Cyberbeveiligingswet, Significant-Incident Reporting Obligations
Cyberbeveiligingswet, Artt. 25-29
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 32 days, effective 15 August 2026.
A vulnerability and incident reporting rule binding public and private bodies.
As of 12 September 2026.
What it requires
- This binds an essential entity (Article 8 or 9) or an important entity (Article 12 or 13) drawn from Annex 1 or Annex 2, on the same scope as this jurisdiction's companion risk-management row: Annex 2's digital-provider entry names an online marketplace, an online search engine and a social-networking-services platform, and Annex 1 separately names a cloud-computing-service provider, a data-centre-service provider and a content-delivery-network provider, each at the medium-enterprise size threshold or above; the wider sector classes are not raised here for the same reason.
- Give your CSIRT and competent authority an early warning without delay, or within 24 hours of becoming aware of a significant incident if immediate reporting is not possible, stating whether the incident is suspected to result from unlawful or malicious action and whether it may have cross-border effects.
- Follow with a notification, without delay or within 72 hours, updating the early warning with an initial assessment of the incident's severity and effects.
- Submit an interim report if your CSIRT or competent authority asks for one.
- Submit a final report no later than one month after your notification, describing the incident in detail, its severity and effects, the likely threat or root cause, mitigating measures applied, and any cross-border effects; if the incident is still ongoing at that point, submit a progress report instead and the final report within one month of resolution.
- Where appropriate, inform the recipients of your service of the incident and of any measures they can take in response (Article 30).
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
The Act's own penalty provision for an Article 25 to 30 infringement is an administrative fine (bestuurlijke boete) under Article 80 (essential entity) or Article 87 (important entity), together with the corrective and enforcement powers of Chapter 15; no provision reviewed here makes the infringement itself a criminal offence.
Penalty structure
Article 80(3)(a) sets the maximum administrative fine for an essential entity's infringement of, among other provisions, Articles 25 to 30, at EUR 10,000,000 or 2 percent of the total worldwide annual turnover of the undertaking to which the entity belongs in the preceding financial year, whichever is higher. Article 87(3)(a), the mirror provision for an important entity, sets the equivalent cap at EUR 7,000,000 or 1.4 percent of that turnover, whichever is higher. Both mirror NIS2 Article 34(4) and (5).
- Rule
- Higher of
- As of
- 12 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The Minister the Cyberbeveiligingswet designates as competent authority for the entity's sector, with the CSIRT designated under Article 16 receiving the notifications; the Nationaal Cyber Security Centrum (NCSC) serves as the sectoral CSIRT for a registered entity, per the NCSC's own description of its role under the Act.
Settledness
- As of
- 12 September 2026
- Guidance link
- https://www.ncsc.nl/cyberbeveiligingswet-nis2
- Guidance body
- Nationaal Cyber Security Centrum (NCSC), Ministerie van Justitie en Veiligheid
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 25 requires an essential entity or an important entity to report every significant incident to its CSIRT and competent authority in accordance with Articles 26 to 29. Article 26 requires an early warning without delay, or within 24 hours of becoming aware of the incident if immediate reporting is not possible, stating whether the incident is suspected to result from unlawful or malicious action and whether it may have cross-border effects.
Article 27 requires a notification, without delay or within 72 hours, updating the early warning with an initial assessment of the incident's severity and effect. Article 28 requires an interim report on request.
Article 29 requires a final report no later than one month after the Article 27 notification, describing the incident, its severity and effects, the likely threat or root cause, mitigating measures taken, and, where relevant, cross-border effects; an incident still ongoing at that point is instead covered by a progress report, with the final report due within one month of the incident's resolution.
This Act transposes NIS2 Directive Article 23 and, by its own Article 106, repeals the Wet beveiliging netwerk- en informatiesystemen (Wbni), the predecessor NIS1 transposition, which lapsed on 15 August 2026, the date this Act took effect.
When LexLint raises it
operates_social_platform