OTRISK
← Field notes
Regulations 31 July 2026 4 min read Harm van den Brink

The Cyberbeveiligingswet countdown: what to have ready before 15 August 2026

On 15 August 2026 two Dutch laws take effect on the same day. For industrial organisations, the hardest of the new duties lands on the OT side. This is what to have ready, and in what order.

The Cyberbeveiligingswet (Cbw) transposes NIS2 into Dutch law. Alongside it, the Wet weerbaarheid kritieke entiteiten (Wwke) transposes the CER directive. The Eerste Kamer approved the package on 7 July 2026, and both laws enter into force on 15 August 2026. Around 8,000 organisations across 18 sectors move from good practice to legal duty.

What actually changes on 15 August

The Cbw is the cybersecurity half: registration, a duty of care, and incident reporting. The Wwke is the physical-resilience half for critical entities, covering continuity and physical protection. They share substance, and for many organisations the same OT risk analysis feeds both. Neither law names a standard. They require outcomes: managed risk, appropriate and proportionate measures, and the evidence that those measures exist.

The three duties

1. Registration

You register your organisation in the entity register kept by the NCSC, so the supervisor knows who falls under the law.

2. Duty of care (zorgplicht)

You take appropriate and proportionate measures to manage the risks to your network and information systems, and you can demonstrate them. What counts as appropriate starts from a documented risk analysis. Without one, you cannot show why your controls are enough, and that demonstrability is the part the law is most interested in.

3. Incident reporting (meldplicht)

You report a significant incident without delay: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month, to the CSIRT and the supervisor.

Above all three sits the board. Directors approve the measures, supervise their implementation, and are expected to follow training. Where they are negligent, they can be held personally liable. That is the line that moves OT security from an engineering backlog onto a board agenda.

The law does not ask for a certificate. It asks whether you can show your risks are managed.

What to have ready

  1. 1 A scope decision. Know whether you are an essential or an important entity, and which installations fall in. Leave the legal classification to your counsel; start the risk work regardless, because you will need it either way.
  2. 2 Registration details ready to file once the NCSC entity register opens for your sector.
  3. 3 A demonstrable OT risk analysis. This is the zorgplicht foundation. IEC 62443-3-2 is the route built for OT: it takes you from scoping an installation to a documented, approved risk picture with target security levels.
  4. 4 An incident-reporting runbook that meets the 24-hour, 72-hour and one-month clock, with roles named and a working channel to the CSIRT.
  5. 5 Board sign-off and an evidence trail, so that approval and oversight are on record rather than assumed.
  6. 6 Requirements on your suppliers and their remote access, since the supply chain is in scope too.

The demonstrable part is where OTRISK earns its place: the risk analysis, the zones and conduits, the approvals and the report live in one model, so showing your work is a click rather than a scramble. The knowledge behind it, though, is worth having whether or not a tool holds it.

Essential or important: what the difference means

The law splits organisations into two classes. The duties are largely the same; the supervision and the penalty ceilings differ.

Essential entity Important entity
Supervision Proactive: audits and checks in advance Reactive: after a signal or an incident
Fine maximum €10 million or 2% of worldwide annual turnover €7 million or 1.4% of worldwide annual turnover
Applied as Whichever is higher Whichever is higher

Fine maxima follow the NIS2 framework. Member states may set higher ceilings.

The date is not the finish line

Fifteen August is a start date, not a deadline for being done. The organisations that will be calm about it are the ones that already know where their OT risks sit and can prove it. Begin with one installation and one risk analysis; that first assessment is manageable work, weeks rather than months, and everything the law asks for builds on it.

Facts checked in July 2026 against primary sources: Rijksoverheid (entry into force 15 August 2026), NCSC (registration, duty of care, reporting) and EUR-Lex (Directive (EU) 2022/2555). This is not legal advice.

Harm van den Brink
Written by
Harm van den Brink

Cybersecurity specialist for critical infrastructure: smart grids, EV charging and the OT behind them. Chairs the cybersecurity working group of the Dutch national charging infrastructure agenda and works with DIVD on vulnerability disclosure.

Keep reading

IEC 62443

Five zone-partitioning mistakes we keep seeing.

The risk analysis the zorgplicht asks for is IEC 62443-3-2 work. Here is where its partitioning step goes wrong.

Read the field note →
Incident analysis

The Polish CHP breach ran on connections nobody drew.

The kind of incident the zorgplicht points at: no malware, no zero-days, and a plant that heats 50,000 homes switched off.

Read the field note →

From standard to signed-off.

Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.

Thirty minutes with an OT security expert, no slideware, no SDR relay.