Verify any claim · lenz.io
Claim analyzed
Legal“Under the Dutch Cyberbeveiligingswet (Cbw), municipalities can be fined up to €10 million for failing to meet duty-of-care (zorgplicht) requirements.”
Submitted by Daring Wolf 0065
The conclusion
Open in workbench →The statement captures the substance of the adopted law, but it overstates its current legal effect. Official sources and municipal guidance indicate that municipalities are expected to fall under the Cbw regime and that duty-of-care breaches can trigger fines reaching €10 million. But the Act is stated to take effect on 15 August 2026, so as of 12 July 2026 those fines are not yet enforceable under the Cbw.
Caveats
- The Cyberbeveiligingswet is not yet in force as of 12 July 2026; official government communication says it starts on 15 August 2026.
- The sanction is simplified: for essential entities the legal maximum can be €10 million or 2% of worldwide annual turnover, whichever is higher.
- The municipal link is well supported by official and VNG guidance, but the provided excerpts do not quote the specific primary classification article naming municipalities directly.
Get notified if new evidence updates this analysis
Create a free account to track this claim.
Sources
Sources used in the analysis
Article 77(1) provides: "The competent authority may, in the event of a violation of the provisions laid down by or pursuant to this Act, impose an administrative fine on an essential entity." Article 77(3) then specifies: "The fine shall amount to at most: (a) in the event of a violation of the provisions laid down by or pursuant to Articles 21 and 25 to 30: €10,000,000 or 2% of the total worldwide annual turnover in the preceding financial year of the undertaking to which the essential entity belongs, if the latter amount is higher; (b) in the event of any other violation: €1,000,000." The explanatory text notes: "Only in respect of the violation of the duty of care, the notification obligation and the obligation to inform recipients of services does the NIS2 Directive contain rules on the maximum amount of an administrative fine for violation of those obligations."
The NIS2 Directive sets maximum administrative fines for infringements of cybersecurity obligations. For essential entities and relevant entities, the maximum amount of administrative fines is at least 10 000 000 EUR or at least 2 % of the total worldwide annual turnover of the undertaking in the preceding financial year, whichever is higher. For important entities, the maximum amount of administrative fines is at least 7 000 000 EUR or at least 1.4 % of the total worldwide annual turnover of the undertaking in the preceding financial year, whichever is higher.
The Cyberbeveiligingswet applies to organisations that provide essential or important services. The Act covers organisations from 18 sectors such as energy, transport and banking. Organisations covered by the Cyberbeveiligingswet will face, among other things: duty of care (zorgplicht) – organisations must take measures to manage risks to the security of network and information systems, and to prevent incidents or limit their consequences; reporting duty (meldplicht) – organisations must report significant incidents within the statutory deadlines to their CSIRT and competent authority via the reporting portal; and supervision and enforcement – supervisory authorities check whether organisations comply with the obligations under the Cyberbeveiligingswet.
De Cyberbeveiligingswet geldt voor essentiële en belangrijke organisaties in verschillende sectoren, zoals energie, ruimtevaart, onderzoek, digitale infrastructuur en overheid. Ook grotere bedrijven in andere sectoren kunnen onder de wet vallen. Dit gaat bijvoorbeeld om bedrijven met meer dan 50 medewerkers, of met een jaaromzet en/of balanstotaal van meer dan 10 miljoen euro. Ook toeleveranciers of dochterbedrijven van zulke organisaties kunnen onder de wet vallen. Dit hangt af van hun rol in de keten.
The Cyberbeveiligingswet (Cbw) introduces obligations including a duty of care (zorgplicht), registration duty and notification duty for organizations falling under the law, including public authorities such as municipalities. Sectoral supervisors under the Cbw are given the power to impose administrative fines for non‑compliance with these obligations. Government guidance clarifies that the NIS2/Cbw framework itself does not create new personal liability rules for public‑sector directors beyond existing Dutch law, but it does allow for enforcement measures, including fines, against the public entity when obligations such as the zorgplicht are breached.
The digital safety of our society and economy is increasingly under pressure. That is why the Cyberbeveiligingswet is being introduced in the Netherlands. Around 8,000 organisations will face new obligations, such as a registration duty, a duty of care (zorgplicht) and an incident reporting duty (meldplicht). In addition, there is a duty of care that obliges organisations to take measures to increase cyber resilience.
The zorgplicht is one of the most important obligations in the Cyberbeveiligingswet (Cbw). Organizations that fall under the law must take appropriate and proportionate technical, operational and organizational measures to manage risks to the security of their network and information systems. The Cbw places responsibilities with the board of organizations: the board must supervise the implementation of the zorgplicht and approve the measures, and a training obligation for board members is included in the law.
