The Cybersecurity Act: set to come into force next month
On Tuesday 7 July 2026, the bill for the Cyber Security Act (“Cbw”) was passed by the Senate, together with the Critical Entities Resilience Act (“Wwke”). Earlier, on 15 April, the House of Representatives had already approved the bill. The Act will come into force on 15 August 2026. The Cbw implements the European NIS2 Directive and will replace the current Network and Information Systems Security Act (“Wbni”).
What does this mean for you?
From 15 August 2026, the obligations under the Cbw will apply to more than 8,000 organisations that provide essential or important services. From that date, organisations falling within the scope of the Wwke will be designated as critical organisations.
Organisations will need to check for themselves whether they fall within the scope of the Cbw. They can do this, for example, using this self-assessment tool provided by the central government. The Act applies to 18 sectors, such as banking, energy, digital service providers and digital infrastructure.

Source: https://www.nctv.nl/onderwerpen/c/cyberbeveiligingswet/welke-organisaties-vallen-onder-de-cyberbeveiligingswet
Key obligations under the Cbw
As the requirements will apply from 15 August 2026, it is important that organisations take steps now to ensure they are compliant. You can read more about the content of these requirements in our previous blog posts dated 7 April, 30 October and 19 September. In brief, the key requirements are:
- Registration requirement: Organisations must register in the register of entities via the National Cyber Security Centre (NCSC). Organisations can start preparing now using this guide. Once registered, organisations can make use of the services of their Computer Security Incident Response Team (“CSIRT”) to help enhance their resilience.
- Duty of care: Organisations must take appropriate measures to manage risks to the security of their network and information systems. The duty of care under the Cbw is risk-based, meaning that organisations may, on the basis of a risk analysis to be carried out by them, determine for themselves the measures to be taken within the framework of that duty of care to prevent incidents and limit their consequences.
- Reporting obligation: Organisations must report significant incidents to the CSIRT and the competent supervisory authority via the reporting portal.
- Directors bear ultimate responsibility: The directors of organisations bear ultimate responsibility for compliance with all Cbw obligations. To this end, they must possess demonstrable knowledge and skills to assess risks and security measures and must undertake regular training in this regard. See also our previous blog on directors and the Cbw.
What’s on the agenda?
European Commission guidelines
In the Memorandum following the second report (29 June), the Minister for Justice and Security (the “Minister”) answered questions from the Senate regarding the bill. A frequently raised concern is the expected regulatory burden. The Minister explains that, when drafting the Cbw within the framework of the NIS2 Directive, keeping the regulatory burden on businesses low was always a key principle, particularly about the supply chain.
According to the minister, the European Commission is also focusing on this issue. The Commission proposes to draw up guidelines containing recommendations on the level of detail and the format that companies should use when (in accordance with their duty of care) requesting information from parties in their supply chain. This could ease the burden on suppliers and service providers and ensure a consistent and efficient approach to securing the supply chain. The minister has welcomed this proposal, particularly with regard to the supply chain.
Cybersecurity Decree
The Cybersecurity Decree, which implements the rules for the implementation of the Cbw, is expected to come into force at the same time as the Cbw. On 1 June, the Advisory Division of the Council of State issued an opinion recommending that the draft decree be amended in four areas: the retention period for personal data; the criteria for defining a ‘significant incident’; the designation of CSIRTs by or pursuant to an order in council rather than by ministerial regulation; and the follow-up phase following a significant incident.
In addition, the various ministerial regulations will also be published.
Getting started
If it is not yet clear whether your organisation falls within the scope of the Cbw, this is the first step to take, given that it comes into force on 𝟏𝟓 𝐚𝐮𝐠𝐮𝐬𝐭𝐮𝐬 𝟐𝟎𝟐𝟔.
Questions about the legal implications of the Cbw: from scope analysis to directors’ liability and supervision & enforcement. Whether you’re a director or representing your organisation, please get in touch with Machteld Robichon, Bente van Kan or Lucas de Vet.