ctipilot.ch

Netherlands Cyberbeveiligingswet (NIS2 transposition)

policy · policy:netherlands-nis2-cyberbeveiligingswet-2026

Dutch NIS2-transposition law approved by the Eerste Kamer on 7 July 2026 and entering into force on 15 August 2026, replacing the Wbni and imposing registration in NCSC-NL's national entity register, a duty of care, an incident-notification duty and board-level accountability on more than 8,000 organisations across 18 sectors (Rijksoverheid, 2026-07-07).

Aliases: Cbw, Cyberbeveiligingswet, Dutch NIS2 law

Coverage timeline
7
first 2026-06-29 → last 2026-08-09
Peak priority
high
1 high · 6 notable
Sources cited
27
24 hosts
Sections touched
2
weekly-looking-ahead, weekly-policy
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Story timeline

  1. 2026-08-09NIS2 enters its enforcement phase in two more jurisdictions from opposite ends — the Netherlands' transposition law takes effect on 15 August for 8,000+ organisations, while Germany's registration deadline has lapsed with BSI's own site telling unregistered entities to register immediately
    weekly-policyOne NIS2 clock starts on 15 August; the other has run out with a registration gap Germany has not closed
  2. 2026-08-092026-W32 looking ahead — items already in motion: a NIS2 law in force in six days, a PAM appliance whose full exploitation detail is due in September, five products that will never be patched, and a federal ISMS deadline five months out
    weekly-looking-aheadW32 outlook — the 15 August Dutch NIS2 clock, WALLIX details due in September, and five products with no fix coming
  3. 2026-07-262026-W30 looking ahead — items already in motion: a nginx pre-auth RCE PoC on a ~21-day release clock, Oracle Fusion Middleware abuse assessed 'very likely', a public AD CS DCSync PoC, a Mitel CVE pending, and two EU compliance clocks tightening
    weekly-looking-aheadW30 outlook — the nginx RCE PoC clock, Oracle Fusion Middleware abuse 'very likely', a public Certighost AD CS PoC, a pending Mitel CVE, and the CRA/NIS2 clocks
  4. 2026-07-12Netherlands NIS2 transposition confirmed: the Senate passed the Cyberbeveiligingswet on 7 July, fixing entry into force at 15 August 2026
    weekly-policyDutch NIS2 (Cyberbeveiligingswet) passed the Senate 7 July — entry into force fixed for 15 August 2026, ~8,000 organisations in scope
  5. 2026-07-12Looking ahead — 2026-W28
    weekly-looking-aheadLooking ahead — 2026-W28: items already in motion for the coming weeks
  6. 2026-07-05Netherlands NIS2 transposition slips past its 1 July target — Senate vote set for 7 July, entry into force now 15 August 2026
    weekly-policyNetherlands NIS2 (Cyberbeveiligingswet) slips — Senate vote 7 July, entry into force now 15 August 2026
  7. 2026-06-29Netherlands NIS2 (Cyberbeveiligingswet) clears the lower house — entry into force targeted for 1 July 2026
    weekly-policy

Where this entity is cited

  • weekly-policy4
  • weekly-looking-ahead3

Source distribution

  • bsi.bund.de2 (7%)
  • ncsc.nl2 (7%)
  • rijksoverheid.nl2 (7%)
  • advisories.ncsc.nl1 (4%)
  • cert.ssi.gouv.fr1 (4%)
  • cybersecuritynews.com1 (4%)
  • cyberstan.co.uk1 (4%)
  • dserver.bundestag.de1 (4%)
  • other16 (59%)

explore in graph

All cited sources (27)

Entries about Netherlands Cyberbeveiligingswet (NIS2 transposition) (7)

2026-08-09 · view entry permalink →

NOTABLENATOA2

NIS2 enters its enforcement phase in two more jurisdictions from opposite ends — the Netherlands' transposition law takes effect on 15 August for 8,000+ organisations, while Germany's registration deadline has lapsed with BSI's own site telling unregistered entities to register immediately

NIS2 has spent two years as a transposition story. This week it is an enforcement story in two member states at once, and the two are at opposite ends of the same process — which makes them more useful read together than separately.