Frequently asked question: "Can supervisory authorities impose fines?" Answer: "Yes, supervisory authorities in the sectors covered by the Cyberbeveiligingswet can impose a financial penalty with a maximum amount of €10,000,000 or 2% of the total worldwide annual turnover in the previous financial year of the undertaking, whichever amount is higher. For other violations under the Act, the Dutch Health and Youth Care Inspectorate (IGJ) can impose a maximum fine of €1 million." Another question explains: "Organisations that fall under the Cyberbeveiligingswet have a duty of care. This means that they must take measures to protect their network and information systems against significant incidents."
Deze Nederlandse wet is vanaf 15 augustus 2026 van kracht. Voldoet je organisatie aan deze voorwaarden, dan val je onder de Cyberbeveiligingswet. Met de nieuwe wet komt er een registratieplicht voor organisaties en een meldplicht voor incidenten. Er komt ook een zorgplicht die organisaties verplicht een risicoanalyse uit te voeren. Op basis van de analyse moeten passende maatregelen worden genomen om systemen te beveiligen.
The Cyberbeveiligingswet requires ten duty-of-care measures that organisations must at least comply with. These include: securing network and information systems against vulnerabilities; establishing procedures for patch management and security settings; ensuring there is a contact point where security researchers can report vulnerabilities; setting policy on how employees are granted access to systems and information; and ensuring insight into all assets in the organisation. It also requires policy to periodically test the effectiveness of measures, for example annually.
De Cyberbeveiligingswet (Cbw) is de Nederlandse uitwerking van de Europese NIS2-richtlijn, die de cyberveiligheid in de Europese Unie naar een hoger niveau wil brengen. In het webinar wordt ingegaan op de zorgplicht, bestuurlijke verantwoordelijkheid en opleidingsplicht. Ook wordt toegelicht welke organisaties als essentieel of belangrijk worden aangemerkt en hoe de handhaving plaatsvindt.
In the event of breaches of the duty of care and the reporting duty, the supervisory authority can impose an administrative fine on the municipality of up to €10 million. In addition, personal fines of up to €25,000 can be imposed on administrators who do not follow the compulsory training.
In the event of breaches of the duty of care and the reporting duty, the supervisory authority can impose an administrative fine on the municipality of up to €10 million. Personal fines of up to €25,000 can be imposed on administrators who do not follow the compulsory training.
The Cyberbeveiligingswet implements the NIS2 Directive in Dutch law. The obligations include, among other things, a duty of care to take measures to manage cybersecurity risks and a reporting duty for significant incidents, as well as information-provision obligations. Section 5.7.12 (Administrative fine) of the explanatory memorandum notes that NIS2 Article 34(4) prescribes that the maximum amount of an administrative fine for violation of the duty of care, reporting obligation and obligation to inform recipients of services by an essential entity is €10,000,000 or 2% of the total worldwide annual turnover in the previous financial year, whichever leads to a higher amount. For other obligations the Dutch legislator has set lower maximums.
In breaches of the duty of care and the duty to report, administrative fines can amount to €10 million for the municipal organisation and personal fines of up to €25,000 for administrators who do not follow the compulsory training. The municipal council must supervise compliance with the law, while the Rijksinspectie Digitale Infrastructuur (RDI) supervises compliance by the entire government.
The advisory opinion from the Council of State explains that the Cyberbeveiligingswet mandates that companies and public authorities take measures to prevent cyber risks (duty of care) and to report incidents that threaten cybersecurity (reporting duty). For essential and important entities there is first of all a duty of care: this obligation is aimed at ensuring entities take measures to manage risks and prevent incidents, or limit their consequences. The bill lists measures that are in any case mandatory. Further specification of the duty of care will be done by the entities themselves, possibly supported by sector-specific rules or by general administrative measures.
Municipalities that do not fulfil their duty of care under the Cyberbeveiligingswet can face fines of up to 10 million euros. ‘In the event of breaches of the duty of care and reporting duty, the supervisory authority can impose an administrative fine on the municipality of a maximum of 10 million euros.’ The duty of care includes, among other things, that an analysis of cyber risks is made and that mayor and aldermen follow compulsory information security training, under penalty of a personal fine of up to 25,000 euros.
This alert on the Dutch Cybersecurity Act (Cyberbeveiligingswet) explains that the central obligation under the CSA is to take "appropriate and proportionate technical, operational and organisational measures" to manage cybersecurity risks (the zorgplicht or cybersecurity risk management obligation). In the event of a significant incident, entities must issue an early warning within 24 hours, notify within 72 hours and file a final report within one month, to both the CSIRT and competent authority. It notes: "Entities, both essential and important, may also face fines for infringements of the cybersecurity and incident reporting obligations. These fines can reach up to EUR 10 million or 2% of the total worldwide annual turnover (whichever is higher) for essential entities, and EUR 7 million or 1.4% of the total worldwide annual turnover (whichever is higher) for important entities."
