NIS2 Netherlands: are law firms in scope of the Cbw?
The Cyberbeveiligingswet took effect on 15 August 2026. Legal services appear in none of its sector annexes, so a Dutch law firm is not a regulated entity. It still receives its clients' NIS2 questionnaires, and the Advocatenwet and Voda already require measures.
The short answer
A Dutch law firm is, in principle, not an entity covered by the Cyberbeveiligingswet (Cbw), the Dutch transposition of NIS2, which entered into force on 15 August 2026[1]. Legal services appear in none of the law's sector annexes[2], and the official table of sectors with their CSIRT and their supervisor lists neither the bar nor the professions[3]. In practice: no entry in the national entity register, no 24-hour reporting clock, no NIS2 supervisor facing you.
That does not close the file. The Cbw applies to more than 8,000 Dutch organisations[1], and it explicitly requires them to secure their supply chain, including security aspects of the relationship with their direct suppliers and service providers (Article 21(2)(d))[6]. A firm advising a hospital, a municipality, a carrier or an energy company therefore receives its client's NIS2 questions without being regulated itself. What actually binds the firm sits elsewhere: the Advocatenwet, the Verordening op de advocatuur and the GDPR.
Are you in scope? The tests, in order
The NCSC describes a two-step check, and the order matters: size is only assessed after sector[2].
- Step 1, sector. The law covers the sectors listed in Annexes 1 and 2 of the Cyberbeveiligingswet, published in Staatsblad 2026, 187[7]. Those annexes also state which entity types count within each sector. Legal advice is not among them.
- Step 2, size. Your organisation is large enough if it has 50 FTE or more, or if, with fewer than 50 FTE, both its annual turnover and its balance sheet total exceed 10 million euro. Partner and linked undertakings, parent and subsidiaries included, count towards those figures[2].
- Size-independent cases. Some entities fall under the law regardless of size: DNS service providers, providers of public electronic communications networks and services, trust service providers, top-level domain name registries and government bodies[2]. A law firm fits none of them.
- The real edge case. If your structure also sells managed IT or a digital service to third parties, for instance a document-sharing platform billed to other firms, read the Beheer van ICT-diensten and Digitale aanbieders rows: there the supervisor is the RDI[3].
The official, free test. The Rijksinspectie Digitale Infrastructuur publishes a NIS2-Zelfevaluatie that determines whether the law applies to you and, if so, whether you are an essential or an important entity; a NIS2-Quickscan then measures the gap in your measures[5][12]. Keep the dated result: it is the evidence you will attach to client answers.
Why the NIS2 file still lands on your desk
The causal chain is short. Your regulated client must maintain seven families of measures under the duty of care: risk analysis, incident handling, continuity and backups, supply chain security, cyber hygiene and training, security in acquiring and maintaining systems, and personnel and access security[6]. The fourth one forces it to question its providers, which means you.
Its reporting calendar explains the pressure. For a significant incident, the regulated entity files an early warning within 24 hours, a notification within 72 hours and a final report within one month, through a single desk on MijnNCSC that forwards to the sectoral CSIRT and the supervisor[4]. If the leak starts in your mailbox or your file-sharing space, it is the client's clock that runs. Hence the pointed questions: multi-factor authentication, encryption at rest, logging, sub-processors, contractual notification deadline.
| Role | Who, in the Netherlands |
|---|---|
| Making and interpreting the law | NCTV, at national level |
| CSIRT and entity register | NCSC, through MijnNCSC |
| Cbw supervision | By sector: RDI, ILT, DNB, AFM, NVWA or ANVS |
| Personal data breaches | Autoriteit Persoonsgegevens |
| Professional conduct | NOvA and the local deken |
The table reproduces the split published by the NCSC[3]. The point to remember: there is no row for the legal profession, so nobody supervises a law firm under the Cbw.
What already binds you
Confidentiality is a core value of the profession, set out in Article 10a of the Advocatenwet[9]. Article 3.1 of the Verordening op de advocatuur operationalises it: the lawyer takes appropriate measures to maintain confidentiality, in particular in the choice of means of communication, the processing and the storage of data, and the security of all three[8]. This is a duty of means, not a technical standard: no certification is imposed, but you must be able to explain why your measures match your risks. Articles 6.10 and 6.11 of the same Voda add the use of the confidentiality number registered with the NOvA for privileged communications[8].
