DORA-Only or Still NIS2? How DNB Draws the CBW Line for Dutch Banks and Insurers
De Nederlandsche Bank runs two jobs in the Netherlands’ NIS2 framework, and conflating them is the fastest way to misjudge your obligations. As the country’s central bank and prudential supervisor, DNB states it supervises no fewer than 1,200 financial institutions, from banks to pension funds to crypto-asset service providers [12]. As of 15 August 2026, when the Cyberbeveiligingswet (CBW) enters into force with no transition period, DNB also becomes a sectoral competent authority under the Netherlands’ NIS2 transposition [3]. Most compliance teams assume the Digital Operational Resilience Act (DORA) has already taken care of NIS2 for anyone in finance. That’s only true for entities DORA’s own scope article actually lists — and DORA’s exemption clause hands a specific population of smaller financial firms straight back to DNB’s, and the CBW’s, full reach. This guide draws that line using DORA’s scope text, the CBW’s own dual-reporting design, and named examples of which Dutch banks sit on which side — a finance-specific companion to our broader breakdown of the Netherlands’ six NIS2 sector supervisors.
Does This Apply to You? The Two-Question Test
In plain terms: if you’re a bank, insurer, investment firm, payment institution, or fund manager operating in the Netherlands, you’re in scope for something — DORA, the CBW, or both. “We’re regulated by DNB” doesn’t answer which one. Two questions, in order, settle it.
| Question | If yes | If no |
|---|---|---|
| Are you one of the 21 financial-entity types DORA Article 2(1) lists — credit institution, payment/e-money institution, investment firm, insurer/reinsurer, crypto-asset service provider, or similar [1]? | Go to question 2 | Check the CBW directly: sectors include energy, transport, banking, healthcare, water, digital infrastructure, and manufacturing, with a size threshold of more than 50 employees or over €10 million in annual turnover or balance sheet [11] |
| Are you exempted under DORA Article 2(3) — e.g. a sub-threshold AIFM, an insurer below the Solvency II premium thresholds, an occupational pension scheme (IORP) with fewer than 15 members, a person exempted under MiFID II, or a micro/SME insurance intermediary [1]? | You’re “residual NIS2” under the CBW — see the residual-entity section below | You’re DORA-covered: DNB or AFM supervises your ICT risk framework and incident reporting, and the CBW’s registration duty still applies on top |
The threshold in question 1’s “no” branch matches the CBW’s general size test, which RDI (the Netherlands’ primary digital-infrastructure regulator) states plainly: more than 50 employees, or annual turnover and balance sheet both above €10 million, puts an organisation in an in-scope sector into “important entity” territory at minimum [11].
DNB’s Two Hats: Prudential Supervisor and NIS2 Sectoral Authority
In plain terms: DNB doesn’t supervise every kind of financial firm — the Netherlands splits financial oversight along a twin-peaks model, and knowing which peak you sit under determines who you actually answer to for both DORA and the CBW.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
| Supervisor | Role | Entity types |
|---|---|---|
| DNB (De Nederlandsche Bank) | Prudential supervision | Credit institutions (banks), payment and e-money institutions, insurance and reinsurance undertakings [7] |
| AFM (Autoriteit Financiële Markten) | Conduct-of-business supervision | Investment firms, MiCA-authorised crypto-asset service providers [7] |
Both authorities carry their DORA mandate and their CBW sectoral role at once — a Dutch source specialising in Secure Audit’s compliance guidance describes it directly: “De Nederlandsche Bank (DNB) remain[s] responsible for the financial sector, where DORA also applies,” positioning DNB as a co-supervisor with AFM under the CBW rather than a separate cybersecurity-only regulator layered on top [4]. An entity with both a banking licence and a payment-services arm can end up coordinating evidence with both DNB and AFM simultaneously, since prudential and conduct exposure don’t always sit inside the same corporate entity [7].
The CBW’s Dual-Reporting Mechanic: Why DNB or AFM Alone Isn’t Enough
In plain terms: a significant incident at a Dutch financial entity doesn’t go to one inbox. It goes to your sector supervisor and to NCSC-NL, on two overlapping clocks, because the two bodies exist to catch different things.
NCSC-NL’s statutory mandate — drawn from the Wbni, the CBW, and related instruments — casts it as the Netherlands’ designated CSIRT and its single point of contact for cross-border coordination with other EU member states [5]. DNB and AFM, by contrast, exist to protect financial stability and market conduct within their own supervised population — they have no mandate to coordinate with a German or French CSIRT when an incident has cross-border implications. That’s the mechanism behind the dual duty: a financial entity’s incident can simultaneously threaten sector-specific stability (DNB/AFM’s problem) and signal a broader, potentially cross-border digital-resilience issue (NCSC-NL’s problem), and neither body is positioned to fully cover the other’s angle alone.
The two reporting tracks run on different clocks, which is where compliance teams most often trip:
| Track | Trigger | Timeline |
|---|---|---|
| CBW / NCSC-NL | A “significant incident” — causes or may cause serious operational disruption or financial loss, or affects other persons through substantial material or immaterial damage [6] | 24-hour early warning, 72-hour incident report, 1-month final report [3][4] |
| DORA / DNB or AFM (DORA-covered entities only) | A major ICT-related incident under DORA’s own classification criteria | Initial notification within 4 hours of classification (24 hours of detection), intermediate report at 72 hours, final report within 1 month [7] |
DORA’s 4-hour classification clock is tighter than the CBW’s 24-hour early-warning window, which means a DORA-covered entity that builds its incident-response process around DORA’s timeline will, in most cases, already have the facts assembled well before a hypothetical parallel CBW deadline would bite — but DORA-covered entities don’t file a second, separate CBW incident report on the same clock; DORA displaces that specific NIS2 obligation under the lex specialis mechanism covered next. A residual-NIS2 entity has no such shortcut: the CBW’s own 24/72-hour/1-month structure is the only clock running, reported straight to NCSC-NL and, per the dual-reporting design described above, its own DNB or AFM supervisor [3][4][5]. Our Article 23 incident-notification breakdown covers the general 24-hour/72-hour/one-month structure in more depth for entities on the CBW-only track.