The Dutch clock starts in six days. The Eerste Kamer approved the Cyberbeveiligingswet and the companion Wet weerbaarheid kritieke entiteiten on 7 July, and the government's announcement states that "de wetten treden op 15 augustus 2026 in werking. Vanaf dat moment gelden nieuwe verplichtingen voor ruim 8000 organisaties in Nederland op het gebied van cyberbeveiliging" — the laws enter into force on 15 August 2026, from which point new cyber-security obligations apply to more than 8,000 Dutch organisations (Rijksoverheid, 2026-07-07). The Cyberbeveiligingswet replaces the existing Wbni and covers essential and important service providers across 18 sectors including energy, drinking water, digital infrastructure, healthcare, government and transport. NCSC-NL's own page confirms the date and the first duty: registration in the national entity register is mandatory from 15 August (NCSC-NL, checked 2026-08-09). Three further duties attach — a duty of care to manage network and information-system security risks, an incident-notification duty to the organisation's CSIRT and competent authority, and board-level accountability with a training requirement — and organisations are themselves responsible for determining whether they fall in scope, which is the provision that generates the most work.

Germany shows what the same process looks like eighteen months later. BSI's NIS2 landing page, fetched during this run, carries the banner "Frist ist abgelaufen" over the text "Die gesetzliche Registrierungsfrist ist bereits abgelaufen. Von NIS-2 betroffen und noch nicht registriert? Dann jetzt umgehend im BSI-Portal registrieren!" (BSI, checked 2026-08-09) — the statutory deadline is past, and the authority is directing non-compliant entities to register immediately rather than describing an active grace period. BSI's own press release establishes the population: "für rund 29.500 Unternehmen in Deutschland und Institutionen der Bundesverwaltung gelten seit Inkrafttreten des NIS-2-Umsetzungsgesetzes neue gesetzliche Pflichten in der IT-Sicherheit" (BSI, 2026-01-06). Against that, the only registration count this run could trace to an official document is the Federal Government's written answer to a parliamentary question: "Zum 5. März 2026 waren 11.388 wichtige und besonders wichtige Einrichtungen beim Bundesamt für Sicherheit in der Informationstechnik (BSI) registriert" (Deutscher Bundestag, 2026-03-13) — roughly 39% of the obligated population, counted the day before the statutory deadline. Higher figures for later dates, and an extension to 31 July 2026, circulate widely with attribution to BSI; this run could not confirm either against a first-party BSI publication, and they are noted here as such rather than repeated as fact.

De Eerste Kamer heeft op 7 juli ingestemd met de Cyberbeveiligingswet (Cbw) en de Wet weerbaarheid kritieke entiteiten (Wwke)... De wetten treden op 15 augustus 2026 in werking. Vanaf dat moment gelden nieuwe verplichtingen voor ruim 8000 organisaties in Nederland op het gebied van cyberbeveiliging.

Rijksoverheid

Die gesetzliche Registrierungsfrist ist bereits abgelaufen. Von NIS-2 betroffen und noch nicht registriert? Dann jetzt umgehend im BSI-Portal registrieren!

Für rund 29.500 Unternehmen in Deutschland und Institutionen der Bundesverwaltung gelten seit Inkrafttreten des NIS-2-Umsetzungsgesetzes neue gesetzliche Pflichten in der IT-Sicherheit.

BSI 2026-01-06

Zum 5. März 2026 waren 11.388 wichtige und besonders wichtige Einrichtungen beim Bundesamt für Sicherheit in der Informationstechnik (BSI) registriert.

Deutscher Bundestag / Bundesregierung 2026-03-13
policy09 Aug 23:45Zmulti-sourceOpen finding ↗

2026-08-09 · view entry permalink →

NOTABLENATOA1

2026-W32 looking ahead — items already in motion: a NIS2 law in force in six days, a PAM appliance whose full exploitation detail is due in September, five products that will never be patched, and a federal ISMS deadline five months out

Items already in motion at the close of ISO week 2026-W32, each with a source and a date. None of these is a prediction.

Dated obligations.

  • 15 August 2026 — the Netherlands' Cyberbeveiligingswet enters into force, together with the companion critical-entities resilience law, imposing registration, duty-of-care, incident-notification and board-accountability duties on more than 8,000 organisations across 18 sectors, with registration in NCSC-NL's national entity register mandatory from that date (Rijksoverheid, 2026-07-07). Relevant to anyone with Dutch entities, suppliers or public-sector counterparts, whose notification behaviour changes on that date.
  • 11 September 2026 — the Cyber Resilience Act's reporting obligations begin, ahead of the regulation's principal obligations in December 2027. 13 September 2026 — ENISA's consultation on the draft EU Managed Security Services certification scheme closes, two days later; providers delivering services under the EU Cybersecurity Reserve would need that certification within two years of the scheme's entry into force, which makes it a procurement gate rather than a voluntary mark. Both were established in prior weekly coverage and neither date has moved.
  • 2 December 2026 — two new prohibited AI practices apply under the AI Act as amended, and 2 December 2027 / 2 August 2028 are the new application dates for high-risk obligations under Annex III and Annex I respectively, following Regulation (EU) 2026/1744 (EUR-Lex, 2026-07-24). Any readiness plan written against 2 August 2026 for Annex III systems is now diarised to the wrong date.
  • 1 January 2027 — Swiss federal administrative units must have built their ISMS. The Informationssicherheitsverordnung requires the administrative units under its Article 2(1)(c) to build their information-security management system within three years of the ordinance's entry into force, and the ordinance entered into force on 1 January 2024 (Fedlex, ISV SR 128.1). Roughly five months remain. The addressee is the federal administration itself; commentary that presents this as a general critical-infrastructure obligation is reading it more broadly than the text supports.

