Since 15 August the Netherlands has had a law transposing NIS2. The Cyberbeveiligingswet, the Dutch cybersecurity act, took effect on that date together with the Wet weerbaarheid kritieke entiteiten, the act on the resilience of critical entities, which transposes the CER directive. The Minister of Justice and Security, David van Weel, presented the two measures as an important step in making both organisations and the country as a whole more resilient, recalling that digital attacks, sabotage and other disruptions can have heavy consequences.
The European deadline for transposing NIS2 was 17 October 2024. On 9 July 2026 the European Commission referred the Netherlands, along with Ireland, Spain and France, to the Court of Justice for failing to notify transposition measures. The law entered into force five weeks later.
Twenty two months late, and then five weeks. Whether the referral is what finally moved The Hague is not something the record establishes, and nobody involved has an interest in establishing it. The sequence of dates is available to anyone who wants to draw the obvious inference and keep it to themselves.
What the Cyberbeveiligingswet actually requires
The act applies to eighteen sectors, among them energy, drinking water, digital infrastructure, healthcare, public administration and transport. Four obligations follow.
Registration in the national entity register operated by the National Cyber Security Centre. Registration is not a formality with no return: it opens access to threat information and to the assistance of the sector CSIRT during an incident.
A duty of care, meaning proportionate security measures to prevent incidents or limit their effects.
Notification of significant incidents to the CSIRT and the competent authority within the statutory deadlines, through the NCSC portal. The thresholds determining what counts as significant are set by ministerial regulation and vary by sector, which means each organisation has to go and read the regulation applicable to its own.
And direct accountability at the top. The management body must approve the measures, supervise their implementation, and undergo appropriate training in order to be able to assess risks and countermeasures. That last obligation is the one that will hurt, and it should. A board can no longer hand security to the IT department and learn about it from the press.
The detail worth pausing on
Organisations are themselves responsible for establishing whether they fall within the scope of the act.
A state that overran its own deadline by twenty two months now asks companies to work out, quickly and on their own, whether they are inside the perimeter. Accountability has an unfailing tendency to travel downwards, and only downwards. Nothing in this arrangement provides for what happens to a body that missed its own date by nearly two years while telling everyone else that speed is essential.
The critical entities act
The Wwke covers roughly 500 organisations that the responsible ministries will designate as critical entities, in sectors running from energy to banking, from financial market infrastructure to nuclear, and on to food production and distribution.
Once designated, they will have nine months to carry out a risk assessment and ten months to put technical, organisational and physical measures in place. Significant disruptions must be reported within twenty four hours. The clock starts on designation, which makes the designation letters the document worth watching.
What this means outside the Netherlands
For companies with subsidiaries or suppliers in the country, the practical consequence is not abstract. It is one more national NIS2 regime, with its own register, its own notification thresholds and its own supervision, to be coordinated with obligations already running in Italy.
This is the part nobody wants to say out loud. A directive designed to harmonise cybersecurity across the Union is producing, transposition by transposition, twenty seven different compliance regimes. Same directive, different registers, different thresholds, different supervisors, different definitions of what a significant incident is in a given sector. A group operating in six member states does not get one security programme. It gets six, plus the internal function whose job is to reconcile them.
The security gain is real. The claim of harmonisation is, at this stage, mostly aspirational. With the Cyberbeveiligingswet in force, The Hague closes one of the more conspicuous gaps on the European map, and the rest of us go back to maintaining a spreadsheet of national variations that was never supposed to exist.
Raffaele Di Marzio
All my “insane” books on cybersecurity and governance are here 👇 https://cyberium.limited/bookshelf.html
