On 15 April 2026, the Dutch House of Representatives approved the legislative proposals for the Cybersecurity Act (Cyberbeveiligingswet, Cbw) and the Law on resilience of critical entities (Wet weerbaarheid kritieke entiteiten). For organizations and for the work of the NCSC, this is a major milestone.
The decisions matter because they bring the European NIS2 requirements into Dutch law and formally expand the group of organizations that will fall under the associated supervision and obligations.
What the Cybersecurity Act is designed to change
The Cybersecurity Act implements the European NIS2 directive into Dutch legislation. In practice, it replaces the current Wbni framework.
Instead of leaving cybersecurity duties scattered across different rules, the new legislation brings three core elements together for thousands of organizations:
- Duty of care (zorgplicht)
- Reporting obligation (meldplicht)
- Registration obligation (registratieplicht)
These requirements are set to become legally anchored, which means organizations will no longer be able to treat cybersecurity governance as optional or purely voluntary.
Why NCSC’s responsibilities will expand
One of the most significant operational consequences of the Cybersecurity Act is that NCSC’s scope of work increases substantially.
The update indicates that NCSC’s responsibilities will extend to roughly 8,000 organizations that will fall under its oversight once the framework is in force. That scale change is important: it means more organizations will need guidance, support, and clarity on expectations.
If you are responsible for security in a regulated organization, it’s wise to start planning now rather than waiting for the final details of implementation.
Which steps come next in the legislative process
Approval in the House of Representatives does not mean the law is fully final yet. The legislative proposals will now move to the Senate (Eerste Kamer).
Based on the standard process, a typical sequence is expected: a written report (verslag), a policy note (nota), and then a plenary debate. The overall planning targets remain ambitious, but the final timing can depend on how quickly the Senate progresses.
Timeline: expected entry into force in 2026
The planning mentioned in the update is that the measures are expected to take effect in the second quarter of 2026. However, the statement also notes that the exact pace depends on the Senate’s schedule.
In other words: organizations should prepare for 2026 implementation, while acknowledging that parliamentary timing can sometimes shift.
Cybersecurity compliance: duty, reporting, and registration
To understand what changes under the Cybersecurity Act, it helps to look at the three pillars that will be legally embedded.
Duty of care
The duty of care sets expectations for how organizations must manage cybersecurity. While the update does not list every operational requirement, it makes clear that this responsibility will be formalized, which typically translates into concrete governance actions such as risk management, organizational oversight, and security planning.
Reporting obligation
The reporting obligation focuses on what happens when incidents occur. Instead of relying solely on internal escalation, the law creates a legal channel for notifying relevant parties when certain cybersecurity events take place.
Registration obligation
Finally, the registration obligation ensures there is an official record of the organizations covered by the framework. Registration supports enforcement and oversight by allowing authorities to identify who is in scope.
If you are unsure whether your organization is covered, the next phase of implementation will likely include more practical guidance on scope and start points.
Parallel work: the Cybersecurity Decision and ministerial regulations
Legislation is only one part of the story. Alongside the parliamentary process, the update indicates that work is also underway on the implementing instruments.
Specifically, authorities are working in parallel on:
- the Cybersecurity Decision (Cyberbeveiligingsbesluit)
- the relevant ministerial regulations under the Cybersecurity Act and the critical entities resilience law
- the resilience decision related to critical entities (Besluit weerbaarheid kritieke entiteiten)
These documents usually contain the operational details organizations need in order to comply effectively. So even as the law advances to the Senate, the practical next steps will likely depend on how these instruments are finalized.
Critical entities resilience law: what it adds
In addition to the Cybersecurity Act, the House also approved the Law on resilience of critical entities. This separate track is aimed at improving resilience in areas that society depends on.
The update does not provide additional technical content in this briefing, but the existence of a dedicated law and a corresponding decision indicates that authorities are treating critical resilience as more than cybersecurity alone—likely involving broader preparedness and robustness expectations.
Practical questions organizations are asking right now
When a new compliance framework moves forward, teams naturally want answers to operational questions. The update itself points readers to topics such as the scope of organizations, the meaning of the duty of care, reporting expectations, and whether registration is required.
For many organizations, the immediate next actions will be information gathering and gap analysis—especially if you operate at scale, handle essential services, or are exposed to increasing regulatory scrutiny.
- Which organizations fall under the Cybersecurity Act?
- What exactly does the duty of care require?
- What triggers the reporting obligation?
- Do you need to register?
- Where should you start planning for CBW compliance?
Even without waiting for every detail, you can start mapping your current cybersecurity governance to the three pillars so you can move quickly when the final implementing documents arrive.
What to do now: prepare for the second quarter of 2026
Because the target entry into force is set for the second quarter of 2026, there is not much time for last-minute compliance. A sensible approach is to build readiness in layers.
First, confirm whether your organization is likely to be in scope. Second, assess whether your current processes cover duty of care elements, incident communication, and the ability to provide the required information for registration. Third, document decisions and owners so that compliance is not dependent on a single person or team.
As the Senate reviews the proposals and the Cybersecurity Decision and ministerial regulations are finalized, the most efficient organizations will be those that already understand where they stand today.
Conclusion
The approval by the Dutch House of Representatives marks a major step toward making the Cybersecurity Act (built on NIS2) and the critical entities resilience law part of Dutch law. The key changes revolve around legally anchored duty of care, reporting, and registration, while also expanding NCSC oversight to around 8,000 organizations.
The next phase is the Senate process, followed by detailed implementing instruments. With entry into force expected in the second quarter of 2026, organizations would do well to begin preparing now—especially if you want to meet compliance requirements without scrambling at the last moment.
Source: https://www.ncsc.nl/nieuws/tweede-kamer-stemt-in-met-cyberbeveiligingswet