Disclosure and exploitation clocks.

  • September 2026 — full technical details of the WALLIX Bastion authentication bypass are due. WALLIX states that the reporting researchers intend to publish the complete write-up of the CVSS 4.0 base 10.0 flaw that gives an unauthenticated caller full product-administrator control of the appliance — its credential vault and session recordings included — in September (WALLIX, 2026-07-20). Bastion 12.3.7 and 12.4.1 and later are patched, per the CERT-FR advisory that relayed the bulletin (CERT-FR, 2026-08-06). This is a dated window for remediating quietly, not a current threat.
  • Cl0p's Windchill and FlexPLM listings have still not begun. Research re-checked this week found no leak-site listing for that campaign, leaving affected organisations in the interval between exfiltration and publication — the status a prior weekly recorded, unchanged.

Flaws with no fix coming. Five items from this week's coverage will not be resolved by waiting for a vendor, and each therefore converts into an architecture or lifecycle decision:

  • Tobit TeamDavid — 22 CVEs bounded at "Rollout 524" with no fixed release named, against roughly 12,000 internet-facing instances, and researchers reporting that both they and the coordinating national cyber security centre were left without a vendor response (InfoGuard Labs, 2026-08-07).
  • Flowise — three CVEs assigned days after the vendor announced it is winding down; self-hosted operators own the compensating controls.
  • Zbtlink routers (ENDLESSDOORS) — a factory-shipped root backdoor on twenty models, where the discloser's remediation is device replacement.
  • CPDLC over ATN-B1 — five flaws that are properties of the standard, with CISA recording the remediation category as none-available.
  • Check Point's end-of-support management trains — R80 through R81.10 are listed as affected by this week's unauthenticated management-authentication bypass with no fix on offer.

In development, no date. NCSC UK confirms it is working with international partners on a reference architecture for forensic observability in network appliances, intended to give vendors something concrete to build to (NCSC UK, 2026-07-29). It is not published, and no publication date is stated. Separately, the Metabase SQL-injection zero-day exploited this week still has no CVE identifier assigned, so it will not reach any process that waits for one.

Builds on: 2026-08-09/wallix-bastion-rest-api-unauth-admin-cvss10 · 2026-08-09/teamdavid-tobit-22-cves-unauth-mailbox-takeover-dach · 2026-08-08/flowise-three-cves-vendor-sunset-no-fix-coming · 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor · 2026-08-08/cpdlc-atn-b1-five-protocol-flaws-no-mitigation-available · 2026-08-05/check-point-cve-2026-18574-management-auth-bypass · 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally

outlook09 Aug 23:45Zmulti-sourceOpen finding ↗

2026-07-26 · view entry permalink →

NOTABLEexploitedNATOA2

2026-W30 looking ahead — items already in motion: a nginx pre-auth RCE PoC on a ~21-day release clock, Oracle Fusion Middleware abuse assessed 'very likely', a public AD CS DCSync PoC, a Mitel CVE pending, and two EU compliance clocks tightening

A justified watch list of items already in motion at the close of 2026-W30 — each a concrete, sourced development, none a prediction.

Exploitation clocks running. The nginx / NGINX Plus pre-auth heap-overflow CVE-2026-42533 has a working pre-auth RCE that the credited discoverer demonstrated defeats ASLR in a single request, with the exploit proof-of-concept deliberately withheld for roughly 21 days from its mid-July disclosure (cyberstan.co.uk, 2026-07-19) — so anyone running internet-facing nginx should complete the F5 out-of-band patch before that window closes in early August. Oracle's July Critical Patch Update carries nine unauthenticated CVSS-10.0 flaws in Fusion Middleware, and NCSC-NL assesses that large-scale abuse in the short term is very likely (NCSC-NL, 2026-07-22) — internet-reachable Fusion Middleware is the exposure to close now. The Windows AD CS "Certighost" flaw CVE-2026-54121, patched by Microsoft in July (Microsoft MSRC, 2026-07-14), now has a full public PoC letting a low-privileged domain user forge a Domain Controller certificate and DCSync the krbtgt hash (CybersecurityNews, 2026-07-24) — treat any AD CS estate that has not applied the July cumulative update as weaponizable now. And Mitel's unauthenticated MiCollab AWV command-injection flaw (CVSS 9.8) still carries only an internal id, MTLVULN-1694, with no assigned CVE (Mitel PSIRT, 2026-07-22), so exposure tracking cannot yet rely on a CVE identifier.

