< Back to all clusters
[TECHNOLOGY] · Netherlands · 2 sources

started · updated

Netherlands implements new cybersecurity laws

The Netherlands has implemented new legislation to strengthen digital and physical resilience, fulfilling European Union mandates. The Cybersecurity Act (Cbw) and the Resilience of Critical Entities Act (Wwke) officially entered into force on August 15, 2026, following a delay that had previously led to an EU infringement procedure.

The Cybersecurity Act, which implements the NIS2 directive, replaces the previous Wbni framework. It applies to approximately 8,000 organizations across 18 critical sectors. Under this law, companies must manage digital security risks through appropriate security policies, business continuity plans, and employee awareness training. Serious incidents, such as hacks or data breaches, must be reported to the CSIRT and relevant supervisory authorities.

In addition to new reporting duties, the regulations introduce personal liability for board members. The Wwke, which implements the CER directive, focuses on approximately 500 organizations to bolster the resilience of critical entities. Officials have noted that these laws mark the end of voluntary cybersecurity measures in favor of mandatory compliance.

Entities

European Union · Ministry of the Interior and Kingdom Relations · Netherlands