The Netherlands just moved the needle on national security. On April 15, 2026, the Dutch House of Representatives voted to pass two long-awaited pieces of legislation: the Cybersecurity Act (Cyberbeveiligingswet) and the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten). For thousands of organizations operating in the Netherlands, the clock is now ticking.
Minister Van Weel put it plainly: cyberattacks and operational disruptions are no longer theoretical threats. They are happening today, to real organizations, with real consequences. These two laws are the Dutch government's answer to that reality, and they stem from a broader European push to raise the floor on security standards across all member states.
The Cybersecurity Act: Europe's NIS2 Directive, Made Dutch Law The Cybersecurity Act is the Netherlands' implementation of the EU's NIS2 Directive, replacing the outdated Network and Information Systems Security Act that has governed digital security obligations until now. The goal is straightforward: make Dutch businesses and institutions meaningfully harder to attack and faster to recover when breaches occur.
Organizations covered by the law will face three core obligations: a duty of care to actively manage cyber risks, a reporting obligation when incidents occur, and a registration requirement with the relevant authorities. Critically, organizations must determine for themselves whether they fall within scope, and the government is not waiting for the ink to dry before urging action. The risks that this law addresses already exist, which means preparation should have started yesterday.
The Critical Entities Act: Protecting the Systems Society Runs On Where the Cybersecurity Act focuses on digital resilience, the Critical Entities Resilience Act tackles physical vulnerabilities in essential services. Rooted in the EU's CER Directive adopted in late 2022, this law targets organizations delivering services that society simply cannot function without, from energy and water to transport and finance.
Unlike the Cybersecurity Act, organizations do not self-identify as critical entities. The relevant minister will designate covered organizations based on statutory criteria, meaning some companies may find themselves in scope whether they expected it or not.
The legislation now moves to the Senate for review. Once the Senate passes both bills, they are set to take effect in the second quarter of 2026, alongside supporting secondary regulations, though that timeline remains tied to the pace of parliamentary proceedings.