Skip to content

Free tool

Does the Dutch Cybersecurity Act apply to me?

The Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw) has applied since 15 August 2026. Answer six questions about your organisation and see whether the Act is likely to apply to you, as an essential or an important entity, and what it then asks of you. No account and no email address.

Cbw self-check: does the Dutch Cybersecurity Act apply to me? | Trustbird

Choose the sector in which you provide most of your services. The sectors come from annexes 1 and 2 of the Act.

Do you deliver software as a service over the internet (SaaS)? Then you may count as a provider of cloud computing services, which puts your organisation under digital infrastructure. That depends on how the service is set up. If in doubt, run the check with that sector as well.

How many FTE work at your organisation?

Include linked enterprises, such as a parent or sister company.

What is the annual turnover?

For the last closed financial year, including linked enterprises.

What is the balance sheet total?

At the end of the last financial year, including linked enterprises.

Does your organisation provide any of these services, or has it been designated a critical entity?

For these services the Act applies regardless of size. Choose all that apply.

Do you supply services or products to organisations that fall under the Cbw?

Think of software, hosting or IT management for hospitals, municipalities, energy companies or hosting providers.

Answer the questions above. Your outcome appears here once everything is filled in.

Your outcome

You are likely in scope of the Cbw, as an essential entity.

The Act applies to your organisation. The supervisor may check whether you meet your obligations even without a specific reason.

You are likely in scope of the Cbw, as an important entity.

The Act applies to your organisation. The obligations are the same as for essential entities; the supervisor checks after the fact, for example after an incident or a report.

You are likely not in scope yourself, but the requirements reach you through your customers.

The Act does not bind you directly. Customers who are in scope must secure their supply chain, and that lands with you.

You are likely not in scope of the Cbw.

Based on your answers the Act does not apply to your organisation. If your services change or you grow, run the check again.

Why this outcome

  • Public administration organisations are in scope regardless of their size.
  • Your organisation is large and operates in a sector from annex 1.
  • Your organisation is medium-sized and operates in a sector from annex 1.
  • Your organisation is large and operates in a sector from annex 2. Organisations from annex 2 are important, not essential.
  • Your organisation is medium-sized and operates in a sector from annex 2.
  • You provide DNS services. These are in scope regardless of size.
  • You run a top-level domain name registry. That is in scope regardless of size.
  • You provide qualified trust services. These are in scope regardless of size.
  • Your organisation has been designated a critical entity. The Act then applies regardless of size.
  • You provide public electronic communications and your organisation is medium-sized or large.
  • You provide public electronic communications. Small providers are in scope too, as important entities.
  • You provide trust services and your organisation is large.
  • You provide trust services. These are in scope regardless of size, as important entities up to medium size.
  • Your sector is covered by the Act, but your organisation is small: fewer than 50 FTE, and an annual turnover or balance sheet total of at most 10 million euros.
  • Your sector is not in the annexes of the Act.
  • You supply organisations that are in scope of the Act.
  • You are not sure whether your customers are in scope. Find out: if they are, their requirements will reach you.

Do you deliver software as a service over the internet (SaaS)? Then you may count as a provider of cloud computing services, which puts your organisation under digital infrastructure. That depends on how the service is set up. If in doubt, run the check with that sector as well.

What the Act asks of you

Register with the NCSC
Through MijnNCSC, with eHerkenning at level EH2+. You provide organisation and contact details, and your public IP ranges, domain names and AS numbers. Changes are reported within 14 days.
Duty of care
Take appropriate measures, based on a risk assessment, to secure your network and information systems, from incident handling and continuity to suppliers and access control.
Incident reporting
A significant incident is reported in three steps, counted from the moment you become aware of it.
  1. Within 24 hours an early warning.
  2. Within 72 hours an incident notification with a first assessment of severity and impact.
  3. Within one month of the notification a final report, or a progress report if the incident is still ongoing.
Management body
Management approves the measures, oversees their implementation and completes training within two years of the Act taking effect. It remains accountable, even when a CISO carries out the work.

Supervision up front: the supervisor may inspect even without any sign of an infringement. The EU directive sets fines of at least up to 10 million euros or 2 percent of worldwide annual turnover.

Supervision after the fact: the supervisor acts after an incident or a report. The EU directive sets fines of at least up to 7 million euros or 1.4 percent of worldwide annual turnover.

What your customers will ask of you

Organisations under the Cbw must manage the risks of their suppliers. Expect questions and contract terms on:

  • the security measures you take;
  • how and how quickly you report incidents to them, so they can report within 24 hours themselves;
  • how you handle vulnerabilities;
  • the continuity of your service.

Your answers

Sector
FTE
Annual turnover
Balance sheet total
Special services
Supplies organisations under the Cbw

This self-check gives an indication based on your own answers. It is not legal advice and not a decision by a supervisor. If in doubt, read the text of the Act or put your situation to the NCSC or a lawyer. Your answers are not stored: they live only in your browser and in the link you choose to share.

Made with trustbird.com

Read on

Plain language explanations in our knowledge base, with sources.

Text of the Act and official sources

The duty of care on top of your ISO 27001 work

A working ISO 27001 management system already covers much of the duty of care. Trustbird links the Act to the controls you have and keeps the rest in view: registration, reporting deadlines and the duties of management.

How NIS2 works in Trustbird

Frequently asked questions

Is the outcome of this self-check binding?
No. The self-check gives an indication based on your own answers and is not legal advice. Whether your organisation falls under the Dutch Cybersecurity Act depends on your exact services and size. If in doubt, read the text of the Act or put your situation to the NCSC or a lawyer.
What is the difference between an essential and an important entity?
The obligations are the same: register, take appropriate measures, report significant incidents and train management. The difference is supervision. For essential entities the supervisor inspects proactively, for important entities after the fact, for example after an incident. The maximum fines differ as well.
Do subsidiaries and sister companies count towards size?
Yes. The Act uses the EU definition of small and medium-sized enterprises. Linked enterprises count in full towards FTE, annual turnover and balance sheet total, and partner enterprises in proportion to their share.
Are my answers stored?
No. The self-check does all its work in your browser. Your answers live only in the page address, so you can share the outcome or come back to it later. Trustbird does not receive them.
I am not in scope myself. Do I need to do anything?
Not under the Act itself. If you supply organisations that are in scope, they will ask you about security measures, incident notification, vulnerability handling and continuity. An ISO 27001 certificate is not required, but it does shorten that conversation.