Two laws, one date, immediate duties

The Cyberbeveiligingswet and its companion Wet weerbaarheid kritieke entiteiten both entered into force on 15 August 2026, and neither one waited for a transition period before the duties that matter first, registration and breach reporting, started to apply.

The Cyberbeveiligingswet was signed on 8 July 2026 and published as Staatsblad 2026, 187 two days later. Its implementing decree, the Cyberbeveiligingsbesluit, was published separately as Staatsblad 2026, 189. Together they transpose EU Directive 2022/2555, the NIS2 directive, into Dutch law. The scope is large by national standards: more than 8,000 organizations across 18 sectors, including energy, drinking water, digital infrastructure, healthcare, government and transport.

The table below sets out how the two Dutch laws differ in reach and origin.

LawEU directive transposedEntities covered
CyberbeveiligingswetNIS2 (2022/2555)8,000+ across 18 sectors
Wet weerbaarheid kritieke entiteitenCER (2022/2557)Roughly 500 critical entities

The nine-month number that got buried

Coverage of the law settled on the phrase 'no grace period', and that is only half right. The clock that genuinely has no grace period is the one for registering with the NCSC and disclosing an incident, not the one for finishing your security programme.

Registration through the national register, MijnNCSC, became mandatory the moment the law took force, and any change to a registered entity's details must be reported within 14 days. Two separate obligations sit on a longer fuse: the risk-assessment duty begins 9 months after an entity is formally designated, and the duty to have security measures in place begins 10 months after designation.

That distinction matters for anyone reading the law as buying time. It does not. It buys time to build the programme. It does not buy time to avoid registering, and it does not buy time on the incident-reporting clock once you are in scope.

A different clock than Germany's

Germany's own NIS2 transposition runs on a slower, audit-driven process: the German cyber authority identifies and confirms entities into scope over a longer window before duties fully attach. A business that checked Germany's timeline and assumed the same applied to its Dutch subsidiary was checking the wrong clock.

The Dutch model ties designation to registration rather than to a national audit cycle, so a Dutch entity's personal 9 to 10 month runway starts running from the moment it registers or is designated, not from a government-set national date. Two EU member states transposing the same directive have produced two different practical timelines, and neither one is a safe proxy for the other.

What this means for you

An owner with a Dutch subsidiary, a Dutch data-processing vendor, or a Dutch logistics or energy partner needs a scope check this week, not in December. Start with whether any of the 18 covered sectors touches a Dutch entity you control or depend on.

If it does, confirm the MijnNCSC registration status directly rather than assuming a vendor or subsidiary has already filed it, since the registration duty carries no runway at all. Then find the entity's designation date, because that date, not 15 August, is what starts its personal 9 to 10 month clock for risk assessment and security measures.

Finally, brief the management board specifically. NIS2's governance article puts accountability on the entity's leadership body, not only on a compliance or IT function, and that line does not soften just because the technical deadlines are still months away.