Country guide

Rail cyber security regulations in the Netherlands

Rail cyber security in the Netherlands now sits within the Cyberbeveiligingswet (Cbw), the Dutch implementation of NIS2. The NCSC confirms that the Cbw and the Wet weerbaarheid kritieke entiteiten (Wwke) entered into force on 15 August 2026. For rail teams, the next task is to connect entity classification and registration to the systems that support reliable train operations.

Official sources checked

Who needs to consider these requirements?

Assess railway undertakings, infrastructure managers and relevant service-facility operators against the statutory activity, size and designation criteria. Do not assume that a group-level assessment covers every operating entity or that every rail supplier is automatically regulated. For cross-border fleets, identify which organisation operates each service and who controls train, depot and wayside systems.

Key regulations and frameworks

Cyberbeveiligingswet (Cbw): Dutch NIS2 implementation

Law — in force from 15 August 2026

Covered organisations must register, manage cyber risks and report significant incidents. The NCSC also identifies board responsibility and training among the obligations. Register through the official NCSC route and establish who owns incident assessment and reporting; purchasing a security product alone does not meet these organisational duties.

Official source: Cyberbeveiligingswet (Cbw): Dutch NIS2 implementation

Cyberbeveiligingsregeling IenW: sector rules including rail

Ministerial regulation — transport includes the rail subsector

Article 2 expressly includes rail within the transport entities covered by this sector regulation. It adds detail to the wider cyber-security framework, including risk-management and incident-significance provisions. Use the requirements applicable to your entity type: provisions written for government organisations or water authorities should not be applied indiscriminately to railway businesses.

Official source: Cyberbeveiligingsregeling IenW: sector rules including rail

Wet weerbaarheid kritieke entiteiten (Wwke)

Critical-entity resilience law — in force from 15 August 2026

The Wwke complements cyber security with a broader resilience framework. Assess critical-entity designation separately from Cbw classification. For rail operations, use a coordinated resilience review to examine dependencies such as power, telecommunications, physical access and maintenance services, while keeping the applicable legal duties and reporting routes distinct.

Official source: Wet weerbaarheid kritieke entiteiten (Wwke)

Practical steps for rail teams

Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.

  1. Record the Cbw scope decision for each legal entity and rail service, including the basis for its size or designation assessment. Assign registration and management-training owners.
  2. Map operational dependencies across rolling stock, depots and infrastructure. Identify remote maintenance connections, supplier accounts and legacy equipment that cannot be updated during normal service.
  3. Build an incident playbook around the applicable IenW significance criteria and statutory reporting process. Rehearse gathering operational impact and technical evidence while maintaining safe service recovery.
  4. Agree supplier escalation times, access controls and evidence requirements in maintenance contracts. Link cyber recovery exercises with the organisation's wider resilience programme.

Using this guide

This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.