Cybersecurity Act
Cybersecurity is an essential part of your business operations. The new Cybersecurity Act (Cyberbeveiligingswet; “Cbw”) transposes the European NIS2 Directive into national law. The Cbw requires organizations to implement appropriate security measures and report incidents. The Cbw replaces the Network and Information Systems Security Act and significantly expands the obligations. The obligations under the Cbw are not merely voluntary guidelines: since they came into force on 15 August 2026, the obligations have become directly enforceable.
The Cbw focuses on organizations classified as “essential” or “important” entities, including companies in sectors such as energy, healthcare, transportation, drinking water, digital infrastructure, and telecommunications. The new law covers more organizations than before, and the obligations are more specific and stringent. The Cbw includes, among other things, a duty of care comprising ten (specific) measures. You can also find these in this blog.
Cyber risk management, incident response, and reporting are therefore not merely technical issues but legal obligations that must be ensured at the management level. Organizations that fail to prepare in a timely manner risk fines, enforcement proceedings, and damage to their reputation. This applies equally to their directors, as they bear ultimate responsibility for compliance with the Cbw obligations and may be held personally liable for it.
What We Do
We have expertise regarding the background, scope, and practical implications of the legislation. We can advise organizations subject to the Cbw on matters such as:
- Compliance assessment and risk analysis: Is your organization subject to the Cbw, and where do the greatest legal risks lie?
- Assistance with information requests, investigations, and enforcement actions by regulatory authorities, including the National Inspectorate for Digital Infrastructure (Rijksinspectie Digitale Infrastructuur; “RDI”) and sector-specific regulators
- Advice and representation at all (appeal) stages: submission of comments, objections, (higher) appeals, and preliminary injunctions
- Advice on policy and contracting. We advise on governance processes, board responsibility, and contractual obligations toward suppliers and supply chain partners
- Incident response: rapid legal assistance in the event of cyber incidents, reporting obligations, and potential consequences
Our approach is both strategic and pragmatic: we quickly identify what is important to your organization and what is feasible. In doing so, we combine legal expertise in enforcement and compliance advice with a focus on practical impact. Our attorneys are ready to advise and guide your organization on the legal aspects of cyber compliance, oversight, and enforcement.
For more information, see the interview with our experts Machteld Robichon and Bente van Kan in *Data Cybersecurity & Privacy* or read the following blog posts, among others:
- The Cybersecurity Act: A New Legal Foundation for Digital Resilience
- The Scope of the Cybersecurity Act
- Directors and the Cybersecurity Act
- New Ministerial Regulations Under the Cybersecurity Act: What Does the Ministry of Economic Affairs’ Regulation Mean for Your Sector?
Do you have questions about the Cybersecurity Act, the duty of care, or directors’ liability? Or are you facing a significant incident? Feel free to contact Machteld Robichon, Bente van Kan, or Lucas de Vet. And in the latter case, please consult the below step-by-step plan, which can be downloaded here:
