Changeflow GovPing Data Privacy & Cybersecurity Tweede Kamer Approves Cyberbeveiligingswet, NIS...
Priority review Notice Added Final

Tweede Kamer Approves Cyberbeveiligingswet, NIS2 Implementation

Favicon for www.ncsc.nl Netherlands NCSC News
Detected
Email

Summary

On April 15, 2026, the Dutch House of Representatives (Tweede Kamer) approved the Cyberbeveiligingswet (Cbw) and the Wet weerbaarheid kritieke entiteiten, implementing the EU NIS2 directive into Dutch law and replacing the current Wbni. The law establishes duty-of-care, reporting, and registration obligations for approximately 8,000 organizations under NCSC responsibility. The bills now proceed to the Eerste Kamer (Senate) for further consideration, with planned implementation in Q2 2026.

“De Cbw implementeert de Europese NIS2-richtlijn in Nederlandse wetgeving en vervangt de huidige Wbni.”

NCSC-NL , verbatim from source
Why this matters

Entities that currently fall outside Wbni scope but may qualify as essential or important entities under NIS2 should proactively assess their classification. Organizations uncertain about their status can use the NCTV organizational classifier linked in the source materials. Given the Q2 2026 implementation target, affected entities have a narrow window to establish duty-of-care, reporting, and registration procedures.

AI-drafted from the source document, validated against GovPing's analyst note standards . For the primary regulatory language, read the source document .
Published by NCSC-NL on ncsc.nl . Detected, standardized, and enriched by GovPing. Review our methodology and editorial standards .

About this source

GovPing monitors Netherlands NCSC News for new data privacy & cybersecurity regulatory changes. Every update since tracking began is archived, classified, and available as free RSS or email alerts — 3 changes logged to date.

What changed

The Tweede Kamer has approved the Cyberbeveiligingswet (Cbw), which transposes the EU NIS2 Directive into Dutch law and replaces the existing Wbni framework. The approved legislation introduces legally anchored duty-of-care, mandatory reporting, and registration requirements for essential and important entities across multiple sectors.

Organizations that will fall within scope—estimated at over 8,000 entities—should begin assessing their NIS2 classification and preparing compliance measures. NCSC-NL's supervisory mandate expands significantly under the new law. The bills now advance to the Eerste Kamer, with implementation targeted for Q2 2026.

Archived snapshot

Apr 23, 2026

GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.

Tweede Kamer stemt in met Cyberbeveiligingswet

Nieuwsberichten 15 april 2026 Cyberbeveiligingswet (NIS2) Vandaag, 15 april, heeft de Tweede Kamer de wetsvoorstellen voor de Cyberbeveiligingswet (Cbw) en de Wet weerbaarheid kritieke entiteiten aangenomen. Dat is een belangrijke stap, ook voor ons werk bij NCSC.

Wat betekent dit?

De Cbw implementeert de Europese NIS2-richtlijn in Nederlandse wetgeving en vervangt de huidige Wbni. Daarmee worden zorgplicht, meldplicht en registratieplicht voor duizenden organisaties in Nederland wettelijk verankerd. Voor NCSC betekent dit dat ons werkterrein significant uitbreidt: naar meer dan circa 8.000 organisaties die straks onder onze verantwoordelijkheid vallen.

Wat zijn de volgende stappen?

De wetsvoorstellen gaan nu naar de Eerste Kamer. Verwacht wordt een verslag, een nota en een plenaire behandeling. De planning blijft: inwerkingtreding in het tweede kwartaal van 2026. Of die planning precies wordt gehaald, hangt af van het tempo van de Eerste Kamer.

Parallel wordt ook gewerkt aan het Cyberbeveiligingsbesluit en de ministeriële regelingen.


Meer weten?

Heeft deze pagina je geholpen? Ja Nee Leave this field blank

Named provisions

Zorgplicht Meldplicht Registratieplicht

Get daily alerts for Netherlands NCSC News

Daily digest delivered to your inbox.

Free. Unsubscribe anytime.

About this page

What is GovPing?

Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission

What's from the agency?

Source document text, dates, docket IDs, and authority are extracted directly from NCSC-NL.

What's AI-generated?

The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.

Last updated

Classification

Agency
NCSC-NL
Instrument
Notice
Branch
Executive
Source language
nl
Legal weight
Non-binding
Stage
Final
Change scope
Substantive

Who this affects

Applies to
Government agencies Healthcare providers Technology companies
Industry sector
2210 Electric Utilities 5170 Telecommunications 6211 Healthcare Providers
Activity scope
Cybersecurity compliance Incident reporting Registration obligations
Geographic scope
NL NL

Taxonomy

Primary area
Cybersecurity
Operational domain
Compliance
Compliance frameworks
NIST CSF
Topics
Critical Infrastructure Protection Data Privacy

Get alerts for this source

We'll email you when Netherlands NCSC News publishes new changes.

Free. Unsubscribe anytime.

You're subscribed!