Skip to content
Beveiligingsnieuws

Cybersecurity and critical entities law: 15 Aug 2026

Cyberbeveiligingswet 15 augustus

On 7 July 2026, the Dutch Senate approved two important laws: the Cybersecurity law (Cbw, based on the EU NIS2 directive) and the Critical Entities Resilience Act (Wwke, based on the EU CER directive). Together, they aim to strengthen both digital and physical resilience of organizations facing growing threats—from cyber incidents to sabotage and natural disasters.

Both laws enter into force on 15 August 2026. From that date, new obligations will apply to more than 8,000 organizations under the cybersecurity law. In addition, organizations that fall under the Critical Entities Resilience Act will be formally designated as critical entities.

Below, we break down what these changes mean in practice and how you can prepare in time.

Why the new cybersecurity law matters

The cybersecurity law implements the European NIS2 directive into Dutch legislation. It replaces the current Network and Information Systems Security Act (Wbni). A key point for organizations: you remain responsible for checking whether your activities fall within scope.

In general, the cybersecurity law applies to organizations that provide essential or important services. Oversight covers organizations in 18 sectors, including energy, drinking water, digital infrastructure, healthcare, public administration, and transport.

Key obligations from 15 August 2026

If you determine that your organization is within scope, you should expect several concrete duties once the cybersecurity law starts. The requirements are designed to reduce the likelihood of incidents and to limit impact when disruptions occur.

1) Registration requirement with the NCSC

From 15 August 2026, organizations subject to the cybersecurity law must register in the entities register via the National Cyber Security Centre (NCSC). The registration itself is an early step—because it is a prerequisite for further alignment with support and guidance.

2) Duty of care for network and information security

Organizations must take measures to manage risks to the security of their network and information systems. That also includes taking steps to prevent incidents or to reduce their consequences if something goes wrong.

In other words, compliance is not just about having policies on paper. The intent is to ensure practical cybersecurity controls are in place, geared toward risk management and resilience.

3) Incident reporting obligations

Another major change is the reporting duty. Organizations must report significant incidents within the statutory timeframes. Reports must be sent to the relevant CSIRT and the competent authority via the designated reporting portal.

Because reporting timelines are time-bound, it’s wise to prepare an internal process for triage, decision-making, and communication before 15 August 2026.

4) Board accountability for cyber risk management

The cybersecurity law places final responsibility for cyber risk management at board level. Decision-makers must have sufficient knowledge to evaluate cyber risks and security measures.

To support that, board members are expected to follow an appropriate training so they can effectively oversee cybersecurity decisions.

5) Supervision and enforcement

Supervisory authorities will check whether organizations comply with the cybersecurity law requirements. This means that preparation should include both documentation and operational measures, not only awareness.

What you should do before 15 August 2026

With the entry date approaching, many organizations will need to move from “assessment” to “implementation.” The cybersecurity law explicitly highlights preparation efforts, and registration is an immediate priority.

First step: confirm whether your organization falls under the cybersecurity law. Then plan your actions around three early milestones: registration, internal risk controls, and incident reporting readiness.

Create a registration plan (and start now)

Registration becomes mandatory per 15 August 2026. To avoid last-minute problems, it is recommended to prepare registration processes ahead of time using a practical checklist. After registration, organizations can connect to the services offered by their CSIRT.

Use CSIRT services to strengthen resilience

Once registered, organizations can align with CSIRT support. CSIRTs provide products and services aimed at increasing organizational resilience and offering support in the event of an incident.

So, registration is not only an administrative step—it also helps enable the assistance framework intended by the cybersecurity law.

Critical Entities Resilience Act (Wwke): who is affected?

In parallel, the Critical Entities Resilience Act implements the EU CER directive. Its purpose is to better protect critical infrastructure and economic activities across Europe against threats, including the consequences of terrorist offenses, sabotage, and natural disasters.

This act applies to approximately 500 organizations. In any case, it covers sectors such as energy, transport, banking, infrastructure for the financial market, healthcare, drinking water, wastewater, digital infrastructure, public administration, spaceflight, nuclear, chemicals, the sector for turning and managing (as reflected in the listed scope), meteorology, and the production, processing, and distribution of food.

Importantly, an organization is only covered when it is designated as a critical entity by the relevant minister.

How the two laws relate in practice

Although they are different instruments, the cybersecurity law and the Critical Entities Resilience Act share a common theme: resilience. The cybersecurity law focuses on cyber-related obligations for a larger group of organizations, while the Critical Entities Resilience Act targets a smaller set of organizations designated as critical entities, with emphasis on protecting essential systems and services.

If you operate in sectors that are heavily interconnected—such as energy, healthcare, digital infrastructure, or transport—you may need to consider both sets of requirements, depending on your role and possible designation status.

Common preparation themes to consider

Even though each organization’s situation is unique, the duties point to several recurring preparation areas:

  • Scope determination: confirm whether your services fall under the cybersecurity law.
  • Risk management: define and maintain measures that address cyber risks to networks and information systems.
  • Incident response readiness: design an internal workflow to assess significance and report within legal timeframes.
  • Governance: ensure board-level oversight, including training to support effective decision-making.
  • Coordination: plan how your organization will connect with CSIRT services after registration.

Approaching these themes early makes the compliance process more realistic and less disruptive.

Conclusion: start planning now

The approval on 7 July 2026 means the countdown is official: on 15 August 2026, the cybersecurity law and the Critical Entities Resilience Act will take effect. From that moment, organizations that are in scope under the cybersecurity law must register with the NCSC, strengthen cybersecurity controls through a duty of care, and report significant incidents within statutory timeframes—while board responsibility becomes central.

With deadlines that affect both operational processes and governance, preparation should start before registration day. By confirming your scope, setting up risk and reporting processes, and arranging board readiness, you can position your organization to comply and—more importantly—to improve resilience against future threats.

Source: https://www.ncsc.nl/nieuws/cbw-en-wwke-vanaf-15-augustus-2026-van-kracht