< Back to all clusters
[TECHNOLOGY] · Netherlands · 4 sources

started · updated

Netherlands Cybersecurity Act enters into force

The Cybersecurity Act (Cbw) has officially come into effect in the Netherlands as of August 15. This national legislation implements the European NIS2 directive, imposing stricter security requirements and reporting obligations on approximately 8,000 organizations.

Under the new law, executives are held ultimately responsible for the cybersecurity posture of their own organizations and their supply chains. For the healthcare sector—a frequent target for cybercriminals—this means large hospitals, mental health institutions, and medical device manufacturers must demonstrate continuous risk management rather than relying solely on static certifications.

Experts emphasize that compliance requires more than just technical tools like firewalls; it demands active oversight of third-party vendors. The law applies to organizations with more than 50 employees or those with an annual turnover and balance sheet exceeding 10 million euros.

Entities

European Union · Netherlands · Z-CERT