Skip to content
Back to the knowledge base

The Cybersecurity Act explained

2026-08-10

The Cyberbeveiligingswet (Cbw, Cybersecurity Act) is the Dutch implementation of the EU's NIS-2 Directive (Directive (EU) 2022/2555). The law requires organisations in designated sectors to have their cybersecurity in order, to report incidents, and to register.

Since when, and for whom

The law enters into force on 15 August 2026, with no transition period: the obligations apply from that date onward. They apply to organisations the law classifies as an essential entity or an important entity — usually mid-sized and large organisations in sectors such as energy, transport, healthcare, digital infrastructure and (decentralised) government. Article 15 Cbw sets out which ministry oversees which sector; see the page on supervisory authorities.

What the duty of care covers

Article 21, third paragraph, Cbw lists ten topics you must take measures on: from a security policy and incident handling to cryptography and assessing whether your measures actually work. The Cyberbeveiligingsbesluit (Cbb, the implementing decree) — decree of 8 July 2026, Staatsblad 2026, 189 — elaborates most of those ten topics further in articles 6 through 18. The knowledge base covers each topic on its own page, quoting the exact article number.

Reporting an incident

Alongside the duty of care, the law has a reporting duty with statutory clocks: an early warning within 24 hours, an initial assessment within 72 hours, and a final report within one month. Munitor prepares that report and keeps the clocks, but never submits anything automatically — filing is something you always do yourself, when you choose to.

What the law doesn't do, and what Munitor doesn't do

The law doesn't hand out a certification mark, and Munitor never gives a "compliant" stamp or a compliance verdict. A supervisor judges whether your measures are sufficient. Munitor helps you record what you've arranged, who owns it and what evidence backs it up, so you can demonstrate it yourself — to a supervisor, a customer or an auditor.

Even if you're not in scope yourself

Not everyone who runs into this law is in scope of it themselves. Customers who are in scope often ask their suppliers for evidence — see the page on supply-chain partners and third parties.

Sources

Also worth reading

Not sure yet whether this applies to you? Take the free scope check.

Take the free scope check