World Watch/Netherlands/Cybersecurity

Cybersecurity · Netherlands

Cybersecurity regulation in Netherlands (2026)

Comprehensive lawWet beveiliging netwerk- en informatiesystemen (Wbni) — currently in force (implements EU NIS1); being replaced by the Cyberbeveiligingswet (Cbw, NIS2 implementation), pending in the Senate with entry into force targeted for Q2 2026. Supervision/incident response led by NCSC-NL and sector regulators (RDI, ILT).Country index 93 · A+

Netherlands shaded by its cybersecurity status

The Netherlands currently has a horizontal cybersecurity statute in force — the Wbni (in effect since 9 November 2018) — which obliges essential-service operators and digital service providers to take security measures and report serious incidents. Its NIS2 upgrade, the Cyberbeveiligingswet (Cbw), was approved by the House of Representatives on 15 April 2026 and is awaiting Senate approval, with entry into force expected in Q2 2026. The regime is layered on top of GDPR data-breach duties and EU sectoral rules (e.g. DORA for finance), with NCSC-NL as the central coordination/incident-response body.

Key points

In-force law (Wbni)

The Network and Information Systems Security Act (Wbni) has been in force since 9 November 2018, requiring providers of essential services and digital service providers (cloud, online marketplaces, search engines) to secure their ICT and report serious incidents.

NIS2 transposition (Cbw) status

The Cyberbeveiligingswet (Cbw), transposing the EU NIS2 Directive, was approved by the House of Representatives on 15 April 2026 and is now before the Senate; entry into force is targeted for Q2 2026. The Netherlands missed the EU deadline of 17 October 2024.

Expanded scope under NIS2

The Cbw will cover 'essential' and 'important' entities across sectors such as energy, transport, healthcare, drinking/waste water, digital infrastructure, manufacturing, public administration, and certain digital services, widening the population well beyond the current Wbni.

Distributed competent authorities

Rather than a single regulator, supervision is spread across sectoral authorities: the Authority for Digital Infrastructure (RDI) for digital infrastructure/managed services and the Human Environment and Transport Inspectorate (ILT) for transport/water, with NCSC-NL acting as national coordinator and CSIRT.

Incident-reporting duties

The Wbni already mandates reporting of serious incidents to the NCSC and the sector regulator. Under the incoming Cbw/NIS2, entities must follow a tiered ladder: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month.

Registration & pre-compliance

Entities can already voluntarily register with NCSC-NL, but the mandatory registration obligation only takes effect when the Cbw enters into force; authorities advise organisations not to wait before preparing risk-management and governance measures.

Timeline - major decisions & events

Apr 15, 2026lawofficial
Dutch House of Representatives Approves Cyberbeveiligingswet (NIS2 Transposition)

The Tweede Kamer passed the Cybersecurity Act (Cyberbeveiligingswet, Cbw), transposing the EU NIS2 Directive and replacing the 2018 Wbni; the bill was forwarded to the Senate (Eerste Kamer) targeting Q2 2026 entry into force. The law expands mandatory cybersecurity risk-management, incident-reporting, and board-training obligations to approximately 8,000 entities across 18 sectors.

Digitale Overheid (Digital Government NL)
Dec 2, 2025guidanceofficial
NCTV Publishes Cybersecurity Assessment Netherlands 2025

The National Coordinator for Security and Counterterrorism released the annual threat assessment, warning that digital threats remain diverse and unpredictable and that basic cyber hygiene is the most critical defence measure. The report feeds directly into national risk-management policy and the forthcoming Cbw implementing guidance.

NCTV (National Coordinator for Security and Counterterrorism)
May 7, 2025enforcementofficial
European Commission Issues Reasoned Opinion for NIS2 Non-Transposition

After the Netherlands missed the 17 October 2024 NIS2 transposition deadline, the Commission escalated to a reasoned opinion — the second stage of EU infringement proceedings — increasing legal and political pressure on the Netherlands to accelerate parliamentary passage of the Cyberbeveiligingswet.

