NIS2 in the Netherlands: the Cyberbeveiligingswet explained

10 min readUpdated August 12, 2026

NIS2 is the European cybersecurity directive that the Netherlands has implemented through the Cyberbeveiligingswet (Cbw, the Dutch Cybersecurity Act), in force from 15 August 2026. If you run or work for an organisation that operates in the Netherlands but you do not read Dutch, this guide is for you: it explains who is covered, what the law requires, and what that means in practice for your logging and monitoring, with the Dutch terminology you will encounter along the way.

From the NIS2 directive to the Cyberbeveiligingswet

NIS2 (Directive (EU) 2022/2555) is the successor to the first NIS directive and had to be transposed into national law by 17 October 2024. The Netherlands does so with the Cyberbeveiligingswet (Cbw), the Dutch Cybersecurity Act, which replaces the earlier Wet beveiliging netwerk- en informatiesystemen (Wbni, the Network and Information Systems Security Act). The Netherlands missed that deadline, but the law is now here: the Cyberbeveiligingswet enters into force on 15 August 2026.

There is no transition period. From that date, the duty of care (zorgplicht), the incident notification duty (meldplicht) and the registration duty (registratieplicht) with the NCSC, the Dutch national cyber security centre, apply immediately, and the management board is personally responsible for compliance. The question is no longer whether you are preparing, but whether you can demonstrate today that you manage your risks, and whether you would spot and report an incident within 24 hours.

The biggest shift compared with the Wbni: that law covered a few hundred providers of vital services. The Cyberbeveiligingswet covers more than 8,000 Dutch organisations across eighteen sectors, including mid-sized companies that never considered themselves “critical infrastructure”. If your company has a Dutch entity in one of those sectors, there is a real chance it is in scope.

Is my organisation covered?

The law distinguishes two categories, with different supervision regimes and different fines:

  • Essential entities (essentiële entiteiten): large organisations in sectors such as energy, transport, banking, financial market infrastructure, healthcare, drinking water and waste water, digital infrastructure, public administration and space.
  • Important entities (belangrijke entiteiten): medium-sized and large organisations in, among others, postal and courier services, waste management, chemicals, food, manufacturing (including medical devices and electronics), digital providers and research.

The size threshold is, as a baseline, around 50 employees or 10 million euro in annual turnover. Smaller organisations can still be covered, for instance as the sole provider of an essential service or as part of a larger group: a Dutch subsidiary of an international company is assessed in that group context. There is also a registration duty (registratieplicht): organisations covered by the law must register with the supervisory authority.

Not sure? The Dutch central government (Rijksoverheid) offers an online NIS2 self-assessment (NIS2-zelfevaluatie) that lets you formally check in a few minutes whether your organisation falls under the law, and in which category. The tool is available in English.

The duty of care: which measures must you take?

The core of the law is the duty of care (zorgplicht): appropriate and proportionate technical and organisational measures to manage the risks to your network and information systems. The directive explicitly lists, among others:

  • risk analysis and information security policies;
  • incident handling: being able to detect, analyse, contain and recover, and being able to prove it;
  • business continuity, backups and crisis management;
  • supply chain security;
  • security in the development, procurement and maintenance of systems;
  • policies to measure the effectiveness of your measures;
  • cyber hygiene and security training;
  • cryptography and, where appropriate, encryption;
  • access control, personnel security and asset management;
  • multi-factor authentication and secured communications.

New compared with the previous regime is the personal responsibility of the management board (bestuurdersverantwoordelijkheid): directors must approve the measures, oversee their implementation, and complete cybersecurity training themselves. In cases of serious negligence, directors can be held personally liable.

The notification duty: 24 hours, 72 hours, one month

Significant incidents must be reported to the national CSIRT (for most organisations the NCSC) and the supervisory authority, in three steps:

  1. Within 24 hours: an early warning, with a first assessment of whether malicious action is suspected and whether the incident could have cross-border impact.
  2. Within 72 hours: a full incident notification with an initial assessment of severity and impact and, where available, indicators of compromise (IOCs).
  3. Within one month: a final report with a detailed description of the incident, the likely root cause, the measures taken and any cross-border impact.

Those deadlines are short. If you only start collecting logs after an incident, you will miss them: saying anything meaningful about malicious action within 24 hours requires that the relevant logs already exist, are searchable, and that detection noticed the incident in the first place. See our guide on NIS2 logging requirements for what that means in detail.

Supervision, fines and liability

The Rijksinspectie Digitale Infrastructuur (RDI), the Dutch Authority for Digital Infrastructure, is the supervisory authority for many sectors; in addition, sector regulators supervise their own domain, such as DNB (the Dutch central bank) for the financial sector. Essential entities face proactive supervision (audits and inspections up front); important entities face reactive supervision (after signals or incidents).

