Illustrative image: container-terminal operations at the Port of Rotterdam, where new Dutch cybersecurity obligations take effect on 15 August 2026.

**Verified development**

The Netherlands’ Cybersecurity Act (Cyberbeveiligingswet, Cbw) and Critical Entities Resilience Act will enter into force on **15 August 2026**. The Dutch government states that the Cbw implements the EU NIS2 Directive and requires in-scope organisations to register in the national entity register maintained through the National Cyber Security Centre (NCSC). The Port of Rotterdam Authority has separately said that, from the same date, hundreds of companies in the Rotterdam port will be subject to new cybersecurity obligations, including registration, a duty of care and reporting of significant cyber incidents.

This is an immediate operational development for a port ecosystem where terminal operating systems, vessel and traffic coordination, cargo-release processes, industrial control systems, customs interfaces and ship–shore communications increasingly depend on connected digital infrastructure. The Port Authority’s July update also linked the coming obligations to work by FERM Zeehavens, the cybersecurity platform for Dutch seaports of national importance.

The official material reviewed does not identify every affected port company or publish a port-specific list of technical controls. It does, however, make clear that the date is fixed and that the regime is broader than a voluntary cyber-resilience initiative. The NCSC confirms that the Act takes effect on 15 August and provides an incident-reporting channel.

**Why this matters**

For shipowners, managers, charterers and cargo interests using Rotterdam, the principal exposure is not simply legal compliance by a terminal or service provider. A cyber incident can interrupt berth planning, gate movements, stowage and cargo-status data, documentation flows, bunker coordination or the availability of operational technology. Those failures can quickly translate into delay, cargo-handling, contractual-performance and claims-notification issues.

Operators and counterparties should therefore establish who owns incident escalation across the port call, which digital service providers are material to safe and timely operations, and how evidence will be preserved if a cyber event affects cargo visibility or vessel turnaround. Contracts and port-call procedures should be checked for notification routes, decision authority, data-access contingencies and interfaces with insurers, P&I correspondents and surveyors.

This is also a supply-chain visibility issue. A carrier or cargo owner may not itself fall within the Dutch regime, yet can depend on an in-scope terminal, agent, towage provider, bunker supplier, logistics platform or industrial facility. The practical value of the new rules will depend on whether incident reporting and resilience planning produce timely, usable operational information for the parties managing the ship and cargo—not only regulatory notifications after disruption has occurred.

Assisted editorial process

Technology supported research and drafting. TWS retains editorial responsibility for the published content and cited sources.

Need operational support?

Turn intelligence into action.

Request attendance