The Cbw applies to ‘essential’ and ‘important’ entities. Ministries, provinces, municipalities and water boards are by law designated as ‘essential’ entities. ‘Essential’ and ‘important’ entities receive a clear duty of care. They must take technical, organisational and operational measures to manage cyber risks, prevent incidents and limit their consequences. A competent authority can, among other things, impose administrative enforcement and fines. Administrative fines can also be imposed on directors if they do not meet their obligations in terms of knowledge and skills.
The duty of care of the Cyberbeveiligingswet applies to organisations active in one of the 18 designated sectors and that meet certain size thresholds. This includes government bodies; all 340+ Dutch municipalities are obliged to comply. Organisations that do not meet the duty of care risk fines that can amount to 10 million euros or 2% of global annual turnover, whichever is higher. Supervisory authorities can also impose other corrective measures and, in extreme cases, temporarily prohibit the exercise of managerial functions.
On the Digitale Overheid page about the Cyberbeveiligingswet (NIS2 Directive) it is explained that the Cyberbeveiligingsbesluit (Cbb) further elaborates parts of the Cyberbeveiligingswet, such as the duty of care, registration duty and training duty for directors. It states that the Cbb specifies the content of the duty of care and the threshold criteria for the reporting duty. This indicates that details on how the zorgplicht must be fulfilled, and when incidents must be reported, are set out in secondary legislation rather than in the Act alone.
For companies subject to the Cyberbeveiligingswet as important entities, the maximum fine is €7 million or 1.4% of worldwide annual turnover. Other examples include fines up to €5 million for late incident reporting and up to €3 million for failure to cooperate with investigations. These amounts reflect how the Dutch implementation of NIS2 differentiates between essential entities (with higher maxima) and important entities (with lower maxima) when setting administrative fines under the Cbw.
Under NIS2 (and later the Cyberbeveiligingswet), administrative fines are possible for breaches of the NIS2 duty of care (Article 21) and reporting duty (Article 23). The directive sets maximum levels per type of entity. For essential entities: a maximum of €10,000,000 or 2% of worldwide annual turnover (whichever is higher). For important entities: a maximum of €7,000,000 or 1.4% of worldwide annual turnover (whichever is higher).
Wanneer je als 'essentiële entiteit' de Cbw niet naleeft, riskeer je een boete van maximaal 10 miljoen euro of 2% van de jaaromzet. Organisaties zijn verplicht om maatregelen te nemen die hun netwerk- en informatiesystemen beschermen, beginnend met een risicobeoordeling. Bij overheidsorganisaties is de ambtelijke leiding (zoals de gemeentesecretaris of het managementteam) verplicht een cyberbeveiligingstraining te volgen; na inwerkingtreding van de wet is hier twee jaar de tijd voor.
Since 17 October 2024, the European NIS2 Directive has been in force. It is expected that in the second quarter of 2026 NIS2 will be translated into national legislation in the Netherlands: the new Cyberbeveiligingswet (CBW). The directive now applies to more sectors and organisations, meaning that municipalities also fall under these rules. This means that municipalities receive a duty of care to take appropriate technical and organisational measures to secure their network and information systems. Significant cyber incidents must be reported to the Rijksdienst Digitale Infrastructuur (RDI) and their CSIRT.
According to the VNG, the draft texts for the Cyberbeveiligingswet (Cbw) and the Wet weerbaarheid kritieke entiteiten (Wwke) do not yet sufficiently reflect differences between municipalities. Municipalities want to be given the opportunity to comply with the new legislation without immediately running the risk of a fine. The state should compensate municipalities for the implementation costs of the Cbw, and not per inhabitant, because small municipalities have the same costs and efforts as larger ones to comply with the law.
The NIS2 Directive lays down common measures for a high level of cybersecurity across the Union. It requires essential and important entities, including public administration entities in member states, to implement appropriate and proportionate technical, operational and organisational cybersecurity measures (duty of care). Article 34 provides that for essential entities, member states must ensure that administrative fines of at least up to 10,000,000 euros or 2% of total worldwide annual turnover can be imposed, whichever is higher.
What do you think of the claim?
Your challenge will appear immediately.
Challenge submitted!
For developers
This same pipeline is available via API.
Verify your AI's output programmatically.
/extract pulls claims from text ·
/verify returns sourced verdicts ·
/ask answers follow-up questions.
Continue your research
Verify a related claim next.
Debate
Two AI advocates debated this claim using the research gathered.
