The Netherlands completed its NIS2 transposition on time to take effect. The Cyberbeveiligingswet (Cbw), Wet van 8 juli 2026 houdende regels ter implementatie van Richtlijn (EU) 2022/2555 (Kamerstukken 36764, Staatsblad 2026, 189), passed the Tweede Kamer on 15 April 2026 and the Eerste Kamer on 7 July 2026, and entered into force on 15 August 2026 by royal decree (Staatsblad 2026, 187).
Its own Article 106 repeals the predecessor Wet beveiliging netwerk- en informatiesystemen (Wbni), which transposed the original NIS Directive (Directive (EU) 2016/1148); the consolidated register confirms the Wbni lapsed on 15 August 2026, so it is not still in force, unlike Ireland's and Spain's predecessor NIS1 regimes.
The Cbw binds an essential entity (Article 8, by operation of law, or Article 9, by criteria-based designation) and an important entity (Article 12 or Article 13) drawn from its Annexes 1 and 2, which restate the NIS2 Annex I and Annex II sector lists, to appropriate and proportionate risk-management measures over its network and information systems (Article 21, with the management board's approval and competency duty under Article 24) and to a graduated significant-incident notification clock to its CSIRT and competent authority: a 24-hour early warning (Article 26), a 72-hour notification (Article 27), an interim report on request (Article 28), and a final report within one month (Article 29).
Annex 2's own digital-provider entry names an online marketplace, an online search engine and a social-networking-services platform, supervised by the Minister of Economic Affairs; Annex 1's digital-infrastructure and ICT-service-management entries separately name a cloud-computing-service provider, a data-centre-service provider and a content-delivery-network provider, also supervised by that Minister.
The wider essential and important entity classes the Cbw designates by sector (energy, transport, banking, health, drinking water, public administration and the rest of the NIS2 Annexes) are a designation and sector class no activity in this vocabulary expresses, so only the digital-provider slice is flagged here.
No Dutch instrument reviewed here imposes a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here; the Netherlands implements only the Cyber Resilience Act (CRA)'s own supervisory arrangements, assigning market surveillance to the Rijksinspectie Digitale Infrastructuur, rather than creating a further substantive duty.
The Netherlands has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and UAVG Article 42's breach-notification duties to the Autoriteit Persoonsgegevens, both of which sit in the privacy topic rather than here.