- Since 15 August 2026, an essential or important entity reports every significant incident via the central reporting point on MijnNCSC: early warning within 24 hours, incident notification within 72 hours, final report no later than one month after that notification.
- That one report reaches your sector CSIRT (usually the NCSC, Z-CERT in healthcare, CERT-WM for water authorities) and your supervisory authority.
- Has personal data been affected? Then you also notify a personal data breach to the Autoriteit Persoonsgegevens within 72 hours, unless the breach is unlikely to result in a risk. The Cbw report does not replace the GDPR notification.
A ransomware attack on a Friday evening is exactly when nobody wants to work out which desk belongs to which law. Yet in practice that is often what happens. After the national cyber exercise ISIDOOR IV, the NCSC concluded that not all organisations that should have reported an incident under the old Wbni actually did so, and that organisations did not always know to which body or how (see the 2024 article on Securitymanagement.nl in the sources). With the Cyberbeveiligingswet (Cbw), the Dutch law implementing NIS2, the reporting desk has become simpler, but more organisations are covered and the deadlines are stricter. This page puts both reporting duties side by side and gives you a decision aid.
The reporting duty under the Cyberbeveiligingswet
The Cbw (Staatsblad 2026, 187) entered into force on 15 August 2026, together with the Cyberbeveiligingsbesluit (the implementing decree), and replaces the Wbni. The reporting duty is set out in Articles 25 to 30 and applies to every essential and important entity.
What is a significant incident?
Under Article 25 Cbw, an incident is significant if it has caused or is capable of causing severe operational disruption of the services or financial losses for the entity, or if it has affected or is capable of affecting other parties by causing considerable material or non-material damage. Note the word capable: you don't have to wait until the damage is established.
The concrete thresholds differ per sector and are set out in ministerial regulations. Two examples:
- Healthcare (Cyberbeveiligingsregeling voor de zorg, Art. 2.2): among other things, when a critical business process is fully or partly down for more than four hours, when the confidentiality of special categories of personal data or citizen service numbers (BSN) has been compromised by a suspected malicious act, or in case of permanent injury, hospital admission or death.
- Local and regional government (Cyberbeveiligingsregeling sector overheid, Art. 6): among other things, an outage of services of at least four hours, or financial consequences that cannot be absorbed within the budget.
For DNS service providers, cloud and data centre providers, MSPs, MSSPs, online marketplaces and trust services, the criteria from Implementing Regulation (EU) 2024/2690 apply. Planned maintenance does not count in either of the regulations mentioned.
The three steps and their deadlines
| Step | Deadline | What it must contain |
|---|---|---|
| Early warning | Without undue delay, no later than 24 hours after becoming aware | Suspected malicious or unlawful act? Possible cross-border impact? Contact details of the responsible officer (Art. 26 Cbw). The Cbb (Art. 24) adds: the suspected start time and, where possible, the nature and visible effects, the expected recovery time and the measures taken or planned. |
| Incident notification | Without undue delay, no later than 72 hours after becoming aware | An update of the early warning, an initial assessment of severity and impact and, if available, indicators of compromise (Art. 27 Cbw). |
| Intermediate report | On request | Relevant status updates when your CSIRT or supervisory authority asks for them (Art. 28 Cbw). |
| Final report | No later than one month after the notification | A detailed description, severity and impact, type of threat or root cause, mitigation measures applied and ongoing, cross-border impact. Is the incident still ongoing? Then first a progress report, and the final report within one month of handling the incident (Art. 29 Cbw). |
The NCSC explicitly mentions two exceptions. If you provide a trust service and the incident affects that service, the notification is due within 24 hours (Art. 27(2) Cbw). And if you also fall under DORA or the network code on cybersecurity for electricity, you may have to report via the route of that regime, with shorter deadlines; the NCSC infosheet mentions an early warning within four hours. If in doubt, contact your supervisory authority.
You must also inform the recipients of your services without undue delay about significant incidents that are likely to adversely affect the provision of those services (Art. 30 Cbw). That is a separate duty next to the report.
Where do you report? One desk, different CSIRTs
You report via the central reporting point at mijn.ncsc.nl. According to the NCSC, the report automatically goes to your sector CSIRT and to the supervisory authority; you don't have to inform them separately. Who that CSIRT and supervisory authority are is set out in the NCSC referral tree (version 18 August 2026):
| Sector | CSIRT (support) | Supervisory authority |
|---|---|---|
| Energy, digital infrastructure, ICT service management, digital providers, postal services, space, manufacturing (non-medical) | NCSC | RDI |
| Transport, drinking water, waste water, waste management, chemicals | NCSC | ILT (packaged drinking water: NVWA) |
| Healthcare, manufacture of medical devices | Z-CERT | IGJ |
| Ministries, independent administrative bodies (zbo's), provinces | NCSC | RDI |
| Municipalities and joint arrangements | NCSC (until at least the end of 2026) | RDI |
| Water authorities | CERT-WM | ILT |
| Banking / financial market infrastructure | NCSC | DNB / AFM (DORA) |
| Food | NCSC | NVWA |
Source: NCSC referral tree (doorverwijsboom). As of 1 October 2026 Z-CERT has not yet been formally designated; according to the explanatory notes to the healthcare regulation, reports in the NCSC portal are also picked up by Z-CERT. For municipalities, the decision on the CSIRT role from 2027 is still pending.
