Skip to content

National Annex — Netherlands (NL)

Status (July 2026): Entering into force — verify. Community-maintained orientation, not legal advice — verify against the official gazette and authority guidance before relying on it. Corrections welcome (see CONTRIBUTING.md).

NIS2 implementation

Field Value
Implementing law Cyberbeveiligingswet (Cbw, bill 36.764) + Wet weerbaarheid kritieke entiteiten (CER) — adopted by the Tweede Kamer 15 April 2026; entry into force expected ~1 July 2026 pending Senate (verify — may be in force now)
Competent authority RDI (Rijksinspectie Digitale Infrastructuur) + sector authorities
National CSIRT / reporting NCSC-NL
Official starting point https://www.ncsc.nl

Country notes for your CDC

NCSC-NL published the Cbw/NIS2 Control Framework and a self-assessment ('NIS2 Zelfevaluatie') — use them as evidence structure; duty of care applied in practice ahead of the law.

Standard checklist (all countries)

  • [ ] Applicability determined per legal entity and sector; recorded in the regulatory applicability register (GOVERN)
  • [ ] Entity registration completed with the national authority where required
  • [ ] Incident-reporting procedure drilled against the national channel and the 24 h early-warning clock (RESPOND)
  • [ ] Contact established with the national CSIRT before the first incident
  • [ ] Data protection authority contact and GDPR Art. 33 flow prepared (runs in parallel with NIS2 reporting)
  • [ ] National guidance/frameworks mapped to your control evidence (see note above)

Selector tag

nl-nat — tick "Netherlands" in tools/regulatory-profile.html to include this country's references.

Open CDC Framework (CC BY 4.0).