Incident reporting
- Product/service
- Coordination & support
- Directe toegang
Are you dealing with a cyber incident? Report it to the NCSC. In some cases this is a legal obligation; in others it is a voluntary way to collaborate on national cyber security. In both cases, support may be available.
As the Cybersecurity Act (the national implementation of the NIS2 Directive) has not yet entered into force, the Wbni (the Dutch Network and Information Systems Security Act) still applies for now. Vital providers and providers of essential services (AESs) are required to report serious incidents to the NCSC. Read more below about Wbni reporting. In addition, since 17 October 2024, organisations can also submit a voluntary NIS2 incident report via this form.
Cybersecurity Act (NIS2) reporting obligation
Organisations that will fall under the Cybersecurity Act will be subject to a reporting obligation. This means they must report significant incidents as soon as possible, and in any event within 24 hours, to the supervisory authority and the relevant sectoral CSIRT. Until the Cybersecurity Act has entered into force, this is a voluntary report.
Voluntary reporting
You can always submit a voluntary report to the NCSC. A report is considered voluntary if there is not (yet) a reason for a legally mandatory report.
The NCSC may be able to provide support and advice in response to voluntary reports. For voluntary reports, there is no obligation to report to the supervisory authority, the Dutch Authority for Digital Infrastructure. You decide which information you wish to share.
We maintain a national overview of cyber security threats. Voluntary reports contribute to this picture and help the NCSC to keep the threat landscape up to date, so organisations are better prepared for current threats.
Reporting obligations under the Cyber Resilience Act (CRA)
If you are a manufacturer, importer, or distributor of products with a digital element targeting the European market, you are required to report instances where active exploitation of a vulnerability has been detected. You must also report serious incidents involving your products. These requirements are set out in the Cyber Resilience Act (CRA). Incidents can be reported using the CRA reporting form. Read more about reporting under the CRA (in Dutch).
Loading results...