Ga naar inhoud

NIS2 ·

NIS2 registration duty: who must register and what evidence belongs with it

Dutch Cbw registration depends on sector, size and exceptions. Significant incidents normally follow a 24-hour, 72-hour and one-month reporting sequence; trust services have a specific exception.

Entities within the scope of the Dutch Cyberbeveiligingswet (Cbw), the Dutch implementation of NIS2, must register through MijnNCSC. Legal duties follow from the applicable law; submitting the registration form does not create or postpone those duties.

Scope and size thresholds

Check the sector and service first. The NCSC describes the general size test as at least 50 full-time equivalents, or fewer than 50 with both annual turnover and balance-sheet total above EUR 10 million. Some categories are covered regardless of size; group relationships and specific designations may also matter. Use the NCSC scope check. Supplying a regulated customer does not by itself make a supplier subject to registration.

Registration timing

The NCSC identifies 15 August 2026 as the date the Cbw entered into force. This guide has not established a universal final registration deadline for every entity. Check the applicable sector rules and instructions instead of relying on an assumed date. The NCSC registration guidance explains access and required entity, contact and network details.

Significant-incident reporting

StageDeadline
Early warningWithin 24 hours of awareness
Incident notificationWithin 72 hours of awareness
Final reportWithin one month of the notification

Report without undue delay. If the incident is still ongoing, provide a progress report and a final report within a month of handling it. See NCSC reporting guidance.

Exceptions matter

Under Article 23(4) of NIS2, a trust service provider must notify significant incidents affecting its trust services within 24 hours rather than the standard 72 hours. The criteria for significance also depend on the sector. The general schedule is therefore not sufficient to design every organisation’s reporting procedure.

Operational evidence

Record the scope decision, responsible person, sources and assessment date. Keep the registration confirmation, define who updates it and test who can submit an incident report when the primary contact is absent. Link corrective actions to the risk register. ISO 27001 can support these processes; certification does not replace legal reporting.

Sources checked on 8 September 2026. Confirm current rules when handling an actual registration or incident.

Primary sources for this topic

Frequently asked questions

Does a workforce of 50 automatically create a registration duty?
No. Size is only part of the scope assessment. Sector, service type, group relationships and specific designations can also matter. The NCSC describes the general threshold as 50 full-time equivalents, or fewer employees with both turnover and balance-sheet total above EUR 10 million. Some categories are covered regardless of size. Record the decision, source and assessment date.
Is the notification deadline always 72 hours?
No. The standard incident notification is due within 72 hours of awareness, following an early warning within 24 hours. Trust service providers must notify significant incidents affecting their trust services within 24 hours. Sector rules also determine when an incident is significant. Check the applicable requirements before approving the organisation’s reporting procedure and escalation rota.

Deep dive in the knowledge base

Run the NIS2 readiness scan

Align NIS2 expectations with your existing management system.

Start NIS2 scan

← Back to overview

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)