Argument for
Under the Dutch Cyberbeveiligingswet (Cbw), municipalities are legally designated as 'essential' entities (Source 19, Nysingh), making them subject to strict enforcement measures including the duty of care (zorgplicht) (Source 5, Digitale Overheid). Consequently, authoritative municipal and legal sources explicitly confirm that supervisory authorities can impose administrative fines of up to €10 million on municipalities that fail to meet these duty-of-care requirements (Source 12, Gemeenteraad Hillegom; Source 15, VNG; Source 17, Gemeente.nu).
The Proponent's case hinges on Source 19 (Nysingh) to supply the missing statutory link—i.e., that municipalities are “by law” designated as essential entities—yet the only primary legal text in the brief (Source 1, Overheid.nl) is cited for fine ceilings without ever being shown to classify municipalities as the finable “essential entity” for zorgplicht breaches, making the conclusion a classic unsupported leap from commentary to statute. The Proponent then compounds this by treating secondary guidance and press-style summaries (Sources 12, 15, 17) as if they were the Cyberbeveiligingswet itself, even though Source 1 and the explanatory materials (Source 14, Internetconsultatie.nl) frame €10 million as a maximum tied to NIS2-style categories and specific articles rather than an explicit, on-the-face statement that “municipalities can be fined up to €10 million for failing the zorgplicht.”
Argument against
The motion is false because the €10 million ceiling in the Cyberbeveiligingswet is explicitly tied to fining an “essential entity” (Article 77(1)–(3) in Source 1, Overheid.nl), and none of the primary legal sources in the brief actually states that municipalities, as municipalities, fall under that finable category for the zorgplicht. Claims that municipalities can be fined up to €10 million come from secondary guidance and commentary (e.g., Source 12/13/15) rather than the statute's own text, so the motion overstates what the Cbw itself demonstrably provides on its face.
The Opponent's argument relies on a false dichotomy between the statutory text and secondary guidance, ignoring that Source 19 (Nysingh) confirms municipalities are legally designated as "essential" entities by law under the Cbw framework. Consequently, the statutory fine of up to €10 million for essential entities outlined in Article 77 of the law (Source 1, Overheid.nl) directly applies to municipalities, as explicitly verified by the Association of Dutch Municipalities (Source 15, VNG) and municipal communications (Source 12, Gemeenteraad Hillegom).
Panel Review
3 specialized AI experts evaluated the evidence and arguments.
Reviewer 1 — The Logic Examiner
The logical chain from evidence to claim is clear and well-supported: Source 1 (Overheid.nl, the official gazette) confirms Article 77 of the Cbw sets a €10 million maximum fine for violations of the duty-of-care provisions (Articles 21 and 25-30) by essential entities; Source 19 (Nysingh, a specialist law firm) confirms municipalities are by law designated as essential entities; Sources 12, 13, and 15 (VNG letters to municipalities and the municipal association itself) explicitly state that municipalities can face fines up to €10 million for duty-of-care breaches. The opponent's argument that the statutory text never explicitly names municipalities as finable essential entities is technically correct as a reading of Source 1 alone, but this is a false dichotomy fallacy — the logical chain is completed by combining the fine provision (Source 1) with the classification of municipalities as essential entities (Source 19, corroborated by Sources 20, 24, 25), and this combined reading is explicitly confirmed by authoritative municipal guidance (Sources 12, 13, 15). The claim follows logically and directly from the evidence with no significant inferential gaps, and the opponent's rebuttal commits a fallacy of demanding that a single source contain all elements of the argument rather than accepting valid multi-source logical inference.
Reviewer 2 — The Source Auditor
The most reliable sources are Overheid.nl (Source 1), Rijksoverheid (Source 3), Digitale Overheid (Source 5), and Raad van State (Source 16), which confirm that the Cbw implements NIS2 fines of up to €10 million specifically for essential entities violating the duty-of-care provisions, with municipalities designated as essential entities subject to those fines. Secondary sources such as VNG and municipal briefings (Sources 12, 15) independently corroborate the same statutory outcome without circularity or conflicts.
Reviewer 3 — The Precision Analyst
The evidence shows the Cbw allows administrative fines up to €10,000,000 (or 2% worldwide turnover if higher) for violations tied to the duty-of-care/risk-management obligations for “essential entities” (Source 1) and the explanatory memorandum links this maximum specifically to duty-of-care/reporting/informing obligations for essential entities (Source 14), while multiple municipality-focused sources state municipalities can be fined up to €10 million for zorgplicht breaches (Sources 12, 13, 15, 17). However, the pool does not include a primary statutory provision that explicitly classifies municipalities as “essential entities,” so the claim is well-supported in practice but not fully proven from the Cbw text shown here; as worded, it is mostly true but slightly over-assertive given the missing on-the-face statutory linkage in the provided legal excerpts.