What is the Cyberbeveiligingswet (Cbw) compliance?

The Cyberbeveiligingswet is the Dutch law transposing the EU NIS2 directive into national rules, raising cybersecurity and resilience obligations for essential and important entities, including a distinct government sector

Banner thumbnail
On this page  
  • Introduction
  • Applicability and scope
  • Duty of care (zorgplicht)
  • Registration obligation (registratieplicht)
  • Reporting obligation (meldplicht)
  • Management liability and training
  • Supervision (toezicht)
  • Challenges of implementing the Cbw
  • Benefits of implementing the Cbw
  • Best practices
  • Conclusion
 

Introduction

If your organization delivers essential or important services in the Netherlands, Cyberbeveiligingswet compliance is about to move from a planning exercise to a legal duty. The Cyberbeveiligingswet (Cbw) is the Dutch transposition of the European Network and Information Security directive, better known as NIS2. It exists because everyday services now depend heavily on digital systems, and the threats against those systems have grown sharper, so the law sets a higher floor for how organizations manage cyber risk and keep their services running.

A NIS2 directive does not bind organizations directly; each member state has to translate it into national law first. In the Netherlands, that translation is the Cbw, and once it takes effect it replaces the current Wet beveiliging netwerk- en informatiesystemen (Wbni). For Dutch organizations in scope, this is the instrument that turns broad European cybersecurity goals into concrete, supervised duties.

Applicability and scope

Under both NIS2 and the Cbw, government is treated as its own sector. The size criterion that decides scope in other sectors does not apply here; instead, separate criteria determine whether a body counts as a government institution. Ministries, provinces, and municipalities are always in scope, while independent administrative bodies and joint arrangements have to be assessed case by case. If your organization works mainly in national security, public safety, defense, or law enforcement, you are excluded, though the directive still expects you to reach an equivalent level of resilience.

The following government organizations fall under the Cbw:

  • Ministries (including their services and agencies)
  • Provinces
  • Municipalities
  • Water authorities (via the Ministry of Infrastructure and Water Management)
  • Independent administrative bodies (where they meet the four criteria)
  • Joint arrangements (where they meet the four criteria)

Compliance levels and requirements

The Cbw rests on a layered set of instruments: the Act itself, the Cyberbeveiligingsbesluit (the general order in council that details duties such as the duty of care, registration, and director training across all sectors), and the sector-specific ministerial regulations. From those instruments flow five core obligations every organization in scope has to satisfy. Working through them in order, you will move from foundational risk management to supervised accountability.

The Cbw's five obligations cover:

  • Duty of care (zorgplicht): Take appropriate, risk-based measures to safeguard service continuity and protect information.
  • Registration obligation (registratieplicht): Register the entity and its internet domains with the national authority.
  • Reporting obligation (meldplicht): Report significant incidents within fixed deadlines.
  • Management liability and training: Place responsibility with the governing body and train its members.
  • Supervision (toezicht): Submit to independent oversight of how the duties are met.

Duty of care (zorgplicht)

The duty of care is the foundation of the whole regime. Organizations in scope have to take appropriate measures to keep their services running as far as possible and to protect the information they handle, and those measures follow from a risk assessment rather than a fixed checklist. The detail is filled in by the Cyberbeveiligingsbesluit and the sector regulations. For the government sector, the duty of care is given shape mainly through the revised Baseline Informatiebeveiliging Overheid (BIO2), which aligns closely with the law's emphasis on sound risk management.

Registration obligation (registratieplicht)

This obligation puts your organization on the map for the authorities and for threat intelligence. The Cbw requires entities in scope to register and supply data for the entity register, after which they receive information about cyber threats in return. Registration runs through a portal operated by the National Cyber Security Centre (NCSC), and by registering an organization it signals that it falls under the law. The obligation also covers registering every internet domain the organization is responsible for, and work is underway to link existing government registers so data already held can be loaded into the NCSC portal.

Reporting obligation (meldplicht)

When something goes seriously wrong, the clock starts immediately. The Cbw requires entities to report significant incidents—those that significantly disrupt or could disrupt the continuity of their services—to their Computer Security Incident Response Team (CSIRT) and their supervisor. To avoid duplicate filings, the report goes through the NCSC portal, which forwards it to both recipients. Factors that make an incident reportable include the number of people affected, how long the disruption lasts, and the potential financial damage, with specific thresholds set in the ministerial regulations.

The reporting obligation runs in three stages:

  • Early warning: An initial notification within 24 hours.
  • Follow-up report: Additional detail within 72 hours, building on the first notification.
  • Final report: A detailed account of the incident, its severity, and its consequences, no later than one month after the first notification.

Management liability and training

This obligation moves cybersecurity squarely into the boardroom. NIS2 places responsibility for an organization's resilience with its governing body, and members have to know enough to make informed decisions about network and information security. For the government sector, the political leadership is designated as that governing body. The directive's separate provision on personal liability for directors does not apply to public authorities; Dutch government directors take on no new liabilities beyond those that already exist, such as liability for gross negligence.

