Cyberbeveiligingswet and Critical Entities Resilience Act Deadline is Here. Is Your Organization Ready?
For the Dutch version of this article, please click here.
On 15 August 2026, two major Dutch laws come into force: the Cyberbeveiligingswet (Cbw), which implements the EU NIS2 Directive, and the Wet Weerbaarheid Kritieke Entiteiten (Wwke), which implements the Critical Entities Resilience (CER) Directive. Together, they introduce stricter cybersecurity requirements for key sectors in the Netherlands.
The key question security leaders must answer is no longer: “Do you have cybersecurity controls?” Regulators now expect affected organizations to demonstrate continuous visibility, monitoring and risk management.
For organizations in the Netherlands, understanding how the Cbw and Wwke work is the first step to meeting the new requirements.
What is the Cyberbeveiligingswet?
The Cyberbeveiligingswet, or Cybersecurity Act, is the Dutch implementation of the NIS2 Directive and replaces the existing Dutch security legislation for network and information systems. The Cbw introduces new obligations for organizations that provide essential services across sectors such as healthcare, energy, transportation, banking, manufacturing, digital infrastructure, government, and water.
Key requirements of the Dutch Cybersecurity Act include:
- Risk management measures
- Vulnerability management
- Security incident reporting
- Supply chain security
- Executive accountability
- Board-level cybersecurity oversight
- Registration requirements
- Cooperation with designated CSIRTs (Computer Security Incident Response Teams)
What is the Wet Weerbaarheid Kritieke Entiteiten?
The Wwke implements the EU Critical Entities Resilience (CER) Directive into Dutch law.
While the Cyberbeveiligingswet focuses primarily on cyber resilience, the Wwke requires critical entities to prepare for disruptions caused by:
- Cyber attacks
- Physical sabotage
- Supply chain disruption
- Natural disasters
- Infrastructure failures
- Geopolitical threats
The objective is ensuring continuity of essential services that society depends on.
Does the Cyberbeveiligingswet or Wwke Apply to Your Organization?
The Cyberbeveiligingswet covers organizations in 18 critical sectors. These include manufacturing, food production and distribution, postal and courier services, public administration, digital services, waste management and research.
Your organization is likely to fall within scope of the Cbw if it:
- operates in a sector listed in the legislation; and
- has at least 50 employees, or an annual turnover above €10 million.
Some organizations are covered regardless of their size, including certain digital infrastructure providers, trust-service providers and public-sector bodies. Group structures and cross-border operations can also affect the assessment.
The Wwke follows a different process. Organizations do not generally determine their own status using the same sector and size test. Instead, the responsible minister formally designates organizations as critical entities based on the essential services they provide.
What Will Regulators Actually Look For?
Policies and controls remain important, but they are now only part of what regulators expect for compliance with the Cbw and Wwke.
Organizations also need to show that they understand their current risk exposure and manage it on an ongoing basis. After an incident, the questions may be straightforward:
Did you know the vulnerable asset existed?
Could you identify and address the exposure before it was exploited?
As discussed in Outpost24’s NIS2-focused webinars, the Cybersecurity Act introduces a clear expectation of visibility and continuous monitoring, not just annual assessments and policy documents.
Why Does Your Attack Surface Matter for Compliance?
Your attack surface encompasses every internet-facing asset that an attacker could potentially target, including:
- Websites
- APIs
- Cloud environments
- SaaS platforms
- Mobile applications
- Remote access services
- Third-party connections
The difficulty is that this environment rarely stays static. New services are deployed, cloud resources are misconfigured, credentials are exposed, and forgotten domains remain online. Shadow IT can add further assets that security teams do not know about.
Attackers actively look for these gaps, scanning for exposed services, vulnerable web applications, leaked credentials, and other weaknesses. Organizations need a comparable level of visibility.
As the attack surface grows and changes, continuous visibility becomes an important part of effective risk management. The Cybersecurity Act and Critical Entities Resilience Directive enforce measures to ensure that is the case.
How Can My Organization Demonstrate Cbw and Wwke Readiness?
A practical starting point is answering these questions:
- Do you have a complete inventory of external-facing assets?
- Can you continuously identify newly exposed systems?
- Can you prioritize vulnerabilities based on actual business risk?
- Can you detect compromised credentials linked to your organization?
- Can you demonstrate board-level oversight of cybersecurity risk?
- Can you identify risks introduced through suppliers and third parties?
- Can you produce evidence of monitoring, testing and remediation activities?
If any of these questions are difficult to answer, there may be gaps to address before enforcement begins.
How Can Outpost24 Help You Prepare?
The Cyberbeveiligingswet and Wwke both require your organization to understand its exposure, manage risk, and demonstrate ongoing resilience. Outpost24’s expert-led services and solutions help you build these capabilities in four keys ways.
Establish Continuous Visibility
Regulators increasingly expect you to know what assets you own, what is exposed, and where risk exists. Outpost24’s External Attack Surface Management (EASM) solution continuously discovers and monitors internet-facing assets, helping you identify unknown assets, forgotten domains, exposed services, and emerging vulnerabilities before they become security incidents.
Validate and Reduce Risk
Risk management is a core requirement of Cbw and Wwke. Outpost24’s OutscanNX helps you identify and prioritize vulnerabilities for more effective risk exposure reduction. Our Penetration Testing as a Service (PTaaS) then helps you determine which represent genuine exploitable risk, such as demonstrating attack chains combining multiple vulnerabilities. This enables you to prioritize remediation efforts and focus resources where they will have the greatest impact.
Identify Threats Beyond Your Attack Surface
Understanding vulnerabilities is only part of the picture. Outpost24’s Threat Intelligence and Digital Risk Protection capabilities help you identify leaked credentials, brand impersonation, dark web exposure, and other external threats targeting your organization, supporting earlier detection and response.
Build Long-Term Resilience
The Cbw and Wwke are ongoing commitments. Outpost24 CyberFlex combines attack surface visibility, expert-led security validation, and ongoing governance within a flexible cybersecurity program that evolves alongside your changing business environment and compliance requirements.
Outpost24’s Managed Security Services team can act as an extension of your security operations, helping you continuously monitor exposure, strengthen security maturity, and maintain resilience over time.
Prepare for Compliance Before 15 August 2026
The Cyberbeveiligingswet and Wet Weerbaarheid Kritieke Entiteiten reflect a broader shift across Europe toward demonstrable resilience, continuous monitoring, and executive accountability. Organizations that act now can use this transition as an opportunity to strengthen both compliance and security maturity.
The question is no longer whether cyber threats will occur.
The question is whether your organization can identify, manage, and reduce exposure before attackers exploit the gaps.
Want to Assess Your Readiness for the Cbw and Wwke?
Talk to an Outpost24 expert and discover how continuous visibility, attack surface management, penetration testing, and threat intelligence can help strengthen your cyber resilience. Contact us today or book a demo to see our solutions in action.