Law / Netherlands

Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and Governance

Cyberbeveiligingswet, Artt. 21 en 24

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 32 days, effective 15 August 2026.

A sector security regimes rule binding public and private bodies.

As of 12 September 2026.

What it requires

  • This binds an essential entity (Article 8 or 9) or an important entity (Article 12 or 13) drawn from Annex 1 or Annex 2; Annex 2's digital-provider entry names an online marketplace, an online search engine and a social-networking-services platform, and Annex 1's digital-infrastructure and ICT-service-management entries separately name a cloud-computing-service provider, a data-centre-service provider and a content-delivery-network provider, so a service in any of those six lines is reached at the medium-enterprise size threshold or above; the wider sector classes (energy, transport, banking, health, drinking water, public administration and the rest of the Annexes) are a designation and sector class no activity in this vocabulary expresses, and are not raised here on that account.
  • Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems you use for your work or to provide your services, and to prevent an incident or limit its effect on the recipients of your services and on other services.
  • Cover at minimum: risk analysis and information-system security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the direct suppliers and service providers you rely on; security in acquiring, developing and maintaining your systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and staff training; cryptography and, where applicable, encryption policy; personnel security, access control and asset management; and, where appropriate, multi-factor or continuous authentication, and secure voice, video, text and emergency communications.
  • Have your management board approve these measures, and ensure every board member holds the knowledge and skills to identify network-and-information-system risks, assess your cybersecurity risk-management measures, and assess their consequences for your services, within two years of this duty taking effect for a member already serving.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

The Act's own penalty provision for an Article 21 or 24 infringement is an administrative fine (bestuurlijke boete) under Article 80 (essential entity) or Article 87 (important entity), together with the corrective and enforcement powers of Chapter 15; no provision reviewed here makes the infringement itself a criminal offence.

Penalty structure

Article 80(3)(a) sets the maximum administrative fine for an essential entity's infringement of, among other provisions, Article 21, at EUR 10,000,000 or 2 percent of the total worldwide annual turnover of the undertaking to which the entity belongs in the preceding financial year, whichever is higher. Article 87(3)(a), the mirror provision for an important entity, sets the equivalent cap at EUR 7,000,000 or 1.4 percent of that turnover, whichever is higher. Both mirror NIS2 Article 34(4) and (5).

Rule
Higher of
As of
12 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The Minister the Cyberbeveiligingswet designates as competent authority for the entity's sector; the Minister of Economic Affairs for the digital-provider and digital-infrastructure sectors named above.

Settledness

As of
12 September 2026
Guidance link
https://www.ncsc.nl/cyberbeveiligingswet-nis2
Guidance body
Nationaal Cyber Security Centrum (NCSC), Ministerie van Justitie en Veiligheid
Open questions
Does the Cyberbeveiligingsbesluit and the sector-specific Cyberbeveiligingsregelingen (BWBR0052875 and its sector siblings), the administrative orders that designate the CSIRT under Article 16 and set further technical detail, create any duty beyond what Articles 21 and 24 already state?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 21 requires an essential entity or an important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems it uses for its work or to provide its services, and to prevent an incident or limit its effect on the recipients of its services and on other services, at a security level matched to the risk and covering, at minimum, risk analysis and information-system security policy, incident handling, business continuity and crisis management, supply-chain security, secure acquisition and development, effectiveness-assessment policy, cyber hygiene and training, cryptography policy, personnel and access-management security, and, where appropriate, multi-factor authentication (Article 21, paragraphs 1 to 3).

Article 24 requires the entity's management board to approve these measures and requires every board member to hold the knowledge and skills to identify network-and-information-system risks, assess cybersecurity risk-management measures, and assess their consequences for the entity's services, with a two-year transition period for a sitting member.

This Act, Wet van 8 juli 2026 (Cyberbeveiligingswet), transposes NIS2 Directive Articles 20 and 21 and, by its own Article 106, repeals the Wet beveiliging netwerk- en informatiesystemen (Wbni), the predecessor NIS1 transposition, which the consolidated register confirms lapsed on 15 August 2026, the date this Act took effect.

When LexLint raises it

  • operates_social_platform

Read the law

Consolidated text, wetten.overheid.nl, Cyberbeveiligingswet, BWBR0052872, version in force from 15 August 2026

Back to the example  ·  Lint your app