The fines are GDPR-grade:

  • essential entities: up to 10 million euro or 2% of worldwide annual turnover;
  • important entities: up to 7 million euro or 1.4% of worldwide annual turnover.

In addition, the supervisory authority can issue binding instructions and, for essential entities, as a last resort have directors temporarily suspended from their duties.

What this means in practice for logging and monitoring

Logging and monitoring appear in almost every obligation: you cannot detect an incident, substantiate a 24-hour notification or write a final report without the right logs. In practice, the duty of care comes down to this:

Centralise your logs

Logs from servers, network equipment, identity providers, cloud services and applications belong in one searchable system. Reconstructing an incident across ten separate systems is not something you do within 72 hours.

Retain them long enough, demonstrably

The law does not set a fixed retention period; the criterion is that you can investigate and report incidents. In practice, 6 to 18 months is common, with a searchable hot tier and a cheaper archive. Document your choice and your reasoning: that is exactly what a supervisory authority will ask for.

Monitor in real time, not after the fact

The notification deadlines assume you see incidents as they happen. That requires detection rules on your logs (failed login attempts, anomalous behaviour, suspicious network connections) and alerting that reaches a human in time, without drowning in false positives.

Keep an audit trail

Who did what, and when, including inside your logging platform itself? A tamper-evident audit trail underpins both your incident reporting and your accountability towards the supervisory authority.

This is the side LogPulse covers: centralised log management with configurable retention per plan, 50+ built-in detections with MITRE ATT&CK mapping in the LogPulse SIEM, risk-based alerting that surfaces a handful of real incidents instead of thousands of notifications, and compliance reports that map your detections and data to NIS2 obligations. All data stays in the EU (GCP Amsterdam), which considerably simplifies accountability towards the regulator and your data processing agreements. To be clear: no product makes you compliant by itself, but the logging, detection and reporting foundation is the part you can put in place today.

Getting started: a step-by-step plan

  1. Establish whether you are covered using the Rijksoverheid NIS2 self-assessment, and in which category.
  2. Inform the board: they will be personally responsible and must approve the approach.
  3. Run a risk analysis and map which systems and suppliers are critical to your services.
  4. Centralise logging and set up detection: this is the foundation under both the duty of care and the notification duty.
  5. Rehearse the notification procedure: know who informs the NCSC and the supervisory authority within 24 hours, and with what information.
  6. Document everything: measures, decisions, retention periods and exercises. Compliance you cannot demonstrate does not exist as far as a regulator is concerned.

Want to know how LogPulse fills in the logging, detection and reporting side? See NIS2 compliance with LogPulse and our pricing, or start for free and set up your first detections today.

Frequently asked questions

What is the Cyberbeveiligingswet (Cbw)?
The Cyberbeveiligingswet is the Dutch Cybersecurity Act that implements the EU NIS2 directive in the Netherlands, replacing the earlier Wbni. It enters into force on 15 August 2026 with no transition period: the duty of care, the incident notification duty and the registration duty with the NCSC apply immediately from that date.
Does the Cbw apply to international companies with a Dutch entity?
Yes, if the Dutch entity operates in one of the eighteen covered sectors and meets the size threshold of roughly 50 employees or 10 million euro in annual turnover. Smaller organisations can also be covered, for instance as part of a larger group or as the sole provider of an essential service. The Rijksoverheid offers an online NIS2 self-assessment, available in English, to check formally.
What are the incident reporting deadlines under the Cbw?
Significant incidents must be reported to the NCSC and the supervisory authority in three steps: an early warning within 24 hours, a full incident notification with an initial impact assessment and available IOCs within 72 hours, and a final report within one month. Meeting the 24-hour deadline requires that your logs already exist, are searchable, and that detection noticed the incident.
Are directors personally responsible under the Cbw?
Yes. The management board must approve the security measures, oversee their implementation and complete cybersecurity training. In cases of serious negligence, directors can be held personally liable, and for essential entities the regulator can, as a last resort, have directors temporarily suspended from their duties.
How long must logs be retained under NIS2 in the Netherlands?
The law sets no fixed retention period; the criterion is that you can investigate and report incidents. In practice, a risk-based 6 to 18 months is common, with a searchable hot tier and a cheaper archive. Document your choice and reasoning: that is exactly what the supervisory authority will ask for. No product makes you compliant by itself, but centralised logging with demonstrable retention is a foundation you can put in place today.

Logging and monitoring, on one EU-hosted engine

Centralise, retain and monitor your logs with AI-assisted search and a risk-based SIEM, GDPR-compliant and hosted in the EU. Start free.

Start free

We use cookies to analyze site traffic and improve your experience. No cookies are placed without your consent. Privacy Policy