Skip to content

Cyberbeveiligingswet (NIS2)

Complying with the Cyber­beveiligings­wet

The Cyber­beveiligings­wet (Cbw) requires a broad range of organisations to manage risk, report incidents and hold management accountable for cybersecurity.

Book an introductory call
  • Information security
  • Risk management

When the Cyberbeveiligingswet applies

The Cyber­beveiligings­wet applies to a broad range of sectors, from energy and healthcare to digital infrastructure and food production, and has been in force since 15 August 2026.

Many organisations fall under these obligations for the first time, without their existing security being set up for it.

  • Your organisation is medium-sized or large and active in a designated sector

  • No registration or risk management process for the Cbw is in place yet

  • It’s unclear whether your organisation is classed as essential or important

What regulators can enforce

Regulators can enforce the law with fines and binding instructions where organisations fall short.

Management is personally responsible for approving and overseeing risk management.

What the law asks of your risk management

The Cbw requires a risk management approach that covers relevant threats, is demonstrably backed by management, and comes with incident reporting obligations.

  • Registration in the entity register

  • A risk management approach: policy, incident response, business continuity and supply chain security

  • Basic cyber hygiene: access control, multi-factor authentication, training

  • Reporting obligations: early warning within 24 hours, notification within 72 hours

  • Management approval of and oversight over risk management

From applicability to management sign-off

Vedeum first determines whether and how the Cbw applies to your organisation, then builds a risk management approach that fits what you already have.

  1. Applicability

    We determine whether your organisation falls under the Cbw, and whether you’re classed as essential or important.

  2. Risk assessment

    We map threats and vulnerabilities according to the law’s requirements.

  3. Implementation

    We help set up policy, incident response and supply chain security.

  4. Management sign-off

    We support management in approving and reviewing risk management.

Book a no-obligation introductory call

Tell us where your organisation stands. We will think through the first steps with you.

Book an introductory call