Netherlands
← All Member States
Netherlands
🔴 NIS2 still in the national legislative procedure.
NIS2 transposition
- National law: Cyberbeveiligingswet (Cbw), Wetsvoorstel 36764 (replaces the Wbni)
- Status / entry into force: Tweede Kamer adopted 2026-04-15; Eerste Kamer vote pending; targeted entry into force 2026-07-01 ⚠️ VERIFY
Competent authority & CSIRT
- Competent authority: Nationaal Cyber Security Centrum (NCSC), under the Ministry of Justice and Security, + sectoral regulators
- CSIRT / incident response: NCSC-NL
- Registration: NCSC.nl portal (fully bilingual Dutch/English)
Incident reporting
Follows the NIS2 cascade: early warning within 24h, notification within 72h, final report within one month, submitted to the national CSIRT / competent authority. Assume national-language submission unless the authority states otherwise.
Penalties & board liability
- Essential entities: up to €10M or 2% of worldwide turnover (directive minimum, adopted here).
- Important entities: up to €7M or 1.4% of worldwide turnover.
- Management-body accountability applies per NIS2 Art. 20; national enforcement mechanisms vary.
CER Directive
Critical-entities resilience is transposed in parallel (often via the same or a connected authority). Member States had to identify critical entities by 2026-07-17. ⚠️ VERIFY national CER instrument.
Notes
Not a ‘Wbni2’ — a new statute. Companion bill Wet weerbaarheid kritieke entiteiten (Wwke) transposes CER in parallel. Escalating enforcement from corrective orders to fines and director disqualification. Referred to the CJEU for late transposition.
Sources
- https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet
- NIS2 Directive (EU) 2022/2555: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
- Commission transposition tracker: https://digital-strategy.ec.europa.eu/en/policies/nis-transposition