Registration is the first Cyberbeveiligingswet duty you really cannot avoid, and also the easiest. According to the NCSC, the registration itself takes about ten minutes, provided you collect the details beforehand. That collecting is the real work: the network details usually sit with IT or your hosting provider, the choice of sector with the board. This page walks through the steps and ends with a checklist you can forward to the colleagues who need to supply the information.

Who has to register?

The duty to register applies to every organisation that falls under the Cbw as an essential or important entity (Articles 43 and 44 Cbw), plus entities that provide domain name registration services. Not sure whether you are in scope? First run the NIS2 scope checker or the NIS2 self-assessment from the RDI (the Dutch Authority for Digital Infrastructure).

A few points that often raise questions:

  • You register per country. According to the NCSC, you cannot register for all EU member states in one go. Most organisations fall under the law of every country where they are established and provide services. Exceptions: public administration entities register in their own country, providers of public electronic communications in the country where they provide their services, and "internet services" (DNS, TLD registries, cloud, data centres, CDNs, MSPs, MSSPs, online marketplaces, search engines, social networks) in the country of their main establishment in the EU.
  • Your sector is your own sector. If you provide cloud services to hospitals, your sector is "Digital infrastructure", not "Healthcare". The NCSC uses exactly this example.
  • Critical entities designated under the Dutch Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten) also fall under the Cbw and, according to the NCSC, can register straight away.

Deadlines

WhatDeadlineSource
Registration in the national registerMandatory from entry into force on 15 August 2026. Dutch government: "This is mandatory as of 15 August."Rijksoverheid 7 July 2026; NCSC
Reporting changesWithout delay, and in any case within two weeks of the changeArt. 44(2) Cbw
Additional details for the ENISA registry (only DNS, TLD, cloud, data centre, CDN, MSP, MSSP, online marketplace, search engine, social network and domain name registration)Within one month of those provisions entering into force or of you qualifying as such; changes within three monthsArt. 47(4) and (5) Cbw

Only just found out that you fall under the law? Register immediately. Once registered, you can also sign up for your CSIRT's services, which you will need straight away if an incident happens.

Before you start: three checks

  1. Can you log in? You need eHerkenning (the Dutch business login) at assurance level EH2+ and an authorisation to register on behalf of your organisation. The credential must be linked to the Chamber of Commerce (KvK) number of the organisation that is registering. The eHerkenning administrator in your organisation sets up the authorisation. If you don't have eHerkenning yet, apply for it via eherkenning.nl; according to the NCSC this can take a few days. Connected central-government bodies log in with SSOnRijk, which has to be enabled once in advance.
  2. Do you have the details? You enter organisation, contact and network details, such as public IP addresses or IP ranges, domain names and AS numbers. These often come from different people: the CISO, the network administrator, the hosting provider.
  3. Are you the right person? The NCSC recommends someone with decision-making authority, preferably with cybersecurity knowledge: a CISO or security expert, or in a small organisation the director, owner or compliance lead.

Step by step on MijnNCSC

After logging in at mijn.ncsc.nl you go through five steps. The description below follows the NCSC registration page (as of 1 October 2026). The portal is in Dutch. The login screen shows the logo of the Justitiële Informatiedienst, which runs the login environment for the NCSC.

Step 1. Organisation details

These are retrieved automatically: for public bodies from the Register of Government Organisations (Register van Overheidsorganisaties), for everyone else from the KvK trade register. Check them. If something is wrong, correct it at the source (the KvK or the register), not in the form.

Step 2. Additional organisation details

Required:

  • Main sectors and subsectors. Pre-filled from your SBI activity codes at the KvK. Check and complete them; SBI codes don't always tell the whole story.
  • Services. The type of service you provide, chosen from the list for your sector.
  • EU member states. The member states in which you provide services and the member state of your main establishment.
  • Entity type. Essential or important.
  • Designation. Whether you have been designated by ministerial decision. Most organisations fall under the law automatically and are not designated.
  • Information-sharing arrangement. Which information-sharing partnerships (such as ISACs) you take part in. Not relevant for everyone.

Optional, as an indication of whether you are essential or important (not for public bodies and designated organisations): number of FTEs (<50, 50 to 249, 250+), annual turnover in the previous calendar year (< €10 million, €10 to 50 million, > €50 million) and balance sheet total for the previous calendar year (< €10 million, €10 to 43 million, > €43 million).

Step 3. Contact details

The organisation's primary contact: first and last name, phone number, email address and job title. The NCSC recommends someone with hands-on cybersecurity knowledge and someone with senior decision-making authority, reachable during incidents. If you, as the person submitting, also want to be contacted, add yourself as a contact too.

Tip: alongside personal addresses, use a shared mailbox that reaches several people, and keep the number reachable outside office hours. A CSIRT that cannot reach you during an active threat gets little value from your registration.

Step 4. Network details

All network details required by law: public IP addresses or IP ranges, domain names and AS numbers (ASN). The NCSC calls this "not easy, but essential". The Act itself asks for IP ranges in Article 44; the Cyberbeveiligingsbesluit (the implementing decree, Art. 27) adds domain names, the type of entity and your KvK number (public bodies: their identifier in the Register of Government Organisations), plus whether you are registering as an essential or important entity. The CSIRT uses these details to warn you when your systems show up in a vulnerability scan or a leak.

Where to find them:

  • Domain names: at your registrar or in your DNS management; don't forget campaign and legacy domains.
  • Public IP addresses: from your internet provider, in your firewall configuration and at your cloud or hosting provider (fixed public addresses).
  • ASN: only if you have your own IP space and your own AS number; most small and mid-sized organisations don't.

Step 5. Summary and submit

You check everything and declare that the form has been completed truthfully and that you will report changes within 14 days. That last point is a legal duty. Once you submit, you are registered.

Checklist: collect this first

  • eHerkenning EH2+ on the KvK number of the right legal entity, with an authorisation for the person registering
  • Correct details in the trade register (name, address, SBI codes) or in the Register of Government Organisations
  • Your main sector and subsector(s) and the type of service, backed up by a scope check
  • The choice between essential and important, with the figures behind it (FTEs, annual turnover, balance sheet total, including partner and linked enterprises)
  • The EU member states where you provide services and the member state of your main establishment
  • Any ministerial designation decision
  • Participation in ISACs or other information-sharing arrangements
  • Contact person or persons: name, job title, phone, email, reachable 24/7
  • All domain names
  • All fixed public IP addresses and IP ranges
  • AS number(s), if you have them
  • An owner who reports changes within two weeks, and a recurring reminder to review the details periodically

After registering

Registration is the beginning, not the end. Record when you registered and with which details, so you can demonstrate it to your supervisory authority. Set up a recurring check on the registration details: a new domain, a new establishment in Germany or a different contact person must be in the register within two weeks. And make sure the same eHerkenning authorisation works for reporting incidents, because that goes through the same portal.

How Dazr helps

In the compliance profile in Dazr Compliance you record your Cbw/NIS2 classification, with the registration date, the competent authority and the CSIRT. You also keep the details you submitted to the register there, so a change in your asset register (a new domain, a new IP range) becomes a prompt to update your registration. The registration itself happens on mijn.ncsc.nl.

Sources

As of 1 October 2026. This page is general information, not legal advice. Laws, regulations and sector rules can change; always check the current source.