Who needs to consider these requirements?
Assess railway undertakings, infrastructure managers and relevant service-facility operators against the statutory activity, size and designation criteria. Do not assume that a group-level assessment covers every operating entity or that every rail supplier is automatically regulated. For cross-border fleets, identify which organisation operates each service and who controls train, depot and wayside systems.
Key regulations and frameworks
Cyberbeveiligingswet (Cbw): Dutch NIS2 implementation
Law — in force from 15 August 2026
Covered organisations must register, manage cyber risks and report significant incidents. The NCSC also identifies board responsibility and training among the obligations. Register through the official NCSC route and establish who owns incident assessment and reporting; purchasing a security product alone does not meet these organisational duties.
Official source: Cyberbeveiligingswet (Cbw): Dutch NIS2 implementation
Cyberbeveiligingsregeling IenW: sector rules including rail
Ministerial regulation — transport includes the rail subsector
Article 2 expressly includes rail within the transport entities covered by this sector regulation. It adds detail to the wider cyber-security framework, including risk-management and incident-significance provisions. Use the requirements applicable to your entity type: provisions written for government organisations or water authorities should not be applied indiscriminately to railway businesses.
Official source: Cyberbeveiligingsregeling IenW: sector rules including rail
Wet weerbaarheid kritieke entiteiten (Wwke)
Critical-entity resilience law — in force from 15 August 2026
The Wwke complements cyber security with a broader resilience framework. Assess critical-entity designation separately from Cbw classification. For rail operations, use a coordinated resilience review to examine dependencies such as power, telecommunications, physical access and maintenance services, while keeping the applicable legal duties and reporting routes distinct.
Official source: Wet weerbaarheid kritieke entiteiten (Wwke)
Practical steps for rail teams
Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.
- Record the Cbw scope decision for each legal entity and rail service, including the basis for its size or designation assessment. Assign registration and management-training owners.
- Map operational dependencies across rolling stock, depots and infrastructure. Identify remote maintenance connections, supplier accounts and legacy equipment that cannot be updated during normal service.
- Build an incident playbook around the applicable IenW significance criteria and statutory reporting process. Rehearse gathering operational impact and technical evidence while maintaining safe service recovery.
- Agree supplier escalation times, access controls and evidence requirements in maintenance contracts. Link cyber recovery exercises with the organisation's wider resilience programme.
Using this guide
This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.
