Your 2026 guide to complying with the Cyberbeveiligingswet (Cbw)
Understand the Dutch NIS2 implementation law and the five duties it places on entities in scope.
As Dutch organisations face intensifying threats to the digital systems everyday services now depend on, the Cyberbeveiligingswet (Cbw) transposes the European NIS2 directive into national law, replacing the Wet beveiliging netwerk- en informatiesystemen (Wbni). It organises its obligations into five core duties: a risk-based duty of care (zorgplicht), registration (registratieplicht), incident reporting (meldplicht), management oversight with mandatory director training, and independent supervision (toezicht). The Act is elaborated by the Cyberbeveiligingsbesluit and by sector-specific ministerial regulations, with the revised Baseline Informatiebeveiliging Overheid (BIO2) giving the duty of care its concrete shape for the government sector.
Expected to take effect in the second quarter of 2026 subject to parliamentary approval, the law binds essential and important entities across the NIS2 sectors — and because the Netherlands treats government as a sector in its own right, ministries, provinces, municipalities and water authorities fall in alongside private operators. Responsibility for cyber resilience sits with the governing body, not a function it has delegated to. This guide breaks down the Cbw duty by duty, outlines what your organisation must implement, and shows how ManageEngine solutions help you operationalise and strengthen compliance.
What you’ll learn
- Understand what the Cbw covers, how it replaces the Wbni, and why treating government as a distinct sector pulls ministries, provinces, municipalities and water authorities into scope.
- Trace the layered instrument stack — the Act, the Cyberbeveiligingsbesluit, sector ministerial regulations, and BIO2 for government bodies — and which one actually sets the requirement you have to meet.
- Work through the zorgplicht in practice: risk assessment, access control over systems and information, strong and continuous authentication, and an up-to-date view of identities and assets.
- Meet the meldplicht deadlines — an early warning to the CSIRT and supervisor within 24 hours, a follow-up report within 72 hours, and a final report within one month.
- See how identity governance and security monitoring evidence compliance to an independent supervisor and give the governing body the oversight the law assigns it.