The Cbw also requires members of the governing body to complete training. Through it, board members learn to:

  • Identify risks: Recognize security risks to network and information systems.
  • Assess controls: Evaluate risk-management measures.
  • Weigh consequences: Judge the effects of those risks and measures.

Once the law takes effect, directors have a maximum of two years to meet the training requirement.

Supervision (toezicht)

Compliance is not self-certified; an independent authority checks it. The Cbw requires that an independent supervisor tests whether organizations meet duties such as the duty of care and the reporting obligation. For government bodies, the Rijksinspectie Digitale Infrastructuur (RDI) is the supervisor, except for water authorities, where the Inspectie Leefomgeving en Transport (ILT) takes that role. To keep the administrative burden low, the RDI builds its supervision upon existing accountability structures, such as the ENSIA method for municipalities and the information-security reports of central-government parties.

Challenges of implementing the Cbw

Bringing an organization into Cbw compliance can be demanding, especially while parts of the framework are still being finalized.

Moving from a directive to a moving target

The Cbw's detail lives in lower regulation (i.e., the Cyberbeveiligingsbesluit and the ministerial regulations), some of which are still in consultation. Organizations have to start preparing against requirements that are not yet fully fixed, which makes early scoping and assumptions harder to lock down.

Determining your own scope

You are responsible for deciding whether your organization falls under the law, and for government bodies that means working through institution criteria rather than a simple size threshold. For independent administrative bodies and joint arrangements, the assessment has to be made case by case, which can be genuinely ambiguous.

Meeting tight reporting deadlines

The 24-hour early warning leaves little room to organize a response under pressure. Many organizations find that their detection, triage, and escalation processes were never built to produce a meaningful notification that fast, and closing that gap takes both tooling and rehearsed procedure.

Embedding board-level accountability

Placing responsibility with the governing body and training its members is a culture change as much as a compliance task. You'll need to bring senior leaders who may have treated security as a technical matter into active decision-making, and build enough literacy for them to weigh risks credibly.

Aligning overlapping frameworks

Government organizations already work to the BIO, now revised as BIO2, alongside other accountability structures. Mapping these onto the Cbw's duties without creating duplicate work or contradictory requirements takes careful coordination across teams.

Benefits of implementing the Cbw

Reaching Cbw compliance pays off well beyond satisfying the supervisor.

Stronger service continuity

The duty of care forces a clear-eyed look at what could interrupt your services and what it would take to keep them running. Organizations that work through that risk assessment honestly tend to come out with resilience they should have had regardless of the law.

Faster, calmer incident response

Building toward the 24-hour and 72-hour reporting stages means having detection and escalation that actually work. You'll find that the same machinery that satisfies the reporting obligation also shortens real-world recovery when an incident hits.

Useful threat intelligence

Registration is not a one-way street. Organizations that register receive information about cyber threats through the NCSC, turning a compliance step into a practical early-warning channel that informs day-to-day defense.

Security that reaches the top

With responsibility and training placed at the board level, cybersecurity stops being something delegated and forgotten. The organization gains decision-makers who understand the risks they own, which usually means steadier funding and clearer priorities.

A common baseline across the sector

Because government is treated as one sector with shared instruments such as BIO2, compliance moves organizations toward a consistent standard. That shared baseline makes collaboration, oversight, and mutual assurance between public bodies far simpler.

Best practices

If the goal is more than minimum compliance, a few practices pay off over the long run.

Governance and risk management

  • Start from the existing baseline. For government bodies, treat BIO2 as the backbone of the duty of care rather than building from scratch.
  • Run the scope assessment early and document the reasoning, especially for independent administrative bodies and joint arrangements where the answer is not obvious.
  • Bring the governing body into the process now, and schedule the mandatory training well inside the two-year window rather than against the deadline.

Incident readiness and registration

  • Register with the NCSC portal as soon as the obligation allows, and keep entity and domain data current as registers are linked.
  • Pressure-test the 24-hour and 72-hour reporting flow with tabletop exercises before a real incident forces the issue.
  • Maintain an up-to-date inventory of all internet domains under the organization's responsibility so nothing slips through unregistered.

Documentation and oversight

  • Keep the risk assessment a living document, reviewed as systems and threats change.
  • Align reporting and evidence with existing accountability structures, such as ENSIA, so supervision adds as little duplicate effort as possible.

Conclusion

The Cyberbeveiligingswet turns the European NIS2 ambition into supervised, enforceable duties for organizations that keep essential and important services running in the Netherlands. It protects the continuity people depend on and the information that flows through public and private systems; and because supervision is independent and built into the law, treating it as optional is not realistic. Organizations that approach it as a one-off project tend to revisit the same gaps after each oversight cycle.

The more durable path is to treat Cyberbeveiligingswet compliance as a capability rather than a deadline. If you ground the work in honest risk assessment, build reporting and registration into normal operations, and give your governing body real ownership, you end up with resilience that holds up between audits, not just during them. Start from the frameworks you already run, close the gaps the five obligations expose, and keep the whole thing current as the lower regulation settles.