Skip to main content

On the Road to August 15: 8 Steps to Get Started with the Cybersecurity Act

Medewerker van Trust en Safety met een wit overhemd aan met een donkerblauw jasje eroverheen
Alan Lucas

Knowledge blog

On August 15, 2026, the Cybersecurity Act (Cbw) takes effect in the Netherlands. Its goal: to make not only your own organization, but the entire supply chain around it, more resilient against real threats. As we wrote in our earlier news article, this means concrete obligations for thousands of Dutch organizations: registration, duty of care, reporting obligations, and board-level accountability. And through supplier assessments, the law also affects tens of thousands of suppliers that don’t fall under it directly.

Two weeks may not sound like much, but the first steps are manageable. Note: this is an ongoing process, not a one-time project. The eight steps below will help you get started now.

1. Check whether your organization falls under the Cbw

The law applies to organizations that provide essential or important services in 18 sectors, including energy, drinking water, digital infrastructure, healthcare, government, and transport. Organizations are responsible for determining themselves whether they fall under the law, and whether that’s as an essential or an important entity. That distinction determines the level of oversight you get: essential entities are proactively supervised, even without an incident, while important entities are mainly checked after the fact. Use the official self-assessment tool from the Dutch government for this.

Note: even if an organization doesn’t fall under the law itself, it can still be confronted with its requirements through Cbw-obligated clients. Cybersecurity is becoming a condition for doing business.

 

2. Inform and involve the board

Under the Cbw, the board is ultimately responsible for managing cyber risks. Board members must be able to assess and monitor risks and measures, and are required to follow specific training for this. So put the topic on the board agenda now, with a clear overview of the key risks, the measures taken, and what still needs to happen.

Worldstream can provide clients with the technical information that makes the boardroom conversation concrete: insight into how the infrastructure is set up, which security and continuity measures have been taken at the infrastructure level, and how these are documented in our certifications and reports.

3. Prepare for registration in the entity register

Registration in the entity register via the NCSC is mandatory as of August 15. The NCSC advises organizations to prepare for registration now; a checklist is available for this. Registration is more than an administrative duty: it gives access to the services of the Computer Security Incident Response Team (CSIRT) for your sector. For most organizations, that’s the NCSC. Think of tailored threat intelligence, alerts on current vulnerabilities, and support during security incidents. Only after registration does the CSIRT know who you are and which service you provide, and can it help in a targeted way. Once registered, speed matters most during an incident, and that’s where we, as an infrastructure partner, can help (see step 6).

4. Map out risks and attack surface

Know which systems are reachable online and which vulnerabilities could be exploited. Risk analysis is one part of the duty of care, alongside supply chain security, continuity, and access management, among others. No security policy yet? Start with the basics: the NCSC’s 5 basic principles. Already working with an information security management system (ISMS)? Test it against the Cbw (NIS2) Control Framework from NOREA and the Dutch Audit Office (Auditdienst Rijk).

If an infrastructure runs with us, we know exactly how it’s built. We help organizations gain insight into their online footprint on our infrastructure and provide protection at the front end, such as DDoS mitigation through our own network. This allows them to determine which findings pose a risk.

5. Ensure business continuity: backup, recovery, and redundancy

Ensure secure storage, recovery capacity, and avoid single points of failure. And just as important: test recovery procedures in practice. Without a recovery test, you don’t know whether a backup actually works.

Continuity is in our DNA. Our own data centers in the Netherlands are designed with redundancy, our global network is built redundantly, and we offer solutions for secure storage and recovery at separate locations. We’re also happy to think along about a recovery test that demonstrates an organization is meeting its duty of care, including the question that really matters: how fast are you back online?

6. Set up an incident process

Reporting deadlines are strict: an early warning within 24 hours, a follow-up report within 72 hours, and a final report within a month. So know who reports, within which deadline, and make sure suppliers can quickly deliver the right technical information.

During an incident, every minute counts. Our support department is available 24/7, and we can quickly provide the technical information an organization needs for a report, think of network data, logging, and infrastructure status. Organizations would do well to already establish who the point of contact is at their suppliers and which information is needed in which scenario. That way, they won’t have to improvise during the first 24 hours.

7. Assess your suppliers

Supply chain security is explicitly part of the duty of care: organizations are also responsible for the risks in their supply chain. Ask IT suppliers for certifications, SLAs, incident processes, and clarity on data location and access. Document the assessment, since organizations must be able to show this too.

We make that assessment easy. We are ISO 27001, ISO 9001, and PCI DSS certified, and are independently audited every year. Data is stored in our own data centers in the Netherlands, with clear agreements on access and SLAs. We provide the documentation organizations need for their supplier file, so they can show the regulator that their supply chain is in order.

8. Document everything

Regulators check for compliance and can take enforcement action. Documentation is your strongest evidence, although auditors also accept interviews and inspections. So record risk analyses, measures, tests, supplier assessments, and board decisions.

Organizations can rely on us for everything related to the infrastructure: certificates, SLAs, descriptions of security measures, and agreements on data location and incident support.

Finally: start today

The Cbw calls for organization-wide measures, from governance and training to technology. No one can arrange compliance for an organization, but organizations don’t have to do it alone. They can already put the technical foundation of their resilience in order: infrastructure, continuity, and insight into the supply chain.

Curious how Worldstream’s infrastructure contributes to your organization’s Cbw obligations? Get in touch with our team for a no-obligation conversation.

More information about the legislation: https://www.ncsc.nl/nieuws/cbw-en-wwke-vanaf-15-augustus-2026-van-kracht