Entities within the scope of the Dutch Cyberbeveiligingswet (Cbw), the Dutch implementation of NIS2, must register through MijnNCSC. Legal duties follow from the applicable law; submitting the registration form does not create or postpone those duties.
Scope and size thresholds
Check the sector and service first. The NCSC describes the general size test as at least 50 full-time equivalents, or fewer than 50 with both annual turnover and balance-sheet total above EUR 10 million. Some categories are covered regardless of size; group relationships and specific designations may also matter. Use the NCSC scope check. Supplying a regulated customer does not by itself make a supplier subject to registration.
Registration timing
The NCSC identifies 15 August 2026 as the date the Cbw entered into force. This guide has not established a universal final registration deadline for every entity. Check the applicable sector rules and instructions instead of relying on an assumed date. The NCSC registration guidance explains access and required entity, contact and network details.
Significant-incident reporting
| Stage | Deadline |
|---|---|
| Early warning | Within 24 hours of awareness |
| Incident notification | Within 72 hours of awareness |
| Final report | Within one month of the notification |
Report without undue delay. If the incident is still ongoing, provide a progress report and a final report within a month of handling it. See NCSC reporting guidance.
Exceptions matter
Under Article 23(4) of NIS2, a trust service provider must notify significant incidents affecting its trust services within 24 hours rather than the standard 72 hours. The criteria for significance also depend on the sector. The general schedule is therefore not sufficient to design every organisation’s reporting procedure.
Operational evidence
Record the scope decision, responsible person, sources and assessment date. Keep the registration confirmation, define who updates it and test who can submit an incident report when the primary contact is absent. Link corrective actions to the risk register. ISO 27001 can support these processes; certification does not replace legal reporting.
Sources checked on 8 September 2026. Confirm current rules when handling an actual registration or incident.
