sota.io
Join the waitlist
2026-08-15·8 min read·sota.io team

The Netherlands' Cyberbeveiligingswet Is Now Law: What Actually Changes for SaaS Vendors on August 15, 2026

The Netherlands' Cyberbeveiligingswet Is Now Law: What Actually Changes for SaaS Vendors on August 15, 2026

If you searched "Netherlands NIS2" any time before this week, you probably read that the Cyberbeveiligingswet has been in force since "late 2024." That was wrong — and as of today, it's provably wrong. The Dutch Senate (Eerste Kamer) only adopted the final law on July 7, 2026. It was signed on July 8, published in the Staatsblad on July 10, and took legal effect at midnight on August 15, 2026 — with no transition period for registration, duty of care, or incident reporting. Every one of those obligations is live right now, for roughly 8,000 organizations across 18 sectors, whether or not their vendors are ready.

This matters beyond trivia. Confusing the 2024 EU transposition deadline with the actual date Dutch national law took effect leads vendors to underestimate how sudden this is for their Dutch customers — and, if you've been telling prospects "the Netherlands has had this since 2024, you're probably fine," you've been giving bad advice for over a year.

Where the "late 2024" confusion comes from

NIS2 (Directive (EU) 2022/2555) required all member states to transpose the directive into national law by October 17, 2024, with rules applying from October 18, 2024 (Art. 41). The Netherlands, like a majority of member states, missed that deadline. What actually happened between October 2024 and this week was a multi-year legislative process — draft bill, parliamentary debate, amendments, Tweede Kamer approval, and finally Eerste Kamer approval on July 7, 2026.

The law itself is Wet van 8 juli 2026, houdende regels ter implementatie van Richtlijn (EU) 2022/2555, published as Staatsblad 2026, 187 on July 10, 2026 — that publication is the actual primary source, not a press summary. Its companion implementing decree, the Cyberbeveiligingsbesluit, was published the same week as Staatsblad 2026, 189. Both took effect August 15, 2026, confirmed directly by the Dutch government's own announcement.

One genuinely interesting detail buried in the Staatsblad text: the law carves out a narrow exception for higher-education institutions, whose duty-of-care obligations phase in on a separate schedule under a dedicated transitional provision — everyone else gets zero grace period. If your SaaS product serves Dutch universities specifically, that's worth checking against the primary text rather than assuming the same day-one clock applies.

What actually changed at midnight today

Four obligations went from "upcoming" to "legally binding, unconditionally" in one step:

ObligationStatus as of August 15, 2026
RegistrationMandatory now — entities register at mijn.ncsc.nl via eHerkenning (level EH2+) or SSO Rijk for public bodies. Any change to registered details must be reported within 14 days.
Duty of care (zorgplicht)Legally enforceable now — risk analysis and "appropriate and proportionate" security measures are required, not aspirational.
Incident reportingThe clock is live — early warning within 24 hours, full notification within 72 hours, final report within one month of the 72-hour notification.
Management board accountabilityEnforceable now — boards must approve the security policy, oversee its implementation, and complete adequate training, and can face personal liability for gross negligence.

The 24h/72h/1-month structure and the board-liability provision both trace back to NIS2 itself — Article 23 (reporting obligations) and Article 20 (governance) respectively — which the Cyberbeveiligingswet transposes essentially unchanged. The registration duty likewise implements NIS2 Article 27 ("Registry of entities").

A second correction: the regulator's name changed years before this law did

Older coverage of Dutch NIS2 — including guidance that described the pre-CBW regime — refers to Agentschap Telecom as the authority for cloud, CDN, and digital infrastructure providers. That name has not existed since January 1, 2023, when Agentschap Telecom was formally renamed Rijksinspectie Digitale Infrastructuur (RDI), per the agency's own announcement. Any vendor documentation, DPA template, or compliance checklist still referencing "Agentschap Telecom" as a Dutch supervisory authority is at least three years out of date.

Under the CBW, supervision is split, not centralized in one office:

For a SaaS vendor whose infrastructure is classified as "digital infrastructure" under Dutch sector codes, RDI — not NCSC — is the body that can run ex-ante inspections, issue binding instructions, or impose fines. Registration itself still runs centrally through NCSC's portal regardless of which authority ultimately supervises you.

The fine tiers, precisely

NIS2 Article 34 sets the caps that Dutch national law transposes without modification:

Whether your organization lands in the essential or important tier follows the standard NIS2 size-and-sector test (Art. 3): essential entities are generally large organizations (250+ staff or €50M+ turnover and €43M+ balance sheet) in the higher-criticality Annex I sectors; important entities are medium organizations (50+ staff or €10M+ turnover) across the fuller sector list. Cloud computing providers, CDN operators, and data centres sit in Annex I's "digital infrastructure" category but still have to clear that same size threshold — a common misreading. The actual "regardless of size" carve-out (Art. 2(2)) is narrower: it applies specifically to DNS service providers, TLD name registries, and certain public electronic communications and trust service providers, not to cloud/CDN/marketplace vendors generally.

What this means if you're a vendor, not a regulated Dutch entity yourself

Most SaaS companies reading this aren't themselves Dutch essential or important entities — they're vendors selling into that market. What changes for you today is not your own legal exposure; it's the tempo of your customers' procurement questions.

Before today, a Dutch enterprise customer asking about your CLOUD Act exposure, sub-processor list, or breach-notification SLA was doing forward-looking risk management. As of today, that same question is compliance-mandatory supply-chain due diligence under a legally binding duty of care — they are not allowed to treat vendor risk assessment as optional anymore, and neither is their auditor.

A short same-day checklist:

See also

For the full implementation guide — security measures, the Dutch zorgplicht in detail, and a complete EU-native alternatives table — see Netherlands NIS2 Implementation: NCSC-NL, Cyberbeveiligingswet & SaaS Compliance Guide (note: treat the entry-into-force date and authority names in that guide as superseded by this post). For a cross-border view, see NIS2 France & Netherlands: SaaS Compliance Guide. For the underlying EU directive, see NIS2 Compliance Guide for SaaS.

Primary sources: Rijksoverheid.nl official announcement · Staatsblad 2026, 187 (official gazette, primary legal text) · NCSC.nl — Cyberbeveiligingswet (NIS2) and registration portal guidance · PIANOo (Dutch government procurement expertise centre) · RDI — Agentschap Telecom rename announcement and RDI — Cyberbeveiligingswet supervision · NIS2 Directive (EU) 2022/2555, Articles 3, 4, 20, 23, 27, 34, 41.

EU-Native Hosting

Ready to move to EU-sovereign infrastructure?

sota.io is a German-hosted PaaS — no CLOUD Act exposure, no US jurisdiction, full GDPR compliance by design. Deploy your first app in minutes.