The Dutch Cybersecurity Act and the Critical Entities Resilience Act enter into force on 15 August 2026. Registration with the NCSC is mandatory from day one. Here is what general counsel need to do now.
On 7 July 2026, the Dutch Senate (Eerste Kamer) adopted two important new laws: de Cyberbeveiligingswet (the Cybersecurity Act, or “Cbw“) and de Wet weerbaarheid kritieke entiteiten (Critical Entities Resilience Act or “Wwke“). Both laws enter into force on 15 August 2026. Together, they form a comprehensive package: the Cbw addresses a broad range of cybersecurity obligations, implementing the EU NIS2 Directive, while the Wwke targets the physical and organisational resilience of critical infrastructure, implementing the CER Directive. The Cbw replaces the existing Wet beveiliging netwerk- en informatiesystemen (Wbni) and applies to organisations providing essential or important services across 18 critical sectors, including energy, healthcare, transport, financial market, infrastructure, drinking water, wastewater, food, digital infrastructure, and postal services. The Dutch government estimates that over 8,000 organisations are affected, and many do not yet realise it.
1. Cbw: The Cybersecurity Act
In general, organisations fall within the scope of the Cbw where they (i) operate in a sector or subsector listed in Annex I or Annex II of Cbw; (ii) qualify as a medium-sized or large enterprise within the meaning of Recommendation 2003/361/EC; and (iii) provide services or carry out activities within the EU.
New obligations include, among others: registration obligation, duty of care, reporting obligation, management board responsibility, and supervision and enforcement.
Register by 15 August 2026
The most immediate obligation is registration. Organisations in scope must register with the National Cyber Security Center (NCSC) in the national entity register via mijn.ncsc.nl by 15 August 2026. Registration requires eHerkenning or SSOnRijk.
Entities should begin preparing now, as registration will require organisational details, the sector in which they operate, contact information, and technical data such as IP ranges, domain names, and AS numbers (ASN). To assist with this process, the NCSC has published a registration checklist that organisations can use to gather the required information in advance.
Duty of care and duty to report
Beyond registration, the Cbw imposes two core obligations: the duty of care and the duty to report.
Under the duty of care, organisations are required to implement appropriate technical, operational and organisational measures to manage their cybersecurity risks. In practice, this involves amongst others, conducting a risk assessment and, based on its outcome, taking appropriate and proportionate measures to protect their network and information systems. These measures must address at least prescribed areas, such as risk analysis, incident handling, business continuity, supply chain security, access control, encryption and multi-factor authentication.
The duty to report requires organisations to report significant incidents to the Computer Security Incident Response Team (CSIRT) and the competent supervisory authority.
Contract review: managing supply chain security risks
Under Article 21(1) of the Cbw, in-scope organisations must manage the security of their relationships with direct suppliers and service providers. In practice, this means that supplier and service provider contracts should include relevant provisions such as cybersecurity clauses, incident notification obligations, audit rights and subcontractor flow-down provisions.
In-scope entities should therefore review their existing supply chain and related contracts for any gaps in relation to their Cbw obligations and ensure they are able to comply with the Cbw requirements.
Board member’s duties and responsibilities, and potential personal liability
The Cbw sets out specific duties and responsibilities for members of the management board, including approving and overseeing cyber risk management measures, as well as acquiring sufficient knowledge and skills through mandatory management board training. If these duties and responsibilities are not properly fulfilled, this could potentially give rise to personal liability.
2. Wwke: The Critical Entities Resilience Act
Where the Cbw focuses on cybersecurity, the Wwke addresses non-cyber risks: sabotage, terrorism, natural disasters and other disruptions that could affect entities that provide essential services. Unlike the Cbw, the Wwke does not apply automatically: obligations take effect only once an organisation has been formally designated as a critical entity by the relevant ministry, with first designations expected by September 2026. Once designated, an entity has nine months to complete a broad risk assessment and ten months to comply with the duty of care and incident reporting obligations. Importantly, any organisation designated as a critical entity under the Wwke automatically qualifies as an essential entity under the Cbw, meaning both regimes apply at the same time.
3. What you should do now
With the Cbw registration deadline approaching, organisations should start assessing whether they fall within scope, prepare their registration, map any cybersecurity gaps and implement cybersecurity measures, begin reviewing their supplier contracts, implement the right governance (e.g. board training) to ensure board oversight and align incident response mechanisms. The clock is ticking.