← All resources

NIS2 Netherlands: are law firms in scope of the Cbw?

Published October 4, 2026 · 8 min read · CyberNovaLabs.io

The Cyberbeveiligingswet took effect on 15 August 2026. Legal services appear in none of its sector annexes, so a Dutch law firm is not a regulated entity. It still receives its clients' NIS2 questionnaires, and the Advocatenwet and Voda already require measures.

The short answer

A Dutch law firm is, in principle, not an entity covered by the Cyberbeveiligingswet (Cbw), the Dutch transposition of NIS2, which entered into force on 15 August 2026[1]. Legal services appear in none of the law's sector annexes[2], and the official table of sectors with their CSIRT and their supervisor lists neither the bar nor the professions[3]. In practice: no entry in the national entity register, no 24-hour reporting clock, no NIS2 supervisor facing you.

That does not close the file. The Cbw applies to more than 8,000 Dutch organisations[1], and it explicitly requires them to secure their supply chain, including security aspects of the relationship with their direct suppliers and service providers (Article 21(2)(d))[6]. A firm advising a hospital, a municipality, a carrier or an energy company therefore receives its client's NIS2 questions without being regulated itself. What actually binds the firm sits elsewhere: the Advocatenwet, the Verordening op de advocatuur and the GDPR.

Are you in scope? The tests, in order

The NCSC describes a two-step check, and the order matters: size is only assessed after sector[2].

The official, free test. The Rijksinspectie Digitale Infrastructuur publishes a NIS2-Zelfevaluatie that determines whether the law applies to you and, if so, whether you are an essential or an important entity; a NIS2-Quickscan then measures the gap in your measures[5][12]. Keep the dated result: it is the evidence you will attach to client answers.

Why the NIS2 file still lands on your desk

The causal chain is short. Your regulated client must maintain seven families of measures under the duty of care: risk analysis, incident handling, continuity and backups, supply chain security, cyber hygiene and training, security in acquiring and maintaining systems, and personnel and access security[6]. The fourth one forces it to question its providers, which means you.

Its reporting calendar explains the pressure. For a significant incident, the regulated entity files an early warning within 24 hours, a notification within 72 hours and a final report within one month, through a single desk on MijnNCSC that forwards to the sectoral CSIRT and the supervisor[4]. If the leak starts in your mailbox or your file-sharing space, it is the client's clock that runs. Hence the pointed questions: multi-factor authentication, encryption at rest, logging, sub-processors, contractual notification deadline.

RoleWho, in the Netherlands
Making and interpreting the lawNCTV, at national level
CSIRT and entity registerNCSC, through MijnNCSC
Cbw supervisionBy sector: RDI, ILT, DNB, AFM, NVWA or ANVS
Personal data breachesAutoriteit Persoonsgegevens
Professional conductNOvA and the local deken

The table reproduces the split published by the NCSC[3]. The point to remember: there is no row for the legal profession, so nobody supervises a law firm under the Cbw.

What already binds you

Confidentiality is a core value of the profession, set out in Article 10a of the Advocatenwet[9]. Article 3.1 of the Verordening op de advocatuur operationalises it: the lawyer takes appropriate measures to maintain confidentiality, in particular in the choice of means of communication, the processing and the storage of data, and the security of all three[8]. This is a duty of means, not a technical standard: no certification is imposed, but you must be able to explain why your measures match your risks. Articles 6.10 and 6.11 of the same Voda add the use of the confidentiality number registered with the NOvA for privileged communications[8].

The GDPR layers on top. In 2025 the Autoriteit Persoonsgegevens received 39,407 data breach notifications, against 37,839 in 2024, of which 2,428 were caused by a cyberattack[11]. The NOvA, for its part, writes that a lawyer's likelihood of becoming a victim of data theft is above average, because case files are valuable to an attacker[10]. The same page carries a figure worth citing when you train your people: in the Ipsos I&O survey commissioned by the NOvA, the share of lawyers facing aggression, threats or intimidation rose from 50% in 2022 to 55% in 2024[10]. Security in a Dutch firm is not only an IT subject.

The first five actions

  1. Date your out-of-scope finding. Run the RDI NIS2-Zelfevaluatie, save the result and the date[12]. One sentence then answers clients: we are not covered by the Cbw, here is the check.
  2. Write a two-page security fact sheet. Multi-factor authentication, device and backup encryption, patch management, list of sub-processors and their hosting countries, contractual incident notification deadline. Our supplier security questionnaire template lists the questions clients will ask.
  3. Check SPF, DKIM and DMARC. Impersonating a law firm in a payment e-mail is the most profitable attack against the sector. The free e-mail security check returns a per-domain verdict in a minute.
  4. Map the Voda onto your actual tools. Read Article 3.1 line by line against your real inventory: mail, file sharing, video calls, AI assistant, archiving[8]. For each, write down where the data lives and who can read it.
  5. Write the incident plan and rehearse it once. Who decides, who warns the regulated client inside its 24-hour window[4], who notifies the Autoriteit Persoonsgegevens, who calls the deken. A one-hour exercise beats ten pages of procedure.

Related reading

Two neighbouring guides, useful when your clients or peers are in scope: NIS2 Netherlands for transport and logistics, which covers a fully regulated Dutch sector, and NIS2 France for accounting firms and fiduciaries, the same reasoning for another regulated profession. Our NIS2 in the Netherlands page collects the country's thresholds, authorities and deadlines.

At CyberNovaLabs.io

We equip firms that want to answer quickly and accurately: out-of-scope verification, security fact sheet, e-mail check, and automation of recurring answers to client questionnaires, described on our AI and automation for business page. Start with the free NIS2 check, then take twenty minutes with us: we will tell you what is a page of procedure and what is a real project. Work is quoted per engagement, with no minimum term.

This guide describes texts published as at 4 October 2026 and is not legal advice. For a determination specific to your firm, consult the annexes to the Cyberbeveiligingswet[7] and your sector authority[3].

Sources

  1. NCSC — Cyberbeveiligingswet (NIS2)
  2. NCSC — Valt mijn organisatie onder de Cyberbeveiligingswet (NIS2)?
  3. NCSC — Toezicht op de Cyberbeveiligingswet (NIS2): hoe zit dat?
  4. NCSC — Meld incidenten onder de Cyberbeveiligingswet (meldplicht)
  5. RDI — Cyberbeveiligingswet (met NIS2-Zelfevaluatie en NIS2-Quickscan)
  6. NCSC — Zorgplicht: de maatregelen van artikel 21 Cbw
  7. Cyberbeveiligingswet, Staatsblad 2026, 187
  8. Verordening op de advocatuur (Voda)
  9. Advocatenwet
  10. NOvA — Weerbaarheid en veiligheid
  11. Autoriteit Persoonsgegevens — Rapportage datalekken 2025
  12. RDI — NIS2-Zelfevaluatie
CyberNovaLabs.io

Qualified meetings, no lock-in.

Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.

→ Get meetings booked

Read next

Newsletter · CyberNovaLabs.io

Security Briefing

One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.

→ Get meetings booked