Live Blog

New Dutch cyber and critical-entity resilience laws: five practical priorities

As of 15 August 2026, two important new resilience laws are in force in the Netherlands: the Cyberbeveiligingswet (“Cbw”), and the Wet weerbaarheid kritieke entiteiten (“Wwke”).

The legislation was approved by the Dutch Senate on 7 July 2026. It comes at a time when Dutch authorities continue to warn about cyberattacks, sabotage and other hybrid threats that could disrupt vital services and infrastructure. More than 8,000 organizations are expected to fall within the scope of the Cbw alone.                                                        

Two laws, one resilience agenda

The Cbw implements the EU NIS2 Directive in the Netherlands and replaces the previous Wet beveiliging netwerk- en informatiesystemen. It considerably broadens the number of sectors and organizations subject to statutory cybersecurity obligations.

Depending on their size, activities and sector, organizations may be classified as either an essential entity or an important entity. Both categories are subject to broadly the same core obligations, although essential entities face a more proactive supervisory regime. For most organizations, there will be no individual letter confirming that the Cbw applies. They are expected to assess their own position against the statutory scope.

The Wwke implements the EU Critical Entities Resilience Directive (“CER Directive”). While the Cbw focuses primarily on cybersecurity, the Wwke takes a broader, all-hazards approach. It addresses physical, organizational and operational threats, including sabotage, natural hazards, pandemics and dependencies that could interrupt the provision of essential services.  

Unlike the Cbw, the Wwke is designation-based. The relevant minister will formally designate critical entities. Once designated, an entity generally has nine months to complete its risk assessment and ten months to implement the applicable duty of care and incident-reporting arrangements. A designated critical entity will also qualify as an essential entity under the Cbw, although not every Cbw entity will be subject to the Wwke.  

In practical terms, the two laws should not be treated as separate compliance exercises. Together, they create a broader resilience framework connecting cybersecurity, physical security, business continuity, crisis management, supplier risk and corporate governance.

What should organizations do now?

1. Confirm the organization’s scope

The first priority is to establish whether the Cbw applies and, where relevant, whether the organization could be designated under the Wwke.

This assessment should consider the precise legal entity, sector, services provided, employee numbers and financial thresholds. Corporate groups should avoid relying solely on a group-level assessment, since applicability and regulatory responsibilities may differ between individual entities.

Organizations within the Cbw’s scope must also register the required information through the national entity register via MijnNCSC and keep that information current.  

2. Establish clear board ownership

The Cbw makes cybersecurity a governance issue, not simply an IT responsibility. Management bodies are expected to approve and oversee cybersecurity risk-management measures and maintain sufficient knowledge to understand the relevant risks.

Organizations should therefore clarify who is accountable for Cbw and Wwke readiness, how management receives assurance, and how material risks and incidents are escalated. Existing committee structures, management information and internal audit plans may also need to be updated.  

3. Rehearse the incident-reporting process

The Cbw introduces a staged reporting process for significant incidents. An early warning may be required within 24 hours, followed by a more detailed notification within 72 hours and, in relevant cases, a final report within one month.

This leaves little time for uncertainty about decision-making. Organizations should define who assesses significance, who has authority to notify, and how information is collected from security teams, service owners, suppliers and senior management. The process should also account for sector-specific reporting obligations.  

Once the Wwke reporting duty applies to a designated entity, incidents that significantly disrupt essential services may also need to be reported within 24 hours. An integrated reporting matrix will be important for organizations that could face several regulatory regimes simultaneously.  

4. Strengthen supply-chain and resilience controls

The Cbw requires appropriate and proportionate technical, operational and organizational measures. These cover areas such as incident handling, business continuity, vulnerability management, access control, security awareness and supply-chain security.

The supply-chain component is particularly significant. In-scope organizations will increasingly require direct suppliers and service providers to demonstrate appropriate security, timely incident notification and continuity arrangements. Even organizations outside the direct statutory scope may therefore experience new contractual, audit and assurance requirements.  

The Wwke adds a wider resilience perspective. Organizations should consider not only cyber threats, but also physical access, utilities, facilities, key personnel, geographic concentration and other dependencies that could affect essential services.

5. Integrate privacy, DPO and GDPR processes

Cybersecurity and privacy teams should not operate separate incident processes. A ransomware attack, compromised supplier or unauthorized access incident could trigger reporting under the Cbw, the GDPR, sector-specific rules and contractual arrangements.

The thresholds are not identical. A significant Cbw incident is not automatically a personal data breach, and a GDPR-reportable personal data breach will not necessarily meet the Cbw significance threshold. Where both regimes apply, the organization may need to provide an initial Cbw warning within 24 hours and notify the Dutch Data Protection Authority within 72 hours, unless the GDPR risk threshold is not met.  

The Data Protection Officer should be involved promptly where an incident raises personal data protection issues. At the same time, operational ownership should remain clearly allocated to management, the CISO, the incident-response team or the crisis-management function, preserving the DPO’s independent advisory and monitoring role.  

A single incident procedure with parallel legal and regulatory assessments is likely to be more effective than separate cyber, privacy and continuity procedures. Supplier contracts should also require sufficiently rapid notification and access to information to support both the 24-hour and 72-hour reporting windows.

From compliance to demonstrable resilience

The central message is that the Cbw and Wwke are not only about policies or formal compliance. Organizations will need to demonstrate that risks are understood, responsibilities are allocated, measures are implemented and incidents can be assessed and escalated within hours.

The most effective approach will be one integrated resilience programme connecting enterprise risk, cybersecurity, physical security, business continuity, procurement, privacy and crisis communications. The immediate test is straightforward: can your organization make a defensible reporting decision quickly, and can it later produce the evidence supporting that decision?