Cyberbeveiligingswet · in force since 15 August 2026

What is the Cyberbeveiligingswet (NIS2)?

The Dutch law that transposes the EU NIS2 directive into national obligations for digital resilience — with no transition period.

The law in short

NIS2 is the 2022 EU directive; the Cyberbeveiligingswet is the Dutch law that transposes it into national law. Both names refer to the same obligations — the law significantly widens the group of organisations that must meet cybersecurity requirements compared with the old Wbni, and places accountability explicitly with management.

In force since15 August 2026, with no transition period.
OriginDutch implementation of the EU NIS2 directive (2022/2555).
SupervisionSector-specific authorities, with the NCSC as the central reporting point.

What the law asks of you

Four core obligations, regardless of sector — the details differ per organisation, the principle doesn't.

Duty of careRisk assessment, access management, back-ups and supply-chain security in place.
Reporting dutySignificant incidents reported quickly — an initial report typically within 24 hours.
RegistrationRegistering with the supervisor or the NCSC, without delay.
Management accountabilityLeadership is responsible and must demonstrably steer compliance.

Enforcement. Non-compliance can lead to directives and fines from the supervisor; repeated or severe breaches can bring management liability into play. Don't wait for an inspection to find out where you stand.

Cyberbeveiligingswet alongside the EU AI Act

Two separate laws that are often both relevant to the same SME.

LawCoversIn force since
Cyberbeveiligingswet (NIS2) Digital resilience and incident reporting 15 August 2026
EU AI Act Responsible use of AI systems Phased since 2025

Both often affect the same organisation. Our free AI-Compliance & Risk Scan weighs both in a single 3-minute report.

Frequently asked questions

Is the Cyberbeveiligingswet the same as NIS2?
Yes. NIS2 is the EU directive; the Cyberbeveiligingswet is the Dutch law that transposes it into national law. In practice both names are used interchangeably for the same obligations.
Since when has the Cyberbeveiligingswet applied?
Since 15 August 2026, with no transition period. Organisations in scope already had to comply from that date.
Which authority supervises the Cyberbeveiligingswet?
Supervision runs through sector-specific authorities, with the NCSC (National Cyber Security Centre) as the central reporting point for cyber incidents.
Is the Cyberbeveiligingswet the same as the EU AI Act?
No, they are two separate laws that often both apply to the same SME. The Cyberbeveiligingswet covers digital resilience and incident reporting; the EU AI Act covers responsible use of AI systems. Both are covered by the same free risk scan.
I'm not sure if my company is in scope — where do I start?
Start with the free AI-Compliance & Risk Scan, which weighs your NIS2 exposure alongside AI-literacy and transparency obligations in one 3-minute report.

Know where you stand in 3 minutes

The free AI-Compliance & Risk Scan shows your exposure on the Cyberbeveiligingswet, AI literacy and transparency — with an honest report, no sales pitch.

Take the free risk scan