The Dutch Cybersecurity Law (Cbw) is currently in its final phase of legislative approval. On 6 and 7 July 2026, the Eerste Kamer will discuss the bill and vote on it. If the proposal is adopted, the law is expected to enter into force on 15 August 2026—bringing new obligations for organizations that fall under the scope.
Because the timeline is relatively short, many organizations will need to prepare now. The law’s core aim is to strengthen digital resilience by implementing the European NIS2 directive in the Netherlands.
Timeline: Eerste Kamer vote and expected start date
In early July 2026, the Eerste Kamer will both deliberate on the Cybersecurity Law and vote on the bill. This is the key step before the law can become effective.
If the vote is positive, the expected effective date is 15 August 2026. From that moment, organizations within scope will have to comply with a new set of cybersecurity and reporting requirements.
What the Cybersecurity Law covers
The Cybersecurity Law implements the European NIS2 directive for the Netherlands. It sets requirements aimed at the digital resilience of more than 8,000 organizations.
A crucial point is that each organization is responsible for determining whether it falls under the law. This means you should not wait for a “final list” before taking action—start assessing your position early.
Practical duties after the law takes effect
Once the law enters into force, organizations that are covered can expect several new obligations. These include:
- Registration with the National Cyber Security Centre (NCSC).
- A statutory duty of care for cybersecurity.
- A reporting obligation for significant incidents.
- Board members must be able to demonstrate cybersecurity knowledge.
- Risk management requirements for suppliers—including the wider supply chain.
Together, these measures push cybersecurity from a purely technical topic toward governance, accountability, and end-to-end risk management.
Why the “vendor and supply chain” requirement matters
One of the most far-reaching elements is the expectation that you manage cyber risk not only inside your own organization, but also across suppliers and the full chain of providers.
That changes how organizations should think about procurement, third-party oversight, and contractual security expectations. In practice, you may need to review how suppliers prove their security capabilities, how incidents are communicated, and how risk is tracked over time.
If your organization depends on external services—managed IT, cloud platforms, development partners, or other critical suppliers—this part of the Cybersecurity Law will likely require early planning.
Board accountability and demonstrated cybersecurity knowledge
Cybersecurity compliance does not stop at the IT department. The Cybersecurity Law includes a requirement for leadership: decision-makers must be able to demonstrate knowledge of cybersecurity.
This is significant because it turns cybersecurity governance into an explicit expectation. Organizations may need to formalize training, internal briefings, and decision processes so that responsibility can be explained and evidenced.
In other words, the question is not only “Do we have security controls?” but also “Can our leadership show that they understand the cybersecurity risks and how we manage them?”
Incident reporting for significant events
The law introduces a legal duty to report significant incidents. While the exact operational details depend on the implementation of the framework, the direction is clear: organizations must be able to detect, assess, and report incidents within the required governance model.
For many organizations, this means reviewing incident response procedures now. You may also need clearer escalation routes, roles and responsibilities, and criteria for what qualifies as “significant.”
Waiting until the law starts could lead to avoidable delays—especially if your detection, triage, and documentation processes are not yet aligned.
Start preparing now: risk analysis and registration
The NCSC’s guidance is straightforward: organizations should not wait until the effective date. Instead, begin building the required foundation in advance.
Two practical starting points are highlighted:
- Conduct an initial risk analysis. Use it to identify which cyber risks you already manage and where gaps remain.
- Map existing measures. Determine what controls and activities you already have in place for cyber risk management.
In addition, you should prepare for registration with the NCSC. That can involve administrative steps, internal documentation, and alignment across departments so the process is not treated as a last-minute task.
Legislative progress: how the bill moved forward
The bill has progressed through parliamentary review. On 2 June 2026, the Eerste Kamer issued a report describing the questions raised by members of different political factions.
Among the topics discussed were implementation, supervision, and the expected consequences for organizations. The government provided answers in a formal note.
In the procedure meeting on 23 June 2026, it was noted that one remaining question from a faction had not yet been answered. That question has since been addressed, meaning the written parliamentary treatment of the proposal has been completed.
This background matters because it indicates that most “open” questions in the written phase have already been settled—leaving the upcoming vote as the decisive step.
Related legislation: Wet weerbaarheid kritieke entiteiten (Wwke)
Besides the Cybersecurity Law, the Wet weerbaarheid kritieke entiteiten (Wwke) is also being handled. This law focuses on strengthening resilience for organizations that deliver essential services in the Netherlands.
Unlike a narrow cybersecurity-only scope, Wwke is broader: it aims to improve preparedness and protection against a range of threats, such as natural disasters, terrorism, sabotage, and other disruptions.
While this article centers on the Cybersecurity Law, it’s useful to recognize the bigger picture. In practice, organizations serving critical roles may need to think about overlapping resilience requirements—cybersecurity as part of a wider preparedness approach.
What to do next (a practical checklist)
If you want to be ready for 15 August 2026, consider the following next steps:
- Confirm whether your organization is in scope. Start with an internal assessment so you know which obligations apply to you.
- Run an initial risk analysis. Identify key cyber risks and compare them with current controls.
- Review incident response and reporting readiness. Ensure you can assess incidents quickly and document them properly.
- Strengthen supplier risk management. Look at how you evaluate vendors and how you manage cybersecurity expectations across the supply chain.
- Prepare leadership accountability. Plan cybersecurity knowledge and governance processes so the board can demonstrate understanding.
- Begin registration preparation. Gather necessary information and coordinate internally to avoid last-minute delays.
Taking these actions now can reduce implementation stress and help you build compliance into your existing security program.
Conclusion
The Cybersecurity Law is nearing the end of its parliamentary process. If the Eerste Kamer adopts the bill, the expected start date is 15 August 2026, after which covered organizations will face new duties related to NCSC registration, a statutory duty of care, significant incident reporting, board accountability, and supply chain risk management.
The most effective approach is to start early—determine whether you fall under the law, run an initial risk analysis, map current measures, and prepare for registration. That way, you are not only compliant on paper, but also ready in practice.
Source: https://www.ncsc.nl/nieuws/de-cyberbeveiligingswet-in-laatste-fase-van-vaststelling
