What is the Cybersecurity Decree (Cyberbeveiligingsbesluit)?
The Cybersecurity Decree (Cyberbeveiligingsbesluit, Cbb) is the Dutch order in council under the Cybersecurity Act that sets out the concrete security measures essential and important entities must take, as a minimum, to meet their duty of care. Where the Act copies the broad lines of article 21 of NIS2, the Decree turns them into auditable requirements in articles 5 to 18: a written policy, demonstrable application and periodic evaluation. It also governs board training, additional reporting data and registration. The Decree covers both IT and OT and entered into force together with the Act on 15 August 2026.
⚖️ What is the legal status of the Cybersecurity Decree?
The Cbb is an algemene maatregel van bestuur (AMvB), a general administrative order: secondary legislation adopted by the government to implement an Act, after advice from the Council of State but without a full parliamentary procedure. The Decree is dated 8 July 2026 and was published in the Dutch Bulletin of Acts and Decrees (Staatsblad 2026, 189) on 10 July 2026. It replaces the Network and Information Systems Security Decree that accompanied the former Wbni.
| Date | Milestone |
|---|---|
| 17 October 2024 | European Commission adopts Implementing Regulation (EU) 2024/2690 |
| 20 February – 30 March 2025 | Public internet consultation on the draft Decree |
| 27 May 2026 | Advisory opinion of the Council of State |
| 8 July 2026 | Decree adopted (Staatsblad 2026, 189) |
| 15 August 2026 | The Cybersecurity Act and the Decree enter into force, without a transition period |
The hierarchy is straightforward. NIS2 (Directive (EU) 2022/2555) is the European basis, the Cyberbeveiligingswet transposes it into Dutch law, and the Decree fills in article 21 of the Act. Under article 19, a minister can still add more detailed, sector-specific rules by ministerial regulation.
Parts of the digital infrastructure and digital provider sectors are carved out. Article 4 states that the measure articles 6 to 18 do not apply to DNS service providers, top-level domain registries, cloud and data centre providers, content delivery networks, managed (security) service providers, online marketplaces, search engines, social networking platforms and trust service providers. For those entities the European Implementing Regulation (EU) 2024/2690 applies directly, with its own detailed technical and methodological requirements.
🔐 Which measures does the Cybersecurity Decree require?
Article 5 states that every entity takes at least the measures in articles 6 to 18. Nearly every article follows the same pattern: an adopted policy, recorded in writing and demonstrably applied.
| Article | Measure area | Core requirement |
|---|---|---|
| 6 | Security policy | Written policy, roles and segregation of duties, a management system (PDCA) |
| 7 | Risk Management | Risk method, acceptance criteria, a risk register and security requirements derived from it |
| 8 | Incident handling | Detection, analysis, response, logging of security-relevant events |
| 9 | Business continuity and crisis management | Recovery procedures, periodically verified backups, continuity, recovery and crisis plans |
| 10 | Supply chain | Policy on supplier dependencies; periodic checks on direct suppliers |
| 11 | Acquisition, development and maintenance | Procurement policy, secure development, configuration and change management |
| 12 | Cyber hygiene and training | Awareness for all staff, regular training for security roles |
| 13 | Cryptography | When to encrypt, which type, who implements it and who manages the keys |
| 14 | Personnel | Assigning security roles, trustworthiness requirements |
| 15 | Access policy | Logical and physical access; periodic review of identities and authentication means |
| 16 | Asset management | Classification, acceptable-use rules, a complete and current inventory |
| 17 | Threat information | Assess targeted alerts and advisories and record the outcome |
| 18 | Evaluation | Periodically test effectiveness, record the result and adjust |
Multi-factor authentication has no article of its own in the Decree. The obligation comes straight from article 21(3)(j) of the Act: multi-factor or continuous authentication and secured (emergency) communications where appropriate. The natural place to record that decision is the access policy required by article 15.
The Decree deliberately does not prescribe how you implement the measures. Its explanatory memorandum names ISO 27001 and NEN 7510 as starting points and gives two examples of a management system: an ISMS or a Cyber Security Management System (CSMS) based on IEC 62443. Terms such as “periodically” are also left open: you decide, and justify, which interval fits your risks.
🏭 How do you translate the Decree’s measures to OT?
In industrial environments almost every article needs its own interpretation, because availability comes first and systems often stay in service for decades. During the consultation several respondents specifically raised backups in OT, and article 9 was amended in response.
| Decree measure | What it means in an OT environment |
|---|---|
| Risk analysis (art. 7) | Zone-based risk assessment of plants, with process safety and availability as criteria |
| Incident handling (art. 8) | Passive network monitoring on the control network, central logging from engineering and operator stations |
| Continuity and backups (art. 9) | Offline backups of PLC programs, HMI projects and configurations, with restore tests on spare hardware |
| Supply chain (art. 10) | Requirements for system integrators and OEMs, including remote access for maintenance |
| Acquisition and maintenance (art. 11) | Security requirements in tender specifications, change management for logic and firmware |
| Cyber hygiene and training (art. 12) | Training for operators and technicians: USB use, third-party laptops, phishing on the shop floor |
| Cryptography (art. 13) | Encrypted connections where protocols allow, such as OPC UA; compensating controls for legacy protocols |
| Access and MFA (art. 15) | MFA on the jump host and at the DMZ boundary, not necessarily on the operator panel in the control room |
| Assets (art. 16) | An up-to-date asset inventory including firmware versions, down to field devices |
| Threat information (art. 17) | Assess vendor advisories and Known Exploited Vulnerabilities and record the patch decision |
| Evaluation (art. 18) | Periodic OT audits, tabletop exercises and tests in a test environment rather than on the running plant |
Note that articles 6 to 18 are a minimum you cannot skip, but they mostly prescribe policies and processes rather than specific technology. How you implement a measure technically follows from your risk assessment. Where something cannot be done directly in OT, such as patching or encrypting on a legacy controller, record in writing which compensating controls you apply and why. The Decree spells out this “comply or explain” approach for segregation of duties; the supervisor judges whether your implementation as a whole is appropriate.
