Law / Netherlands

Cyberbeveiligingswet, Significant-Incident Reporting Obligations

Cyberbeveiligingswet, Artt. 25-29

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 32 days, effective 15 August 2026.

A vulnerability and incident reporting rule binding public and private bodies.

As of 12 September 2026.

What it requires

  • This binds an essential entity (Article 8 or 9) or an important entity (Article 12 or 13) drawn from Annex 1 or Annex 2, on the same scope as this jurisdiction's companion risk-management row: Annex 2's digital-provider entry names an online marketplace, an online search engine and a social-networking-services platform, and Annex 1 separately names a cloud-computing-service provider, a data-centre-service provider and a content-delivery-network provider, each at the medium-enterprise size threshold or above; the wider sector classes are not raised here for the same reason.
  • Give your CSIRT and competent authority an early warning without delay, or within 24 hours of becoming aware of a significant incident if immediate reporting is not possible, stating whether the incident is suspected to result from unlawful or malicious action and whether it may have cross-border effects.
  • Follow with a notification, without delay or within 72 hours, updating the early warning with an initial assessment of the incident's severity and effects.
  • Submit an interim report if your CSIRT or competent authority asks for one.
  • Submit a final report no later than one month after your notification, describing the incident in detail, its severity and effects, the likely threat or root cause, mitigating measures applied, and any cross-border effects; if the incident is still ongoing at that point, submit a progress report instead and the final report within one month of resolution.
  • Where appropriate, inform the recipients of your service of the incident and of any measures they can take in response (Article 30).

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

The Act's own penalty provision for an Article 25 to 30 infringement is an administrative fine (bestuurlijke boete) under Article 80 (essential entity) or Article 87 (important entity), together with the corrective and enforcement powers of Chapter 15; no provision reviewed here makes the infringement itself a criminal offence.

Penalty structure

Article 80(3)(a) sets the maximum administrative fine for an essential entity's infringement of, among other provisions, Articles 25 to 30, at EUR 10,000,000 or 2 percent of the total worldwide annual turnover of the undertaking to which the entity belongs in the preceding financial year, whichever is higher. Article 87(3)(a), the mirror provision for an important entity, sets the equivalent cap at EUR 7,000,000 or 1.4 percent of that turnover, whichever is higher. Both mirror NIS2 Article 34(4) and (5).

Rule
Higher of
As of
12 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The Minister the Cyberbeveiligingswet designates as competent authority for the entity's sector, with the CSIRT designated under Article 16 receiving the notifications; the Nationaal Cyber Security Centrum (NCSC) serves as the sectoral CSIRT for a registered entity, per the NCSC's own description of its role under the Act.

Settledness

As of
12 September 2026
Guidance link
https://www.ncsc.nl/cyberbeveiligingswet-nis2
Guidance body
Nationaal Cyber Security Centrum (NCSC), Ministerie van Justitie en Veiligheid

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 25 requires an essential entity or an important entity to report every significant incident to its CSIRT and competent authority in accordance with Articles 26 to 29. Article 26 requires an early warning without delay, or within 24 hours of becoming aware of the incident if immediate reporting is not possible, stating whether the incident is suspected to result from unlawful or malicious action and whether it may have cross-border effects.

Article 27 requires a notification, without delay or within 72 hours, updating the early warning with an initial assessment of the incident's severity and effect. Article 28 requires an interim report on request.

Article 29 requires a final report no later than one month after the Article 27 notification, describing the incident, its severity and effects, the likely threat or root cause, mitigating measures taken, and, where relevant, cross-border effects; an incident still ongoing at that point is instead covered by a progress report, with the final report due within one month of the incident's resolution.

This Act transposes NIS2 Directive Article 23 and, by its own Article 106, repeals the Wet beveiliging netwerk- en informatiesystemen (Wbni), the predecessor NIS1 transposition, which lapsed on 15 August 2026, the date this Act took effect.

When LexLint raises it

  • operates_social_platform

Read the law

Consolidated text, wetten.overheid.nl, Cyberbeveiligingswet, BWBR0052872, version in force from 15 August 2026

Back to the example  ·  Lint your app