| What it is | EU directive, implemented in Dutch law as the Cyberbeveiligingswet (Cbw). | A standard for an information security management system, an ISMS. |
|---|
| Who it applies to | Essential and important entities in 18 sectors. More than 8,000 Dutch organisations. | Any organisation, of any type or size, that chooses to adopt it. |
|---|
| Mandatory or voluntary | Mandatory. Registration, duty of care and incident reporting, all from day one. | Voluntary. One exception: essential entities in the government sector must apply it. |
|---|
| Applies since | 15 August 2026, when the Cyberbeveiligingswet entered into force. | Current edition published 25 October 2022, with a climate amendment added in 2024. |
|---|
| Supervisor or issuing body | Sector inspectorates: RDI, ILT, DNB, AFM, IGJ, NVWA. The NCSC runs the reporting portal. | An accredited certification body, in the Netherlands accredited by the RvA. |
|---|
| What you must be able to show | Ten duty of care elements, lettered a to j, and a management system on a PDCA cycle. | A documented ISMS: scope, risk method, Statement of Applicability, audit and review records. |
|---|
| Consequence of non-compliance | Essential entities: up to EUR 10 million or 2% of group turnover, whichever is higher. | No fine. The certificate is suspended or withdrawn, which customers and tenders notice. |
|---|
| Certification available | No. There is no NIS2 certificate and the Cbw does not require one. | Yes, by an accredited certification body. |
|---|