Cyberbeveiligingswet readiness for Dutch healthtech
Asteron helps healthcare and healthtech organisations determine whether the Dutch Cyberbeveiligingswet applies and prepare the governance, evidence and response capability required from 15 August 2026. We connect applicability, NCSC registration, duty-of-care measures, management oversight, supplier security and statutory incident reporting within one practical readiness programme. The service is designed for organisations operating in the Netherlands and European healthtech companies entering the Dutch healthcare market.
- Essential or important entity status assessed
- NCSC registration and ownership prepared
- Duty-of-care measures mapped
- 24- and 72-hour reporting rehearsed
What is the Cyberbeveiligingswet?
The Cyberbeveiligingswet, commonly abbreviated as Cbw, implements the EU NIS2 Directive in the Netherlands and replaces the Wet beveiliging netwerk- en informatiesystemen. It enters into force on 15 August 2026.
The law introduces cybersecurity risk-management, registration, incident-reporting and management-accountability duties for essential and important entities across 18 sectors, including healthcare. It is a legal obligation rather than a certifiable standard: there is no “Cyberbeveiligingswet certificate”.
Who may be in scope?
Applicability depends on the organisation’s services, sector, size, Dutch establishment and any specific designation—not on employee count alone.
Healthcare providers and certain other organisations within the health sector may qualify directly. Healthtech companies may also fall within scope through digital infrastructure, managed services, manufacturing or another listed activity.
A supplier is not automatically regulated merely because it serves a hospital. However, regulated customers must manage supply-chain security and may pass stronger security, incident-notification and assurance requirements into contracts.
The four operational obligations
Registration
In-scope organisations must register through the NCSC portal. Registration requires accurate entity, service and contact information, clear internal ownership and the appropriate eHerkenning authorisation.
Duty of care
Organisations must adopt proportionate technical, operational and organisational measures based on their risks. Documentation must show not only that controls exist, but how risks were assessed, decisions approved and effectiveness reviewed.
Incident reporting
A significant incident requires an early warning within 24 hours and a fuller notification within 72 hours. Further updates may be requested, followed by a final report normally within one month.
Management accountability
Management must approve and oversee cybersecurity measures, understand material risks and receive appropriate training. Responsibility cannot be delegated entirely to IT or an external provider.
Incident-reporting timeline
Detect and assess
Establish whether the event may be significant and trigger the reporting decision workflow.
Within 24 hours
Submit the early warning to the NCSC through the authorised channel.
Within 72 hours
Provide the incident notification with available assessment of severity, impact and indicators.
During the response
Provide intermediate updates if requested by the supervisory or CSIRT authority.
Within one month
Submit the final report, or a progress report if the incident remains ongoing.
Reporting readiness requires named decision-makers, escalation thresholds, evidence preservation, rehearsed communications and coordination with existing incident-response plans. Improvising these decisions within a 24-hour statutory window is not a workable strategy.
What the duty of care means in practice
Governance and resilience
- – Cybersecurity risk analysis and approved security policies
- – Incident handling, business continuity, backup and crisis arrangements
- – Management oversight, staff awareness and recurring training
- – Regular evaluation of whether measures remain effective
- – Defined ownership, access control and asset management
Product and supply-chain security
- – Supplier and service-provider risk management
- – Secure acquisition, development and maintenance
- – Vulnerability identification, disclosure and remediation
- – Appropriate encryption, authentication and secure communications
- – Security requirements reflected in contracts and product decisions
The appropriate depth depends on the organisation’s services, threat exposure and potential impact, not on a generic checklist. Measures should be justified against documented risks, reviewed at defined intervals and demonstrably approved by management.
Cyberbeveiligingswet, NIS2 and NEN 7510
NEN 7510 or ISO 27001 certification can reduce duplicated work, but neither automatically confirms full Cyberbeveiligingswet compliance. Applicability, NCSC registration, management duties and statutory reporting must still be addressed explicitly.
How Asteron prepares your organisation
Applicability assessment
Map entities, services, sectors and Dutch establishment to determine whether the organisation is an essential or important entity, or exposed primarily through supply-chain obligations.
Governance and registration
Assign management, security and reporting ownership. Prepare NCSC registration information, eHerkenning authorisations and internal notification routes.
Risk and evidence review
Assess current controls, documentation and material gaps against duty-of-care expectations. Reuse existing NEN 7510 or ISO 27001 evidence where available.
Readiness programme
Prioritise governance, product-security, supplier and resilience measures according to actual risk rather than a generic checklist.
Incident-reporting exercise
Test the 24- and 72-hour decision and reporting process with named decision-makers, escalation thresholds and rehearsed communications.
Management readiness
Prepare approval records, reporting cadence and defensible evidence so management can demonstrate oversight and informed risk decisions.
Deliverables
Deliverables are tailored to the agreed scope and existing security programme. Organisations with a mature NEN 7510 or ISO 27001 baseline typically require targeted extensions rather than a full rebuild.
