Skip to content

Cyber Security Act Netherlands (Cbw / NIS2)

In the Netherlands, NIS2 is implemented through the Cyberbeveiligingswet (Cbw). This page explains what organisations should prepare in practice.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence, without endless document churn.

Check your NIS2 gaps

The Cyberbeveiligingswet (Cbw) implements NIS2 in the Netherlands, scope, measures, incidents and supply-chain expectations for essential and important entities.

Start with the NIS2 hub and NIS2 compliance for detail. SMEs under customer pressure: NIS2 for SMEs.

Combine with your ISMS, DORA (financial sector) and GDPR where personal data is involved.

Key takeaways

  • Cbw translates NIS2 into national rules and supervision.
  • Essential and important entities face concrete risk and incident duties.
  • Reporting routes must be rehearsed before a crisis.
  • Suppliers feel pressure through contracts even when not directly in scope.

Frequently asked questions

Is the Cbw the same as NIS2?
NIS2 is the EU directive; the Cbw is the Dutch implementation with national supervision.

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)