News
August 11, 2026

Dutch Cybersecurity Act, implementing NIS2, takes effect on 15 August 2026: what organisations should do now

The Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw) and the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten, Wwke) take effect on 15 August 2026.

The Cbw implements Directive (EU) 2022/2555, known as the NIS2 Directive, in the Netherlands and replaces the Network and Information Systems Security Act (Wet beveiliging netwerk- en informatiesystemen, Wbni). The Dutch Act, rather than the Directive alone, determines the applicable national obligations.

According to the Dutch government, more than 8,000 organisations will become subject to new cybersecurity obligations. Organisations are responsible for assessing whether they fall within scope. The Cbw applies to entities providing essential or important services across 18 sectors, including energy, drinking water, digital infrastructure, healthcare, government and transport.

The principal obligations

1. Registration duty: entities within scope must register in the national entity register through the National Cyber Security Centre (NCSC). Registration is already available and becomes mandatory when the Act takes effect.

2. Duty of care: entities must take appropriate and proportionate measures to manage risks to network and information systems, prevent incidents and limit their consequences.

3. Incident-reporting duty: significant incidents must be reported within the statutory time limits to the relevant CSIRT and competent authority through the designated reporting portal.

4. Management responsibility: the management body bears ultimate responsibility for cyber-risk management. Its members must have sufficient knowledge to assess risks and security measures and must undertake appropriate training.

5. Supervision and enforcement: competent supervisory authorities will monitor compliance with the obligations under the Cbw.

The supply chain also matters

Digital resilience does not stop at the boundary of a single organisation. Many business processes depend on software vendors, cloud providers, integration partners and data exchange. Entities within scope must consider supply-chain security and may therefore impose additional cybersecurity and assurance requirements on their suppliers.

Suppliers that are not directly within scope may consequently receive more detailed questions about access management, logging, incident response, continuity, vulnerability management, subcontractors and available assurance evidence. A one-off supplier declaration is rarely enough; organisations need a repeatable process for assessing risks, documenting agreements and demonstrating follow-up.

What Semansys customers may expect

Semansys supports digital reporting, digital invoicing and digital identity. Information security, service continuity and traceable processing are therefore important components of its services.

Depending on the service and contractual relationship, customers may see Semansys request targeted information, periodically review security and access controls, manage changes through controlled processes, and maintain incident and continuity procedures. Contractual commitments and assurance information are provided through the appropriate customer and security channels.

This way of working supports cooperation but does not replace a customer's own legal scope assessment, risk assess mentor statutory responsibilities.

Practical preparation checklist

1. Confirm scope. Use the official criteria to determine whether your organisation falls within the Cbw.

2. Prepare registration. If your organisation is within scope, prepare registration through MijnNCSC before the obligation takes effect.

3. Assign ownership. Define responsibility for cyber risks, incident notifications and management reporting.

4. Update the risk assessment. Link appropriate and proportionate measures to demonstrable risks.

5. Map dependencies. Identify critical suppliers, systems, data flows and other digital dependencies.

6. Review agreements. Check contracts, incident arrangements, continuity measures and available assurance evidence.

7. Exercise decision-making. Test escalation, notification and management information for a significant incident.

8. Plan training. Provide appropriate cybersecurity training for management and relevant employees.

Start with evidence, not check marks

The core of the Cbw is not the collection of isolated documents, but demonstrable risk management. Start with the processes and services that are genuinely essential to your organisation. Record the relevant risks, the selected measures, the accountable owners and how effectiveness is reviewed.

Discuss your digital reporting  infrastructure

Would you like to explore the role that reliable regulatory digital infrastructure plays in your supply chain? Schedule a discovery call

This publication provides general information and does not constitute legal advice.