On 15 August 2026 two Dutch laws take effect on the same day. For industrial organisations, the hardest of the new duties lands on the OT side. This is what to have ready, and in what order.
The Cyberbeveiligingswet (Cbw) transposes NIS2 into Dutch law. Alongside it, the Wet weerbaarheid kritieke entiteiten (Wwke) transposes the CER directive. The Eerste Kamer approved the package on 7 July 2026, and both laws enter into force on 15 August 2026. Around 8,000 organisations across 18 sectors move from good practice to legal duty.
The Cbw is the cybersecurity half: registration, a duty of care, and incident reporting. The Wwke is the physical-resilience half for critical entities, covering continuity and physical protection. They share substance, and for many organisations the same OT risk analysis feeds both. Neither law names a standard. They require outcomes: managed risk, appropriate and proportionate measures, and the evidence that those measures exist.
You register your organisation in the entity register kept by the NCSC, so the supervisor knows who falls under the law.
You take appropriate and proportionate measures to manage the risks to your network and information systems, and you can demonstrate them. What counts as appropriate starts from a documented risk analysis. Without one, you cannot show why your controls are enough, and that demonstrability is the part the law is most interested in.
You report a significant incident without delay: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month, to the CSIRT and the supervisor.
Above all three sits the board. Directors approve the measures, supervise their implementation, and are expected to follow training. Where they are negligent, they can be held personally liable. That is the line that moves OT security from an engineering backlog onto a board agenda.
The law does not ask for a certificate. It asks whether you can show your risks are managed.
The demonstrable part is where OTRISK earns its place: the risk analysis, the zones and conduits, the approvals and the report live in one model, so showing your work is a click rather than a scramble. The knowledge behind it, though, is worth having whether or not a tool holds it.
The law splits organisations into two classes. The duties are largely the same; the supervision and the penalty ceilings differ.
| Essential entity | Important entity | |
|---|---|---|
| Supervision | Proactive: audits and checks in advance | Reactive: after a signal or an incident |
| Fine maximum | €10 million or 2% of worldwide annual turnover | €7 million or 1.4% of worldwide annual turnover |
| Applied as | Whichever is higher | Whichever is higher |
Fine maxima follow the NIS2 framework. Member states may set higher ceilings.
Fifteen August is a start date, not a deadline for being done. The organisations that will be calm about it are the ones that already know where their OT risks sit and can prove it. Begin with one installation and one risk analysis; that first assessment is manageable work, weeks rather than months, and everything the law asks for builds on it.
Facts checked in July 2026 against primary sources: Rijksoverheid (entry into force 15 August 2026), NCSC (registration, duty of care, reporting) and EUR-Lex (Directive (EU) 2022/2555). This is not legal advice.
Cybersecurity specialist for critical infrastructure: smart grids, EV charging and the OT behind them. Chairs the cybersecurity working group of the Dutch national charging infrastructure agenda and works with DIVD on vulnerability disclosure.
The risk analysis the zorgplicht asks for is IEC 62443-3-2 work. Here is where its partitioning step goes wrong.
Read the field note → Incident analysisThe kind of incident the zorgplicht points at: no malware, no zero-days, and a plant that heats 50,000 homes switched off.
Read the field note →Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.
Thirty minutes with an OT security expert, no slideware, no SDR relay.