The GDPR layers on top. In 2025 the Autoriteit Persoonsgegevens received 39,407 data breach notifications, against 37,839 in 2024, of which 2,428 were caused by a cyberattack[11]. The NOvA, for its part, writes that a lawyer's likelihood of becoming a victim of data theft is above average, because case files are valuable to an attacker[10]. The same page carries a figure worth citing when you train your people: in the Ipsos I&O survey commissioned by the NOvA, the share of lawyers facing aggression, threats or intimidation rose from 50% in 2022 to 55% in 2024[10]. Security in a Dutch firm is not only an IT subject.
The first five actions
- Date your out-of-scope finding. Run the RDI NIS2-Zelfevaluatie, save the result and the date[12]. One sentence then answers clients: we are not covered by the Cbw, here is the check.
- Write a two-page security fact sheet. Multi-factor authentication, device and backup encryption, patch management, list of sub-processors and their hosting countries, contractual incident notification deadline. Our supplier security questionnaire template lists the questions clients will ask.
- Check SPF, DKIM and DMARC. Impersonating a law firm in a payment e-mail is the most profitable attack against the sector. The free e-mail security check returns a per-domain verdict in a minute.
- Map the Voda onto your actual tools. Read Article 3.1 line by line against your real inventory: mail, file sharing, video calls, AI assistant, archiving[8]. For each, write down where the data lives and who can read it.
- Write the incident plan and rehearse it once. Who decides, who warns the regulated client inside its 24-hour window[4], who notifies the Autoriteit Persoonsgegevens, who calls the deken. A one-hour exercise beats ten pages of procedure.
Related reading
Two neighbouring guides, useful when your clients or peers are in scope: NIS2 Netherlands for transport and logistics, which covers a fully regulated Dutch sector, and NIS2 France for accounting firms and fiduciaries, the same reasoning for another regulated profession. Our NIS2 in the Netherlands page collects the country's thresholds, authorities and deadlines.
At CyberNovaLabs.io
We equip firms that want to answer quickly and accurately: out-of-scope verification, security fact sheet, e-mail check, and automation of recurring answers to client questionnaires, described on our AI and automation for business page. Start with the free NIS2 check, then take twenty minutes with us: we will tell you what is a page of procedure and what is a real project. Work is quoted per engagement, with no minimum term.
This guide describes texts published as at 4 October 2026 and is not legal advice. For a determination specific to your firm, consult the annexes to the Cyberbeveiligingswet[7] and your sector authority[3].
Sources
- NCSC — Cyberbeveiligingswet (NIS2)
- NCSC — Valt mijn organisatie onder de Cyberbeveiligingswet (NIS2)?
- NCSC — Toezicht op de Cyberbeveiligingswet (NIS2): hoe zit dat?
- NCSC — Meld incidenten onder de Cyberbeveiligingswet (meldplicht)
- RDI — Cyberbeveiligingswet (met NIS2-Zelfevaluatie en NIS2-Quickscan)
- NCSC — Zorgplicht: de maatregelen van artikel 21 Cbw
- Cyberbeveiligingswet, Staatsblad 2026, 187
- Verordening op de advocatuur (Voda)
- Advocatenwet
- NOvA — Weerbaarheid en veiligheid
- Autoriteit Persoonsgegevens — Rapportage datalekken 2025
- RDI — NIS2-Zelfevaluatie
Qualified meetings, no lock-in.
Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.
Read next
Data breach at FWB: three weeks before it was confirmed (05/10)
Flagged from outside in mid-September, confirmed on 5 October 2026: the EAD-online.be data breach shows where the GDPR's 72 hours are really lost, and why the weak link is so often a supplier.
Read the article →October 7, 2026 · 7 min readNIS2 France: are hotels and tourism in scope?
Tourist accommodation is absent from the NIS2 annexes, and France's transposition was still in parliament on 7 October 2026. Yet in May 2026 three French tourism operators lost their reservation databases within 72 hours. Here is what actually applies to you.
Read the article →October 6, 2026 · 7 min readDGFiP breach: stolen logins, no MFA, no detection (29/09/2026)
On 29 September 2026 France's cyber agency ANSSI published its incident report on the cyberattacks against the tax administration. No rare technique: passwords stolen from personal computers, a second factor sent by email, sensitive applications reachable without segmentation, and a portal nobody was watching. All four links exist in most SMEs.
Read the article →