👔 What does the Decree require of the management body?
The Act obliges every board member to complete training; chapter 5 of the Decree defines its content. The training must enable directors to identify cyber risks and to assess risk-management measures and their impact on the services the entity provides. As a minimum it covers types of risk, risk management processes, risk assessment methodology and the ten measure areas listed in the Act.
The certificate states the director’s name, the date or dates, the topics covered and the name of the provider, and must be in Dutch or English. The training itself may be delivered in any language. A requirement for an independent trainer appeared in the consultation draft but was dropped. The certificate is only required for the mandatory training; keeping your knowledge up to date afterwards can be demonstrated in other ways. The regulatory burden study attached to the Decree assumes almost 9 hours per director at a large company and almost 5 hours at a medium-sized one.
🔍 How does supervision differ for essential and important entities?
The measures in the Decree are identical for both categories; the difference lies in supervision and fines under the Cybersecurity Act. Which category applies to you is explained in Cybersecurity Act Scope.
| Feature | Essential entity | Important entity |
|---|---|---|
| Supervision | Proactive (ex ante) and reactive (ex post), also without a specific trigger | Reactive only, after indications or incidents |
| Typical instruments | Audits, inspections, scans and information requests | Investigation after a report or indication |
| Maximum fine | 10 million euros or 2% of worldwide annual turnover | 7 million euros or 1.4% of worldwide annual turnover |
In both cases the supervisor assesses, entity by entity, whether the chosen implementation is appropriate and proportionate. Your written justification is therefore your most important piece of evidence.
🔄 How does the Decree relate to reporting, the Wwke and the CRA?
- Incident reporting — chapter 6 supplements the reporting obligation: under article 24 an early warning also includes the presumed start time, the nature and noticeable effects of the incident, a forecast of the recovery time and the measures taken or planned
- Wwke — its sister decree is the Critical Entities Resilience Decree (Besluit weerbaarheid kritieke entiteiten, Staatsblad 2026, 190), which covers the physical and organisational resilience of critical entities
- Cyber Resilience Act — sets requirements for products; according to the explanatory memorandum, it does not relieve entities of their own assessment of the products they deploy
- Supply chain policy — article 10 builds on thinking about supply chain risk and the continuity of critical suppliers
🛠️ How do you approach implementation step by step?
- Determine scope and regime — do articles 6 to 18 of the Decree apply to you, or Implementing Regulation 2024/2690?
- Choose a management system — an ISMS based on ISO 27001, supplemented with IEC 62443-2-1 for the OT zones
- Run a gap analysis per article — map each article of the Decree against existing policy and log missing evidence
- Document your policies — security, risk, cryptography, access, asset and supply chain policies, adopted by the board
- Secure recoverability — demonstrably test backups and recovery plans, including for controllers
- Train people — awareness for everyone, in-depth training for security roles, and the mandatory board training
- Evaluate and improve — schedule an annual effectiveness review and record the outcome in writing
❓ Frequently asked questions
What is the difference between the Dutch Cybersecurity Act and the Cybersecurity Decree?
The Dutch Cybersecurity Act sets out the main obligations: duty of care, incident reporting, registration and board accountability. The Cybersecurity Decree is the order in council that works the duty of care out into concrete measures in articles 6 to 18. Both entered into force on 15 August 2026.
Is ISO 27001 certification mandatory under the Cybersecurity Decree?
No, the Cybersecurity Decree does not require certification. It does require a management system so that you can demonstrate compliance with the duty of care, and its explanatory memorandum cites ISO 27001 and a CSMS based on IEC 62443 as examples. A certificate can, however, make it easier to provide evidence to the supervisor.
Is multi-factor authentication mandatory under the Cybersecurity Decree?
Multi-factor authentication is mandatory where appropriate, based on article 21 of the Dutch Cybersecurity Act; the Cybersecurity Decree elaborates the access policy in article 15. In OT, MFA is most relevant for remote access and at the boundary between the office network and the control network.
Does the Cybersecurity Decree apply to cloud and data centre providers?
The measure articles 6 to 18 of the Cybersecurity Decree do not apply to cloud and data centre providers, DNS services, managed service providers and several other digital providers. They must comply with the European Implementing Regulation (EU) 2024/2690 instead. Board training and incident reporting still apply to them.
How often must measures be tested under the Cybersecurity Decree?
The Cybersecurity Decree uses the word “periodically” without a fixed interval. Each entity decides and justifies, based on its own risks, which frequency is appropriate. In practice an annual evaluation and restore test is a common minimum.
What must the board training certificate contain?
Under article 22 of the Cybersecurity Decree, the certificate states at least the board member’s name, the date or dates of the training, the topics covered and the name of the training provider. The certificate must be written in Dutch or English, even if the training itself was delivered in another language.
📌 In summary
Since 15 August 2026, the Cybersecurity Decree has been the Dutch order in council that turns the duty of care of the Cybersecurity Act into thirteen measure articles, from risk management and backups to cryptography, access policy and periodic evaluation, which you must document in writing and demonstrably apply.
The Decree is risk-based and does not mandate a specific standard, but it aligns with ISO 27001 and IEC 62443. For OT this means the same articles, implemented in a way that puts availability, long asset lifetimes and compensating controls at the centre.
