What is incident reporting under the Dutch Cybersecurity Act?
Incident reporting under the Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw) is the legal obligation for essential and important entities to report every significant incident in stages to the CSIRT and their supervisor: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. The obligation comes straight from Article 23 of NIS2 and has applied since 15 August 2026, together with a registration duty that tells the government exactly who falls under the Cybersecurity Act. For industrial organisations, reporting is above all an OT matter: a stopped production line or a lost control system is often precisely what makes an incident significant.
π§ When is an incident significant?
Not every cyber incident has to be reported. The Act uses two general criteria. An incident is significant if it:
- has caused or can cause severe operational disruption or financial loss for the entity; or
- has affected or can affect other people or organisations by causing considerable material or non-material damage.
These open standards are made concrete per sector through thresholds in ministerial regulations. Under the Regeling cyberbeveiliging EZK (the Ministry of Economic Affairs regulation), among others, an incident is also always significant if it has caused or can cause death or considerable damage to peopleβs health. Whether your organisation is in scope is explained in Cybersecurity Act Scope; the duty-of-care measures themselves are set out in the Cybersecurity Decree.
| Sector | Example thresholds |
|---|---|
| Manufacturing (Regeling cyberbeveiliging EZK) | Safety functions lost; availability or integrity of essential control or monitoring functions lost; continuity of the production process endangered; environmental damage |
| Chemicals (Cyberbeveiligingsregeling IenW) | Contractual delivery times exceeded by three weeks or more; a dependent critical entity without the service for six hours or longer |
| Drinking water (Cyberbeveiligingsregeling IenW) | No drinking water supplied to 10,000 or more connections for six hours or longer |
| Healthcare (Cyberbeveiligingsregeling voor de zorg) | A critical business process fully or partly unavailable for more than four hours |
Note the OT angle: in manufacturing, losing control or monitoring functions is enough on its own. You do not have to calculate financial damage before the clock starts running.
ποΈ What are the reporting deadlines?
The clock starts when your organisation becomes aware of the significant incident, not at the first odd log entry. Each stage builds on the previous one.
| Deadline | Stage | Content |
|---|---|---|
| Within 24 hours | Early warning | Whether malicious or unlawful action is suspected, possible cross-border impact, contact person |
| Within 72 hours | Incident notification | Update of the early warning, initial assessment of severity and impact, available indicators of compromise |
| On request | Intermediate report | Status update when the CSIRT or the supervisor asks for one |
| Within 1 month of the notification | Final report | Detailed description, severity and impact, type of threat or root cause, mitigation applied and ongoing, cross-border impact |
| Incident still ongoing | Progress report | A progress report after one month; the final report follows within one month of handling the incident |
The CSIRT responds to the early warning within 24 hours with initial feedback and can provide technical support on request. If a criminal offence is suspected, the CSIRT explains how to report it to the police.
π¨ Where do you report, and who else must you inform?
You report through the central reporting point on MijnNCSC. A single report reaches both the sectoral CSIRT and your supervisor at once. For most sectors the NCSC is the CSIRT; for healthcare it is Z-CERT. Supervision is divided by sector, with the Dutch Authority for Digital Infrastructure (RDI) covering manufacturing and energy, the Human Environment and Transport Inspectorate (ILT) covering chemicals, drinking water and transport among others, the NVWA covering food and the IGJ covering healthcare. The NCSC is therefore not a supervisor: it is your CSIRT and the place where you register. Where an incident has cross-border impact, the CSIRT shares the information with other member states and ENISA.
Besides the report itself, two duties to inform apply:
- Recipients, after a significant incident β you inform the recipients of your services without undue delay when the incident is likely to adversely affect the services they receive
- Recipients, about a significant cyber threat β you tell them what measures they can take and, where appropriate, what the threat itself is
Smaller incidents, near misses and threats can be reported voluntarily. Voluntary reports go to the CSIRT only, not to the supervisor, and are handled with lower priority than mandatory ones.
ποΈ What does the registration duty involve?
Every essential and important entity registers itself in the national entity register, kept by the Ministry of Justice and Security through the NCSC. Registration takes place on MijnNCSC using eHerkenning (assurance level EH2+) or, for central government bodies, SSOnRijk. You provide, among other things:
- Organisation details β name, address and Chamber of Commerce data, largely retrieved automatically
- Sector and subsector β from Annex I or II, plus the type of service and the member states where you provide it
- Category β essential or important
- Contact person β name, position, telephone number and email address
- Network data β public IP addresses and ranges, domain names and AS numbers
You report changes within 14 days. Failing to register, or registering incorrectly, can lead to an order subject to a penalty payment or a fine.
π How does Cbw reporting relate to the GDPR and the CRA?
