Does the Cyberbeveiligingswet apply to your organisation?

Published · Updated

The Cyberbeveiligingswet (Cbw) applies to organisations active in one of eighteen designated sectors that are at least medium-sized, and to a number of organisations that fall under the Act regardless of size. The Act is the Dutch implementation of the EU NIS2 Directive and entered into force on 15 August 2026, without a statutory transition period.

There is no list of covered organisations and no letter from the supervisor. The RDI puts it plainly: organisations are themselves responsible for determining whether they fall under the Cbw. This article walks through the three tests that decide it.

The three tests in brief

Whether the Act applies to you follows from three questions. Are you active in a sector listed in Annex 1 or Annex 2 of the Act? Are you large enough? And do you perhaps fall, regardless of size, into a category that is always in scope? The answers also decide whether you are an essential or an important entity.

Test 1: are you active in a designated sector?

The Act designates eighteen sectors. Eleven are in Annex 1, seven in Annex 2.

  • Annex 1: energy, transport, banking, financial market infrastructure, healthcare, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration and space.
  • Annex 2: postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research.

Some sector names are broader than they sound. Digital infrastructure covers DNS service providers, trust services, top-level domain name registries, providers of public electronic communications networks and services, internet exchange points, cloud and data centre services and content delivery networks, among others. ICT service management covers managed service providers and managed security service providers. Manufacturing in Annex 2 covers computers and electronics, electrical equipment, machinery, motor vehicles and other transport equipment.

Test 2: are you large enough?

The Act states no numbers itself; it refers to the EU definition of small and medium-sized enterprises. In plain figures it comes down to this.

  • Medium-sized, the entry threshold: 50 or more FTE, or fewer than 50 FTE with both annual turnover and balance sheet total above EUR 10 million.
  • Large: 250 or more employees, or annual turnover above EUR 50 million and a balance sheet total above EUR 43 million.

Partner and linked enterprises count. A subsidiary with forty staff can therefore still be medium-sized if the group behind it is. The figures are indicative. The official test is the RDI NIS2 self-assessment; the NCSC gives the same explanation.

Essential or important

An organisation in an Annex 1 sector that is larger than medium-sized is an essential entity. A medium-sized organisation in an Annex 1 sector is an important entity. An organisation in an Annex 2 sector is always an important entity, however large it grows.

Both classes carry the same substantive obligations. The difference lies in supervision and in the level of fines. Essential entities are supervised proactively: compliance is actively checked, even when nothing has gone wrong. For important entities supervision happens mainly after the fact, for example following an incident. The maximum fine is EUR 10 million or 2% of worldwide annual turnover for an essential entity, and EUR 7 million or 1.4% for an important entity, whichever is higher.

Test 3: in scope regardless of size

Some organisations fall under the Act however small they are. The following are always essential entities:

  • qualified trust service providers;
  • top-level domain name registries;
  • DNS service providers;
  • public administration bodies, such as ministries, provinces, municipalities and water authorities;
  • entities designated as critical entities under the Wet weerbaarheid kritieke entiteiten (Wwke).

Small providers of public electronic communications networks or services and small trust service providers are important entities, even below the medium-sized threshold. In addition, the minister can designate an organisation regardless of size: for example where it is the sole provider in the Netherlands of a service essential to society, or where a disruption could have significant consequences for public safety or public health.

Who falls outside the Act

The Act does not apply to the Ministry of Defence, the intelligence and security services, the Public Prosecution Service, the police, the safety regions or the operators of root name servers. For higher-education institutions that are designated, the duty of care and the board duties only apply 36 months after designation.

Outside the scope, you can still be affected

The duty of care of an organisation that is in scope includes its direct suppliers and service providers. It has to assess each supplier's vulnerabilities, the quality of its products and security practices, and its secure development procedures. In practice this happens through contract clauses. That is how a supplier below the threshold still ends up with requirements from the Cyberbeveiligingswet.

If you are in scope: what has applied since 15 August 2026

Organisations in scope have had three duties since entry into force, without a transition period.

  • Registration in the national entity register at the NCSC, through mijn.ncsc.nl using eHerkenning. You report any change within two weeks.
  • The duty of care of article 21: ten elements, lettered a to j, from risk analysis policy and incident handling to access management and authentication, worked out in the Cyberbeveiligingsbesluit.
  • The notification duty: you report a significant incident in three stages, after 24 hours, 72 hours and one month.

The Act also places duties on the board itself. The board approves the measures, and every board member must be able to identify and assess cybersecurity risks and must hold a training certificate by 15 August 2028. The Act creates no personal liability; the supervisor can, however, impose an administrative fine of up to EUR 25,000 on an individual board member.

In doubt?

If you are far from the thresholds, these three tests settle it. If you are close to one, because of a group structure, an activity on the edge of a sector or a role as supplier to an organisation in scope, a web page will not settle it. Start with the RDI self-assessment. If you want the outcome checked and to know what it means for you, request the free applicability check: four fields, and a written analysis within 24 hours.

Read alsoThe notification duty under the Cyberbeveiligingswet: 24 hours, 72 hours, one month

Want to be sure?

Within 24 hours you receive a written analysis of whether and how the Cyberbeveiligingswet applies to your organisation. No cost, no sales call.

Request the free applicability check