risk management), a reporting obligation for incidents and active board accountability.
When does the Dutch Cybersecurity Act take effect?
The Cybersecurity Act entered into force on 15 August 2026. From that moment, the duty of care (Art. 21), the governance obligation for directors (Art. 24), the reporting obligation (Art. 25–30) and supervision with enforcement apply.
Which organizations does the act apply to?
The act applies to essential and important entities in sectors such as energy, transport, drinking water, healthcare, digital infrastructure, government, space, postal, waste, chemicals, food and manufacturing. Medium and large organizations are usually in scope; some types of providers regardless of size.
What are the reporting deadlines for a significant incident?
For a significant incident: an early warning within 24 hours, a full notification with initial assessment within 72 hours and a final report within one month — to your CSIRT and the competent authority.
What are the fines for non-compliance?
For essential entities, up to 10 million euros or 2% of global annual turnover; for important entities, up to 7 million euros or 1.4%. In addition, directors are explicitly responsible for managing cyber risks.
How does uComply help with the Cybersecurity Act?
uComply has the entire Dutch Cybersecurity Act integrated as a working CBW/NIS2 control framework. The platform links the act to existing standards such as ISO 27001 and NEN 7510, supports the reporting-obligation workflow and, with the Flightdeck dashboard, demonstrably shows what Article 24 asks of directors.
Read more about the Cybersecurity Act
- The Dutch Cybersecurity Act goes live tomorrow — and uComply fully integrates it
- Cybersecurity Act from 15 August 2026 — what to arrange now
- The Cybersecurity Act in the Netherlands (NIS2): what you need to know
- Practical steps to meet the NIS2 requirements
- The CBW/NIS2 control framework integrated in uComply
Start with the Cybersecurity Act today
Discover how uComply helps you demonstrably comply with the Dutch Cybersecurity Act — from scope and duty of care to reporting and the board.
