Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and Governance
Cyberbeveiligingswet, Artt. 21 en 24
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 32 days, effective 15 August 2026.
A sector security regimes rule binding public and private bodies.
As of 12 September 2026.
What it requires
- This binds an essential entity (Article 8 or 9) or an important entity (Article 12 or 13) drawn from Annex 1 or Annex 2; Annex 2's digital-provider entry names an online marketplace, an online search engine and a social-networking-services platform, and Annex 1's digital-infrastructure and ICT-service-management entries separately name a cloud-computing-service provider, a data-centre-service provider and a content-delivery-network provider, so a service in any of those six lines is reached at the medium-enterprise size threshold or above; the wider sector classes (energy, transport, banking, health, drinking water, public administration and the rest of the Annexes) are a designation and sector class no activity in this vocabulary expresses, and are not raised here on that account.
- Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems you use for your work or to provide your services, and to prevent an incident or limit its effect on the recipients of your services and on other services.
- Cover at minimum: risk analysis and information-system security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the direct suppliers and service providers you rely on; security in acquiring, developing and maintaining your systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and staff training; cryptography and, where applicable, encryption policy; personnel security, access control and asset management; and, where appropriate, multi-factor or continuous authentication, and secure voice, video, text and emergency communications.
- Have your management board approve these measures, and ensure every board member holds the knowledge and skills to identify network-and-information-system risks, assess your cybersecurity risk-management measures, and assess their consequences for your services, within two years of this duty taking effect for a member already serving.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
The Act's own penalty provision for an Article 21 or 24 infringement is an administrative fine (bestuurlijke boete) under Article 80 (essential entity) or Article 87 (important entity), together with the corrective and enforcement powers of Chapter 15; no provision reviewed here makes the infringement itself a criminal offence.
Penalty structure
Article 80(3)(a) sets the maximum administrative fine for an essential entity's infringement of, among other provisions, Article 21, at EUR 10,000,000 or 2 percent of the total worldwide annual turnover of the undertaking to which the entity belongs in the preceding financial year, whichever is higher. Article 87(3)(a), the mirror provision for an important entity, sets the equivalent cap at EUR 7,000,000 or 1.4 percent of that turnover, whichever is higher. Both mirror NIS2 Article 34(4) and (5).
- Rule
- Higher of
- As of
- 12 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The Minister the Cyberbeveiligingswet designates as competent authority for the entity's sector; the Minister of Economic Affairs for the digital-provider and digital-infrastructure sectors named above.
Settledness
- As of
- 12 September 2026
- Guidance link
- https://www.ncsc.nl/cyberbeveiligingswet-nis2
- Guidance body
- Nationaal Cyber Security Centrum (NCSC), Ministerie van Justitie en Veiligheid
- Open questions
- Does the Cyberbeveiligingsbesluit and the sector-specific Cyberbeveiligingsregelingen (BWBR0052875 and its sector siblings), the administrative orders that designate the CSIRT under Article 16 and set further technical detail, create any duty beyond what Articles 21 and 24 already state?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 21 requires an essential entity or an important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems it uses for its work or to provide its services, and to prevent an incident or limit its effect on the recipients of its services and on other services, at a security level matched to the risk and covering, at minimum, risk analysis and information-system security policy, incident handling, business continuity and crisis management, supply-chain security, secure acquisition and development, effectiveness-assessment policy, cyber hygiene and training, cryptography policy, personnel and access-management security, and, where appropriate, multi-factor authentication (Article 21, paragraphs 1 to 3).
Article 24 requires the entity's management board to approve these measures and requires every board member to hold the knowledge and skills to identify network-and-information-system risks, assess cybersecurity risk-management measures, and assess their consequences for the entity's services, with a two-year transition period for a sitting member.
This Act, Wet van 8 juli 2026 (Cyberbeveiligingswet), transposes NIS2 Directive Articles 20 and 21 and, by its own Article 106, repeals the Wet beveiliging netwerk- en informatiesystemen (Wbni), the predecessor NIS1 transposition, which the consolidated register confirms lapsed on 15 August 2026, the date this Act took effect.
When LexLint raises it
operates_social_platform