European Commission – Digital Strategy
Jul 2, 2024lawofficial
Draft Cyberbeveiligingswet Submitted to Tweede Kamer

The Dutch government formally introduced the Cybersecurity Act bill to the House of Representatives, launching the parliamentary review process; the bill would replace the Wbni with a NIS2-aligned framework covering 18 sectors and requiring supply-chain security audits, mandatory board training, and fines up to €10 million.

Digitale Overheid (Digital Government NL)
Dec 6, 2022guidanceofficial
Netherlands Cybersecurity Strategy 2022–2028 Published

The government released a six-year national cybersecurity strategy covering digital resilience, international cyber norms, secure hardware/software, and public–private cooperation; it also announced the merger of the NCSC, Digital Trust Center, and CSIRT-DSP into a single national cybersecurity authority to streamline incident response and guidance.

NCSC-NL
Mar 1, 2019lawofficial
Computer Crime Act III (Wet computercriminaliteit III) Enters into Force

The most expansive revision of Dutch cybercrime law granted police — with prior judicial authorisation — powers to covertly hack suspects' devices, install investigative software using zero-day exploits, and remotely render data inaccessible; it also criminalised possession of hacking tools and strengthened prosecution of ransomware and DDoS offences.

Government of the Netherlands
Nov 9, 2018lawofficial
Network and Information Systems Security Act (Wbni) Enters into Force

The Wbni transposed the EU NIS Directive into Dutch law, imposing mandatory risk-management and incident-reporting obligations on operators of essential services, designated vital providers, and digital service providers; the NCSC was designated as the national CSIRT and supervisory authorities were assigned per sector.

wetten.overheid.nl (official Dutch legislation portal)
Apr 21, 2018guidanceofficial
National Cyber Security Agenda (NCSA) Published

The government launched its third national cybersecurity strategy with seven ambitions: broad detection/response capabilities, international cyber peace and security, secure hardware and software, resilient digital infrastructure, effective cybercrime barriers, knowledge development, and a structured public–private partnership model that underpinned the Wbni framework.

ENISA (hosting official Dutch NCSA document)
Jan 12, 2012decisionofficial
National Cyber Security Centre (NCSC) Officially Established

The NCSC was formally stood up within the Ministry of Justice and Security as the Netherlands' central hub for cyber expertise, national CSIRT, and operational coordination with critical infrastructure; it was created directly in response to the 2011 NCSS and accelerated by the DigiNotar incident.

NCSC-NL
Aug 29, 2011incidentofficial
DigiNotar CA Breach: Government Revokes Certificates, CA Collapses

Following an undetected June 2011 intrusion in which attackers issued 531+ fraudulent TLS certificates (used to surveil ~300,000 Iranian Gmail users), the Dutch government revoked all DigiNotar root certificates on 29 August 2011, immediately disabling DigiD and vehicle-registration services; DigiNotar filed for bankruptcy in September 2011. The incident exposed critical single-CA dependencies and directly accelerated creation of the NCSC and the first NCSS.

ENISA – Operation Black Tulip Report
Feb 1, 2011guidanceofficial
First National Cyber Security Strategy (NCSS I) Published

The Ministry of Security and Justice published the Netherlands' inaugural National Cyber Security Strategy, establishing a whole-of-government framework for cyber defence and calling for creation of the NCSC and a Cyber Security Council with public–private representation; it was one of the earliest national cybersecurity strategies in the EU.

ENISA (hosting official Dutch NCSS I document)
Jan 1, 1993lawofficial
First Computer Crime Act (Wet computercriminaliteit I) Enacted

After an eight-year parliamentary process, the Netherlands enacted one of Europe's earliest computer crime laws, criminalising unauthorised computer access, data manipulation, and sabotage with penalties up to four years' imprisonment; it established the foundational legal framework on which all subsequent Dutch cybercrime and cybersecurity obligations were built.

Council of Europe – Octopus Cybercrime Community

Netherlands - other topics

Last verified 5/23/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →