Netherlands

← All Member States
In legislative procedure
NIS2 status
In legislative procedure
National law
Cyberbeveiligingswet (Cbw), Wetsvoorstel 36764 (replaces the Wbni)
Competent authority
Nationaal Cyber Security Centrum (NCSC), under the Ministry of Justice and Security, + sectoral regulators
CSIRT
NCSC-NL
Last verified
2026-07-16

Netherlands

🔴 NIS2 still in the national legislative procedure.

NIS2 transposition

  • National law: Cyberbeveiligingswet (Cbw), Wetsvoorstel 36764 (replaces the Wbni)
  • Status / entry into force: Tweede Kamer adopted 2026-04-15; Eerste Kamer vote pending; targeted entry into force 2026-07-01 ⚠️ VERIFY

Competent authority & CSIRT

  • Competent authority: Nationaal Cyber Security Centrum (NCSC), under the Ministry of Justice and Security, + sectoral regulators
  • CSIRT / incident response: NCSC-NL
  • Registration: NCSC.nl portal (fully bilingual Dutch/English)

Incident reporting

Follows the NIS2 cascade: early warning within 24h, notification within 72h, final report within one month, submitted to the national CSIRT / competent authority. Assume national-language submission unless the authority states otherwise.

Penalties & board liability

  • Essential entities: up to €10M or 2% of worldwide turnover (directive minimum, adopted here).
  • Important entities: up to €7M or 1.4% of worldwide turnover.
  • Management-body accountability applies per NIS2 Art. 20; national enforcement mechanisms vary.

CER Directive

Critical-entities resilience is transposed in parallel (often via the same or a connected authority). Member States had to identify critical entities by 2026-07-17. ⚠️ VERIFY national CER instrument.

Notes

Not a ‘Wbni2’ — a new statute. Companion bill Wet weerbaarheid kritieke entiteiten (Wwke) transposes CER in parallel. Escalating enforcement from corrective orders to fines and director disqualification. Referred to the CJEU for late transposition.

Sources