Applicability and governance
- – Documented applicability and entity-class assessment
- – Scope, ownership and management-responsibility model
- – NCSC registration preparation
- – Legal-obligation and evidence map
- – Prioritised remediation roadmap
Operational readiness
- – Duty-of-care control assessment
- – Supplier-security and contract review
- – Incident-classification and escalation workflow
- – Reporting timeline and decision records
- – Management briefing and readiness summary
Cyberbeveiligingswet readiness pricing
For organisations that already maintain an Asteron Compliance Core. Existing risks, policies, suppliers, incidents, continuity arrangements and evidence are reused and extended for the Dutch obligations.
For organisations without an established Compliance Core. Final scope depends on entity structure, services, existing documentation, supplier landscape and operational complexity.
The published entry price reflects the initial 10–50 employee band. Larger or more complex organisations are scoped through the relevant pricing band.
- – 40% at signing
- – 40% after delivery of the applicability and gap baseline
- – 20% after the contracted readiness outcome
Prices exclude VAT where applicable.
What remains separate
The Cyberbeveiligingswet is not a certification scheme, so no certification audit or certificate is included. External providers are contracted and paid separately unless explicitly included in the proposal.
- – Formal external legal opinions
- – Technical remediation or product development
- – Penetration testing and continuous vulnerability management
- – Replacement of security tooling
- – Regulatory filings or authority decisions beyond the agreed support
- – Work for separate legal entities or materially expanded scope
Responsibilities
Asteron
- – Assess applicability using the information provided
- – Translate obligations into practical governance and evidence
- – Identify gaps and prioritise remediation
- – Prepare registration and incident-reporting workflows
- – Support management readiness and decision records
Your organisation
- – Confirm legal entities, services and operational facts
- – Appoint accountable management and internal owners
- – Approve policies, risks and remediation priorities
- – Implement agreed technical and operational changes
- – Submit registrations and incident reports through authorised channels
Frequently asked questions
What is the Dutch Cyberbeveiligingswet?
The Cyberbeveiligingswet (Cbw) is the Dutch law implementing the EU NIS2 Directive. It sets binding cybersecurity risk-management, registration, incident-reporting and management-accountability duties for essential and important entities across 18 sectors, including healthcare.
When does the Cyberbeveiligingswet enter into force?
The Cyberbeveiligingswet enters into force on 15 August 2026. Applicability, registration, duty-of-care measures and reporting workflows must be operational from that date for in-scope organisations.
Does it apply to every healthcare or healthtech company?
No. Applicability depends on Dutch establishment, sector, listed activity and size or specific designation. Healthcare providers and certain other health-sector organisations may qualify directly. Many healthtech suppliers are not directly regulated but face contractual obligations through their regulated customers.
What is the difference between an essential and important entity?
Both classes share the main risk-management and reporting duties. The difference lies mainly in supervision and enforcement: essential entities face proactive supervision, important entities are supervised primarily in response to indications of non-compliance.
Must an in-scope organisation register with the NCSC?
Yes. In-scope organisations must register through the NCSC portal, providing accurate entity, service and contact information and assigning clear internal ownership, typically using eHerkenning authorisation.
What are the 24- and 72-hour incident-reporting deadlines?
A significant incident requires an early warning within 24 hours of becoming aware of it and a fuller incident notification within 72 hours. Further updates may be requested, followed by a final report normally within one month.
Does supplying software to a hospital make us directly subject to the law?
Not automatically. Direct applicability depends on the supplier’s own sector, activity, Dutch establishment and size. However, regulated hospitals must manage supply-chain security, so contractual security, notification and assurance obligations frequently reach suppliers even when they are not directly regulated.
Is NEN 7510 certification enough for Cyberbeveiligingswet compliance?
No. NEN 7510 provides substantial governance and healthcare-specific control evidence, but it does not by itself confirm compliance. Applicability, NCSC registration, statutory reporting and management-accountability duties must still be addressed explicitly.
Is ISO 27001 certification enough?
No. ISO 27001 is a strong management-system foundation and can reduce duplicated work, but it does not cover the specific Dutch obligations concerning registration, incident reporting and management duties under the Cyberbeveiligingswet.
What is management responsible for?
Management must approve and oversee cybersecurity measures, understand material risks, receive appropriate training and maintain defensible evidence of decisions. Responsibility cannot be delegated entirely to IT or an external provider.
How much does Cyberbeveiligingswet readiness cost?
For the initial published company-size band, readiness starts at €6,900 from an existing Asteron Compliance Core or from €8,900 as a first project. Larger or more complex organisations are scoped through the relevant pricing band.
Official references
- – Ministerie van Justitie en Veiligheid — Cyberbeveiligingswet information
- – Nationaal Cyber Security Centrum (NCSC) — registration and reporting
- – Rijksinspectie Digitale Infrastructuur — supervisory guidance
- – EU NIS2 Directive (Directive (EU) 2022/2555)
- – NEN 7510 guidance on cybersecurity in Dutch healthcare
Last reviewed: July 2026
Asteron is not endorsed by or partnered with the Dutch government, NCSC, NEN, ISO or any supervisory authority.
Related services and frameworks
Prepare for the Dutch Cyberbeveiligingswet
Establish whether the law applies, give management a defensible view of current readiness and turn the remaining obligations into an actionable programme before 15 August 2026.