Compliance clocks tightening. Two EU dates established and sourced in prior weeklies are now close enough to act on: the Dutch NIS2 transposition, the Cyberbeveiligingswet, enters into force on 15 August 2026 (about three weeks out), and the CRA Article 14 obligation — a 24-hour early warning to a CSIRT/ENISA on awareness of an actively-exploited vulnerability, a 72-hour notification and a 14-day final report — begins on 11 September 2026. Freshly anchoring that September window, ENISA's public consultation on the mandatory EU Managed Security Services certification scheme closes on 13 September 2026 (ENISA, 2026-07-24), two days after the CRA clock starts. For Swiss and European organisations with Dutch entities, EU-market product suppliers, or MSSP relationships touching the EU Cybersecurity Reserve, these are calendar items to fold into August-September planning now.

Builds on: 2026-07-20/cve-2026-42533-nginx-pcre-capture-clobber-preauth-rce · 2026-07-26/oracle-july-2026-cpu-fusion-middleware-cvss10-unauth · 2026-07-25/certighost-cve-2026-54121-ad-cs-dc-impersonation-poc · 2026-07-24/mitel-micollab-awv-unauth-command-injection · 2026-07-12/weekly-w28-netherlands-nis2-in-force · 2026-07-19/weekly-w29-eu-ci-resilience-regulatory-deadlines

outlook26 Jul 23:50Zmulti-sourceOpen finding ↗

Earlier coverage (4)

2026-07-12NOTABLENATOB2Looking ahead — 2026-W28Items already in motion, not predictions: the Dutch NIS2 Cyberbeveiligingswet enters into force 15 August 2026 (five weeks out) and the EU Cyber Resilience Act's 11 September vulnerability/incident-reporting obligation is ~60 days away; FINMA's post-quantum expectation-setting may harden into a binding circular; the Joomla extension file-upload wave's newest members (RSFiles!/Phoca) are patched but not yet exploited, and prior wave members reached CISA KEV within days; Unit 42 references an Expel write-up of The Gentlemen's suspected EDR-disable zero-day that has not yet published; and the STAC3725 initial-access broker continues weaponising CitrixBleed 2 against un-session-terminated NetScaler.2026-07-12NOTABLEupdateNATOA1Netherlands NIS2 transposition confirmed: the Senate passed the Cyberbeveiligingswet on 7 July, fixing entry into force at 15 August 2026The Dutch First Chamber passed the Cyberbeveiligingswet (the NIS2 transposition) and the companion Wet weerbaarheid kritieke entiteiten (CER transposition) on 7 July 2026; both enter into force 15 August 2026. This closes the 'slipped past 1 July' status prior weeklies tracked and fixes a hard date. The Cbw covers ~8,000 organisations across 18 sectors with a duty of care including supply-chain risk management, mandatory incident reporting to the CSIRT, entity-register registration, and board-level accountability. For Swiss-domiciled organisations with Dutch subsidiaries, NL critical suppliers, or cross-border NIS2-equivalent reporting relationships, 15 August 2026 is now the operative compliance clock.2026-07-05NOTABLEupdateNATOA2Netherlands NIS2 transposition slips past its 1 July target — Senate vote set for 7 July, entry into force now 15 August 2026The Dutch NIS2 transposition (Cyberbeveiligingswet) missed the 1 July 2026 entry-into-force target reported in prior coverage. The Eerste Kamer (Senate) tabled its response to the second committee report on 29 June — the last written step before debate — and its bill-tracking page now sets the floor vote for 7 July, with the government's revised entry-into-force target 15 August 2026. Substantive scope is unchanged (NCSC-NL supervisor, 24h/72h/1-month notification, fines to EUR 10M/2%, board liability, ~1,000→~8,000 in-scope entities).2026-06-29HIGHNetherlands NIS2 (Cyberbeveiligingswet) clears the lower house — entry into force targeted for 1 July 2026Policy: the Netherlands' NIS2 law cleared its lower house (entry into force targeted for 1 July); the EU CRA reporting obligation is ~75 days out (11 September) — enforceable Dutch notification clocks are imminent and CRA SRP onboarding should start. (NL Digital Government, ENISA SRP)