simler
CyberbeveiligingswetNIS2Compliance

Does the Cyberbeveiligingswet apply to your organisation? How to work it out.

Michiel van der SteegAugust 11, 20264 min read

The Cyberbeveiligingswet comes into force on 15 August 2026, with no transition period. In an earlier post we covered what the law asks of organisations: a duty of care, incident reporting, and board members who are personally accountable.

Plenty of organisations are still one step earlier than that. They don't know whether the law applies to them at all.

That isn't carelessness. Scope depends on sector, on size, and on a set of exceptions where size stops mattering entirely. Here is how to work it out, and where organisations most often get it wrong.

The main rule: sector and size

For most organisations it comes down to two questions, answered in order.

Are you active in a designated sector? The Act covers eighteen sectors across two annexes. Annex 1 holds the highly critical ones: energy, transport, banking, financial market infrastructure, healthcare, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Annex 2 holds the other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing of certain products, digital providers and research.

Read the wording carefully. What matters is not your industry code or how you describe yourself, but the type of entity named within that sector. The annexes list specific entity types.

Do you meet the size threshold? The Act follows the European definition of company size:

  • Medium: from 50 employees, or more than €10 million in annual turnover or balance sheet total.
  • Large: from 250 employees, or more than €50 million in annual turnover.

Fall below both and, as a general rule, you fall outside the Act.

Essential or important, and why the difference matters

If you do meet the threshold, your annex and your size together determine how you qualify. Large organisations in an Annex 1 sector are essential entities. Medium-sized organisations, and organisations in Annex 2, are generally important entities.

Every obligation in the Act applies to both. The difference is in supervision, and it is a significant one.

Essential entities are subject to proactive supervision. A regulator can check compliance without anything having gone wrong. Important entities fall under reactive supervision: checks happen mainly after the fact, following an incident or a signal of non-compliance.

For an essential entity that means you can be asked to demonstrate your measures at a moment you don't choose.

Four ways organisations get this wrong

The main rule covers most cases. The exceptions are where it goes wrong.

1. For some organisations, size is irrelevant

Certain entity types fall under the Act no matter how small they are. That covers central and decentralised government bodies, qualified trust service providers, top-level domain name registries and DNS service providers. They always qualify as essential entities.

Medium-sized providers of public electronic communications networks or services are also essential entities, where their size alone would have made them important. And smaller telecom providers can fall under the Act without reaching the 50-employee threshold at all.

A municipality with forty staff is in scope. So is a six-person DNS provider.

2. A minister can designate you

The responsible minister can designate an individual organisation as an essential entity even when it doesn't automatically fall under the Act. That applies, for example, when you are the sole provider of a service, or when an outage would have serious consequences for public safety.

This isn't hypothetical. The Minister of Education has announced that all higher education institutions will be designated as important entities.

3. The link with the Critical Entities Resilience Act

If you are designated a critical entity under the Wet weerbaarheid kritieke entiteiten, you are automatically treated as an essential entity under the Cyberbeveiligingswet as well. Two laws, one consequence. Organisations tracking the Wkte designation without tracking the Cbw miss this.

4. You're out of scope, your customer isn't

This affects the largest group by far. The supply chain provisions require in-scope organisations to manage the cyber risk their suppliers introduce. In practice that means they will be asking you.

If you supply a hospital, a bank, a utility or a government body, the question about your security arrives through your contract whether or not the law names you. For many suppliers this is the point at which the Cbw becomes their problem.

Who is explicitly excluded

Not every public body is in scope. Organisations principally active in national security, public safety, defence or law enforcement are excluded. That covers the Ministry of Defence, the intelligence services, the police, the Public Prosecution Service and the safety regions. Their security is governed by separate sectoral legislation.

Run the check

We built a free Cbw checker that walks through these steps. Answer a few questions about your sector, size and services, and you get an initial indication of whether the law is likely to apply to you.

No account, done in a few minutes.

Run the free check

It remains an indication. Where there is doubt, and particularly around group structures or borderline cases near the thresholds, legal advice is the right next step. For most organisations though, the check answers the question they are currently stuck on.

And if you are in scope

Registration in the NCSC entity register comes first, then the duty of care. Part of that duty is testing how effective your incident response actually is. A response plan that has never been run under pressure won't hold up in front of a regulator asking for evidence that it works.

That is what we build: tabletop exercises grounded in your own policies and organisation, ending in a debrief report you can put in your audit file.

Frequently asked questions

Which organisations fall under the Cyberbeveiligingswet?

As a main rule: organisations active in one of the eighteen designated sectors (across two annexes) that meet the size threshold — from 50 employees, or more than €10 million in annual turnover or balance sheet total. Annex and size together determine whether you qualify as an essential or an important entity.

Can a small organisation still be in scope?

Yes. Government bodies, qualified trust service providers, TLD registries and DNS service providers are in scope regardless of size, and a minister can designate individual organisations. A municipality with forty staff or a six-person DNS provider falls under the Act.

What's the difference between an essential and an important entity?

Every obligation applies to both; the difference is supervision. Essential entities face proactive supervision — a regulator can check compliance without anything having gone wrong. Important entities are supervised reactively, mainly after an incident or a signal of non-compliance.

My organisation is out of scope — am I done?

Often not. The supply-chain provisions require in-scope organisations to manage the cyber risk their suppliers introduce. If you supply a hospital, bank, utility or government body, the security question arrives through your contract whether or not the law names you.

Ready to practice it for real?

Generate a tabletop exercise tailored to your organization in minutes.

Sign up