On August 15, 2026, the Netherlands' Cyberbeveiligingswet (Cbw) and Wet weerbaarheid kritieke entiteiten (Wwke) entered into force, transposing the EU's NIS2 and CER directives into Dutch law. Together they cover roughly 8,500 organizations across 18 sectors — energy, digital infrastructure, drinking water, healthcare, banking, transport, government, food, space, nuclear, and more — with the Cbw applying to about 8,000 "essential" and "important" entities and the Wwke targeting some 500 designated "critical entities" (Rijksoverheid, 7 July 2026; NCTV, 15 August 2026).
The headline mechanics are strict but procedural, not discretionary. Covered firms must report significant incidents to the national CSIRT within 24 hours — not the vaguer "without undue delay" language some member states have used — and the Wwke separately mandates 24-hour disruption reporting for designated critical entities (NCSC; NCTV). Boards, not just CISOs, now own the compliance obligation: under Article 24(1) of the Cbw, management must formally approve cyber-risk measures, maintain "demonstrable" and continuously updated knowledge of network-and-information-system risk, and can be fined or hit with a penalty order (last onder dwangsom) as individuals — not just have their company fined — if they fail to meet that knowledge standard (RDI). Existing board members have until mid-2028 to comply; new appointees get two years from the date they take office.
The Steelman
There is a real case for this design, and it deserves to be stated plainly before it's critiqued. Digital infrastructure operators sit upstream of everything else the Wwke and Cbw try to protect — hospitals, water utilities, the payments system — so a compromise several layers removed from the public can still cascade into a public-safety emergency in hours, not months. Voluntary cybersecurity frameworks have a well-documented track record of being deprioritized the moment they compete with product roadmaps, and Dutch policymakers are not inventing that concern from nothing: NIS2 exists precisely because its predecessor, the 2016 NIS Directive (transposed domestically as the Wbni, which the Cbw now replaces), produced patchy, inconsistent national security baselines across the EU's single market. Tying obligations to board-level sign-off, rather than delegating them entirely to a security team with no budget authority, is a coherent response to a genuine principal-agent problem: the people who decide the security budget are the people who should own the security risk.
Where the Design Choice Matters
What's notable — and what distinguishes this from the internet-shutdown playbook seen elsewhere this year, including India's attempt to geoblock Jack Dorsey's Bitchat source code on GitHub during the New Delhi protests, or the kill-switch pressure Access Now's #KeepItOn campaign has tracked ahead of Zambia's elections — is that the Dutch regime is procedural and rights-preserving even as it reaches deep into private operations. There is no minister with standing authority to order a digital infrastructure operator offline. Enforcement runs through sector regulators (a designated minister per sector) who can compel a security audit, issue a binding directive, publicize a violation, or escalate to an administrative fine or penalty order — and, per Dutch legal commentary on the Cbw, a supervisor can in severe, sustained noncompliance cases petition a civil court to suspend a director, but that is a judicial remedy, not an executive one (RDI FAQ). That is the correct place for that power to sit. A state that can compel disclosure and audit trails is exercising oversight; a state that can unilaterally sever a network is exercising control, and those are not the same instrument even when both are marketed as "resilience."
That said, proportionality is a design choice that has to be actively maintained, not a one-time legislative achievement. Roughly 8,000 firms under the Cbw alone is a wide net, and the Wwke's compressed timeline — a nine-month risk assessment and a ten-month deadline for protective measures after an entity is designated critical — will strain mid-sized operators without in-house compliance functions far more than it strains incumbents who can absorb the audit and legal cost (NCTV). Personal fines on directors are a sharper incentive than corporate fines, but they also raise the cost of sitting on the board of any Dutch digital infrastructure or critical-entity firm — a tax that risks pushing risk-averse, qualified candidates away from exactly the companies that most need competent oversight, unless the RDI is disciplined about calibrating enforcement to genuine negligence rather than good-faith gaps.
The Broader Signal
The Netherlands is not alone in this NIS2 transposition wave, and the comparison across member states will be instructive over the next 12–18 months: which capitals build the RDI's audit-and-fine model, and which reach for broader emergency-intervention language that could, in a crisis, blur into something closer to a shutdown authority. For a publication watching states' emergency powers over digital infrastructure, the Dutch approach — proceduralist, judicially checked, no unilateral disconnection power — is the version worth pointing regulators elsewhere toward, even as its compliance burden on mid-market firms deserves scrutiny as enforcement data starts to accumulate.