blog hero

Cybersecurity Blog

Stay updated on the latest trends and insights in cybersecurity.

Date: 8/16/2026

Cybersecurity

The Dutch Cybersecurity Act is in force: from knowledge to demonstrable resilience

The Dutch Cybersecurity Act entered into force on 15 August 2026. How do you move from understanding NIS2 to implementation and demonstrable cyber resilience?

The Dutch Cybersecurity Act is in force: from knowledge to demonstrable resilience

TL;DR

The Dutch Cybersecurity Act has been in force since 15 August 2026. For organisations in scope, the work moves from preparation to execution. The hard part is rarely reading the law. It is translating it into your own organisation — and knowing whether it holds up when it has to.

A lot has been written about the Dutch Cybersecurity Act this summer. Most of it stops exactly where the interesting part begins.

On 15 August 2026 the Cyberbeveiligingswet and the accompanying Cyberbeveiligingsbesluit entered into force. The Cbw is the Dutch implementation of the European NIS2 Directive. For organisations in scope, NIS2 is no longer something for next year's plan.

What changes is not really what is being asked. Duty of care, incident reporting, registration, supervision and management accountability were all visible on the horizon, and risk management is the basis for measures that are appropriate and proportionate. What changes is when you have to be able to show it.

So the question shifts. No longer only:

What does the Dutch Cybersecurity Act require from us?

But mainly:

Can we make that work inside our own organisation, and demonstrate that it does?

There is more distance between those two questions than most roadmaps admit.

Knowing is not the same as being able

We look at this in three layers: Knowledge, Skills & Abilities. Not because it sounds neat, but because organisations get stuck at each of them, and the fix is different every time.

Knowledge: understanding what is required

The first layer is knowledge. Do you understand which parts of NIS2 and the Dutch Cybersecurity Act apply to your organisation? That covers:

  • whether your organisation falls within the scope of the act;
  • which duty-of-care, reporting and registration obligations apply;
  • where management accountability sits;
  • which sector-specific rules or additional requirements are relevant;
  • which network and information systems and services are in scope.

That first question is the most important one, and organisations have to answer it themselves. No letter arrives telling you that you are in scope.

There are plenty of routes to that knowledge. You can read the legislation, the Cyberbeveiligingsbesluit and the related regulations yourself. You can use the official NCSC guidance, read professional analysis, or spend an afternoon with peers who are working through the same questions.

Knowledge is necessary. But no organisation ever became more resilient by reading a law.

Skills: translating it into your own organisation

The second layer is the translation. Can you turn legal requirements into concrete risks, governance, processes and measures that fit your environment? In practice that means:

  • identifying cyber risks and putting them in order of priority;
  • assigning ownership and responsibility, with an actual name attached;
  • selecting appropriate technical and organisational measures;
  • setting up incident and reporting processes that also work at night;
  • managing supply-chain exposure;
  • organising continuity and recovery;
  • being able to explain why a measure is appropriate and proportionate.

That last point tends to be underestimated. The goal is not to do everything, but to explain why you do this and not that. It is a conversation about risk, not about a list.

Abilities: actually making it work

The third layer is the hardest, and the only one that counts on a bad day.

Having an incident response plan is different from knowing whether the manager on duty knows who to call at three in the morning.

Having backups is different from being able to demonstrate recovery, within a time the organisation can live with.

Having a segmentation design is different from knowing whether that separation actually exists in the field.

Having a supplier policy is different from knowing which vendor can reach a critical system remotely tomorrow.

Abilities are about applying knowledge and skills, testing them and sustaining them — including after the people who designed it all have moved on.

The useful thing about that layer is that you cannot tick it off. You can only practise it.

Where it tends to stall

What we run into at organisations is rarely a problem on the first layer. The law has been read, there is a gap analysis, there is a steering group. And still it stalls, usually for three recognisable reasons.

The first is that the scope question stays open too long. Organisations have to determine for themselves whether they fall within the scope of the Cbw, and while that is undecided every following step stays non-committal. A provisional answer with reasoning behind it beats no answer at all.

The second is that measures get chosen without anyone being able to retell the risk behind them. You end up with a list that looks right on paper and nobody who can explain why those ten items are on it and another fifteen are not.

The third is that the supply chain stays out of view. The internal environment is described neatly, but the supplier watching over your shoulder remotely, the managed service provider with its own VPN and the package the whole service depends on appear in no risk assessment at all. Which is often exactly where it goes wrong.

There is no single correct learning route

Not everyone needs the same path. Some professionals want to work through the legislation and official guidance themselves, and the source is enough for them. Others learn mainly from practical experience, mentoring, or talking to someone who has already done it once.

If you are looking for more structure, self-study or formal training helps you see the parts in relation to each other rather than as a set of separate obligations. For that we offer the official PECB NIS 2 Directive Lead Implementer. The course is delivered in English. Self-study is available immediately; if there is sufficient interest we will schedule a live-online edition.

A course does not make you compliant

Let us be clear about this: a course, certification, checklist, gap assessment or framework does not automatically make an organisation compliant with the Dutch Cybersecurity Act. Anyone claiming otherwise is selling something.

Training helps with Knowledge and Skills. After that the real work starts: assigning ownership, implementing measures, bringing people along, testing, adjusting, and being able to show that the chosen approach does what you expect of it.

Knowledge helps you understand what needs to be done. Capability determines whether you can actually make it work.

From compliance to resilience

Compliance should not be the only objective. An organisation can be extensively documented and poorly prepared for a serious incident. That is not a theoretical scenario; it is the most common outcome of a programme steered by documents.

So alongside "can we demonstrate compliance with the Dutch Cybersecurity Act?" the other question belongs on the table: "do our people know what to do, can they execute it, and does it work when it matters?"

Do the right things well, and compliance becomes a consequence rather than the goal. The other way around rarely works.

If you want to know where you stand today, an honest baseline is usually more useful than another roadmap. That is what our readiness work around NIS2, ISO 27001 and IEC 62443 is for.

And then there is OT

For organisations that depend on industrial processes, this translation does not stop at IT. Where critical services depend on OT, those risks and dependencies have to be included as well. That is a different world, with different asset lifetimes, different suppliers and different consequences when you change something.

Our analysis of the attack on a Polish power plant shows how that goes wrong in practice: no zero-day, just a chain of individually reasonable decisions. In a follow-up article we will look at how IEC 62443 can help structure NIS2 and Cbw risk management in industrial environments. Helping is not the same as delivering compliance, and it is worth keeping those apart.

PECB NIS 2 Directive Lead Implementer

Delivered in English. Self-study is available immediately; a live-online edition is scheduled when there is sufficient interest.

View the training

The CyberBusters takeaway

Whichever route you take — reading the legislation yourself, learning from peers, self-study, formal training or support with implementation — make sure the knowledge ends up in measures that work in practice.

The act is in force. The interesting phase starts now.

If you would like to talk through the Dutch Cybersecurity Act, NIS2 or practical implementation in your own organisation, feel free to get in touch.

Sources

CyberBusters Logo

CyberBusters B.V.

Registered at the Chamber of Commerce under number: 89637631

CyberBusters supports boards and executive teams when cyber risk threatens continuity, safety or trust. We are brought in when the situation is complex, pressure is high and decisive leadership is required...

Cyber risk is a boardroom priority. When the stakes are high, call CyberBusters.

© 2026 - All rights reserved.