The personal data breach notification under the GDPR
The GDPR notification duty is separate from the Cbw and applies to every organisation that processes personal data, even if you don't fall under the Cbw. The essentials (Art. 33 and 34 GDPR):
- Notify the Autoriteit Persoonsgegevens without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of people. If you notify later, give the reasons for the delay.
- Phased notification is allowed: if you don't have all the information yet, you add it later (Art. 33(4)).
- Inform data subjects without undue delay if the breach is likely to result in a high risk (Art. 34).
- Always document: breaches you don't notify must also be recorded, with the facts, effects and remedial action taken (Art. 33(5)).
- Processor? Then you don't notify the AP yourself, but inform your controller without undue delay (Art. 33(2)). Check your data processing agreement for the deadline you agreed.
When do you have to report to both?
In many cyber incidents. Think of ransomware at a healthcare provider with more than 50 FTEs: the patient record system is unavailable for hours (a significant incident under the healthcare regulation) and special categories of personal data are at stake (a personal data breach). You then run two tracks at once:
- Cbw track: an early warning via MijnNCSC within 24 hours, the notification within 72 hours, the final report within a month. Goes to the CSIRT and the supervisory authority.
- GDPR track: a breach notification via the AP's reporting desk within 72 hours, and informing the data subjects where needed.
Both clocks run from awareness, but they are not identical: the Cbw final report has its own deadline, and the GDPR track has no early warning. So use one incident file with one timeline, and reuse the facts in both notifications. That way you avoid telling the AP something different from what you told your CSIRT.
If the incident looks like a criminal offence, your CSIRT explains how to file a report with the investigative services (NCSC). That is a separate track too.
What to have ready in advance
24 hours is short. If you arrange the following before an incident, you will meet the deadline:
- A MijnNCSC login with eHerkenning (EH2+) and an authorisation, for more than one person. If only the director is authorised, you are stuck when they are on holiday.
- Your registration in the register of entities is complete, so the portal knows your sector and CSIRT. See registering on MijnNCSC.
- A reporting matrix: which thresholds apply in your sector regulation, who decides that something is significant, and who reports.
- Contact details of the officer who makes the report, and a 24/7 phone number.
- The AP's notification form reviewed in advance, including the questions on numbers of data subjects and types of data.
- Agreements with suppliers on how quickly they inform you of an incident in their systems; without that information you cannot properly complete the 72-hour notification.
- A list of service recipients you must inform under Article 30 Cbw, with a contact channel.
- Logging and time synchronisation in order, so you can substantiate the suspected start time.
Common mistakes
- Waiting for certainty. Both laws count from awareness, not from the moment the forensic analysis is finished. Report what you know and add to it later.
- Assuming the NCSC report also reaches the AP. The central reporting point forwards to the CSIRT and supervisory authority. The Autoriteit Persoonsgegevens is a separate notification.
- Forgetting availability. A personal data breach isn't only data leaking out; personal data that is unavailable or encrypted by an attacker can be a breach too.
- Notifying the AP yourself as a processor instead of informing your customer, or only telling your customer days later.
- Forgetting service recipients (Art. 30 Cbw). Your customers need to be able to take measures.
- Not sending a final report because the incident is "resolved". The final report is mandatory; for an ongoing incident, send a progress report first.
- Not documenting what you decided not to report. Under the GDPR you must also record breaches you did not notify, and under the Cbw the supervisory authority can ask why you did not consider an incident significant.
How Dazr helps
For every incident, the incident register in Dazr Compliance starts the clocks for the GDPR (72 hours) and the Cbw/NIS2 (24 hours, 72 hours, one month) from the moment of awareness. The NIS2 significant-incident check (based on Implementing Regulation 2024/2690) helps you record your assessment, and you keep the AP and NCSC case numbers with the incident. Dazr does not file the report for you: you do that yourself via MijnNCSC and the AP's reporting desk.
Sources
- Cyberbeveiligingswet, Staatsblad 2026, 187
- Cyberbeveiligingsbesluit, Staatsblad 2026, 189
- NCSC, Meldplicht Cyberbeveiligingswet (in Dutch)
- NCSC, Infosheet Meldplicht (pdf, September 2025, in Dutch)
- NCSC, Toezicht op de Cyberbeveiligingswet: hoe zit dat? (in Dutch)
- NCSC, Doorverwijsboom Cyberbeveiligingswet 2026 (pdf, 18 August 2026, in Dutch)
- Cyberbeveiligingsregeling voor de zorg, Staatscourant 2026, 28763
- Cyberbeveiligingsregeling sector overheid, Staatscourant 2026, 27679
- Implementing Regulation (EU) 2024/2690, EUR-Lex
- Regulation (EU) 2016/679 (GDPR), EUR-Lex
- Autoriteit Persoonsgegevens (data breach reporting desk)
- Rijksoverheid, news item 7 July 2026: Cbw and Wwke in force from 15 August 2026
- Securitymanagement.nl, Organisaties weten vaak niet waar ze een cyberincident moeten melden (28 August 2024, in Dutch)
As of 1 October 2026. This page is general information, not legal advice. Laws, regulations and sector rules can change; always check the current source.