A single attack can trigger three separate reporting duties, each with its own recipients and deadlines.
| Regime | Who reports | What | To whom | Deadlines |
|---|---|---|---|---|
| Cyberbeveiligingswet | Essential and important entities | Significant incident | CSIRT and supervisor via MijnNCSC | 24 hours / 72 hours / 1 month |
| GDPR (AVG) | Every controller | Personal data breach | Dutch Data Protection Authority (Autoriteit Persoonsgegevens) | 72 hours after becoming aware |
| Cyber Resilience Act | Manufacturer of a product with digital elements | Actively exploited vulnerability or severe incident | CSIRT and ENISA via the Single Reporting Platform | 24 hours / 72 hours / 14 days or 1 month |
A GDPR notification does not replace a Cbw report, nor the other way round. If ransomware exfiltrates staff records, you report to the NCSC and to the Autoriteit Persoonsgegevens. The CRA duty has applied to manufacturers since 11 September 2026, so a machine builder can fall under the CRA Reporting Obligations as a manufacturer and under the Cbw as an entity.
π What does reporting look like for ransomware in a factory?
A medium-sized manufacturer of electrical equipment, an important entity supervised by the RDI, is hit by ransomware on a Monday night. The MES server and two SCADA servers are encrypted; operators lose sight of the line and stop production. Because essential control and monitoring functions have been lost, the incident is significant under the Regeling cyberbeveiliging EZK.
| Time | Event | Reporting action |
|---|---|---|
| Mon 02:10 | HMIs display a ransom note; the line is stopped | β |
| Mon 04:00 | The OT incident team establishes that the incident is significant | The 24-hour clock starts |
| Mon 05:30 | IT-OT link disconnected, PLCs brought to a safe state | Evidence preserved for forensic investigation |
| Mon 11:00 | Customers are told deliveries will be delayed | Recipients informed without undue delay |
| Tue 02:00 | β | Early warning via MijnNCSC |
| Wed 15:00 | Forensics reveals theft of HR files | GDPR notification to the Autoriteit Persoonsgegevens (within 72 hours of discovery) |
| Thu 03:00 | Recovery from offline backups under way | Incident notification with impact and IOCs |
| Day 10 | The CSIRT asks for a status update | Intermediate report |
| Within 1 month of the notification | Production fully restored | Final report with root cause and measures |
π§ Which step-by-step procedure works for an OT plant?
- Beforehand: translate the criteria β define per installation which loss of control, safety or monitoring crosses the sector threshold, so the shift supervisor does not have to guess
- Beforehand: register and assign roles β keep the MijnNCSC registration current, arrange eHerkenning, and appoint a reporter and a deputy who can be reached at night
- Detect and record β OT monitoring or an OT SOC raises the alarm; record the moment of awareness straight away, because the deadline starts there
- Assess β test against the criteria within a few hours; doubt is no reason to wait, as an early warning may be incomplete
- Contain without destroying evidence β follow the incident response plan and isolate zones, but copy logs and memory first
- Report in stages β 24 hours, 72 hours, on request, final report; keep one incident log as the single source for every submission
- Report in parallel β check each time whether GDPR or CRA notifications are needed, and inform recipients through the crisis communication plan
- Close and learn β feed the root cause back into the risk analysis and rehearse the scenario every year together with those responsible for business continuity
β Frequently asked questions
How quickly must an incident be reported under the Dutch Cybersecurity Act?
Under the Dutch Cybersecurity Act you submit an early warning within 24 hours of becoming aware of a significant incident. The incident notification follows within 72 hours, and the final report within one month of that notification.
Where do you report an incident under the Cyberbeveiligingswet?
An incident under the Cyberbeveiligingswet is reported through the central reporting point on MijnNCSC. That single report reaches both the sectoral CSIRT, usually the NCSC, and the supervisor for your sector.
Does a ransomware attack on OT have to be reported under the Dutch Cybersecurity Act?
A ransomware attack on OT must be reported under the Dutch Cybersecurity Act as soon as it is a significant incident. In manufacturing that is already the case when essential control or monitoring functions are lost or the continuity of the production process is endangered.
Does Cbw incident reporting replace a GDPR data breach notification?
No, Cbw incident reporting and the GDPR data breach notification apply side by side. If personal data is also compromised, you notify the breach separately to the Autoriteit Persoonsgegevens within 72 hours.
What data does the Cbw registration duty require?
The Cbw registration duty requires organisation details, sector and subsector, the member states where you provide services, a contact person, and public IP ranges, domain names and AS numbers. You report any changes through MijnNCSC within 14 days.
What happens if you report a significant incident too late?
Reporting a significant incident late, or not at all, breaches the Dutch Cybersecurity Act and can lead to an order subject to a penalty payment or an administrative fine. The fine can reach 10 million euros or 2% of worldwide annual turnover for essential entities, and 7 million euros or 1.4% for important entities, whichever is higher.
π In summary
Incident reporting under the Dutch Cybersecurity Act requires essential and important entities to report a significant incident via MijnNCSC within 24 hours, update it within 72 hours and close it with a final report within one month.
Sector thresholds decide when an incident is significant; in manufacturing, losing control or monitoring functions is already enough. Alongside the report you must inform the recipients of your services, keep your registration current and check separately whether the GDPR or the CRA calls for a second notification. A procedure rehearsed in advance makes the 24-hour deadline achievable, even for an OT plant.
