As of 15 August 2026, the Dutch Cybersecurity Act has entered into force. This legislation strengthens the protection of organizations against digital threats and contributes to the continuity and availability of essential services, including healthcare in the Netherlands.
"The Cybersecurity Act marks an important milestone for Z-CERT. The law is the result of years of preparation, but it also marks the beginning of a new phase for Z-CERT," says Wim Hafkamp, Director of Z-CERT. "The Cybersecurity Act gives us a statutory mandate and enables us to receive information about incidents more quickly. As a result, the law enhances digital security in healthcare. Thanks to the mandatory reporting requirements that form part of the Cybersecurity Act, we can fulfill our role even more effectively, while also strengthening our position."
What is the Cybersecurity Act?
The Cybersecurity Act is the Dutch implementation of the European NIS2 Directive. The law applies to organizations that provide essential or important services. An organization falls within the scope of the Cybersecurity Act if it meets the criteria established in the relevant legislation and regulations, taking into account both the type of services it provides and the size of the organization.
Rights and obligations
The Cybersecurity Act entitles healthcare organizations to receive threat intelligence and support from Z-CERT. Organizations that fall within the scope of the Act are subject to registration, duty of care, incident reporting requirements, and mandatory supervision and enforcement.
If organizations identify significant incidents, they must report them to their CSIRT within the legally prescribed timeframes. For healthcare organizations, this CSIRT is Z-CERT. Incident reporting takes place through the NCSC reporting portal.
With the introduction of the Cybersecurity Act, the Z-CERT Foundation will become a so-called legal entity with a statutory task. Pending the advice of the Netherlands Court of Audit, the steps required for this transition have been put on hold. In practice, Z-CERT will continue to perform CSIRT duties for the healthcare sector. The Court of Audit's advice is expected after the summer. The Minister for Long-term Care, Youth and Sport will formally designate Z-CERT as the CSIRT for the healthcare sector and the manufacturing subsector as soon as possible. Until then, organizations that fall under the Cybersecurity Act and are entitled to support can continue to rely on Z-CERT.
For more information, please visit the Data for Health website of the ministry of Health, Welfare and Sport (VWS).