Why DORA Doesn’t Erase the CBW: Article 4’s Equivalence Test
In plain terms: DORA switching off NIS2 isn’t automatic or blanket for “the finance sector” — it’s a provision-by-provision test built into NIS2 itself, and it only fires for the entities DORA’s own scope article actually names.
NIS2 Article 4 states that where a sector-specific EU legal act imposes cybersecurity risk-management or incident-notification requirements “at least equivalent in effect” to NIS2’s own Article 21 and Article 23, the corresponding NIS2 obligations and supervision don’t apply to the entities that sector-specific act covers — but if the act doesn’t reach every entity in the sector, NIS2 continues applying to whoever’s left out [2]. DORA is that sector-specific act for finance. Its scope, though, is a named list of 21 entity categories in Article 2(1), with a separate exemption clause in Article 2(3) that carves out a defined set of smaller players: sub-threshold alternative investment fund managers, insurers below the Solvency II premium-income thresholds, occupational pension schemes with fewer than 15 members, persons exempted under MiFID II Articles 2 to 3, and — the category that comes up most often in practice — insurance and reinsurance intermediaries that qualify as microenterprises or SMEs [1]. Everyone Article 2(3) exempts doesn’t get a lighter version of DORA’s rules. They fall straight back to whatever NIS2’s own scope catches them under, transposed in the Netherlands as the CBW. Read our general NIS2 vs DORA comparison for how this displacement mechanism works EU-wide, outside the Netherlands-specific mechanics covered here.
DORA-Covered in Practice: Systemic Banks and the TLPT Layer
In plain terms: for the Netherlands’ largest banks, DORA coverage isn’t a debate — it’s been operational since January 2025, and it comes with a testing obligation the CBW never asks residual entities for.
DORA applies to credit institutions with no size exemption in Article 2(1) — every one of the roughly 5,500 EU credit institutions is in scope, whether supervised directly by the ECB as a Single Supervisory Mechanism “significant” institution or by a national authority as a smaller one [10]. Rabobank, the Netherlands’ second-largest bank by assets, states it “already complies with a substantial part” of DORA’s requirements through a group-wide implementation programme — a fairly typical position for an institution DORA never gave an exemption route to consider [8]. ING built its own DORA programme under its COO, with its global head of security strategy describing the work of mapping and registering the applications behind its critical business services as “the quite complex step” — ordinary operational reality for a DORA-covered bank, not a special case [9].
Institutions in this bracket also carry Threat-Led Penetration Testing (TLPT): live, production-system red-team exercises run roughly every three years through accredited providers, required of Other Systemically Important Institutions and Global Systemically Important Institutions — an estimated 100 to 120 banks across the EU, with the first testing cycle running 2025 to 2027 [10]. Nothing in the CBW’s own text imposes an equivalent TLPT-grade testing mandate on residual-NIS2 entities; it’s a DORA-specific obligation that lands only on the institutions large enough to be designated for it.
Residual NIS2: Who Article 2(3) Leaves Fully Exposed to the CBW
In plain terms: DORA’s exemption list reads like relief for smaller financial firms. It isn’t. It’s a routing decision — and the destination is full NIS2 exposure through the CBW, with none of DORA’s own displacement working in your favour.
| Entity type | DORA status | CBW exposure if size threshold met |
|---|---|---|
| Sub-threshold / registered-only AIFMs | Exempted, Art.2(3) | Full CBW: risk-management measures, dual-track incident reporting, registration [1] |
| Insurers below Solvency II premium threshold | Exempted, Art.2(3) | Full CBW exposure [1] |
| IORPs with fewer than 15 members | Exempted, Art.2(3) | Full CBW exposure [1] |
| Micro/SME insurance intermediaries | Exempted, Art.2(3) | Full CBW exposure [1] |
| Credit institutions, non-exempt insurers, non-exempt investment firms, CASPs | Covered, Art.2(1) | DORA displaces CBW risk-management/incident rules; CBW registration duty likely still applies [1][2] |
A microenterprise insurance intermediary that crosses the CBW’s 50-employee or €10 million threshold gets the full Article 21-equivalent risk-management measure set, the CBW’s own 24-hour/72-hour/1-month incident clock reported to both NCSC-NL and DNB or AFM, and the registration duty — with no DORA-lite version to soften any of it, because Article 2(3) was never designed to reduce their regulatory burden. It was designed to keep DORA’s own scope proportionate to institutions large enough to warrant its specific ICT-testing regime, and everything below that line reverts to the general rule.
Reader Playbook by Role
The two-question test and DNB’s dual role land differently depending on your seat.
Compliance officer or legal: run the two-question test per legal entity, not per group — a banking group can hold a DORA-covered credit institution alongside a sub-threshold AIFM subsidiary that’s fully residual-NIS2. Document which supervisor (DNB, AFM, or both) and which reporting track (CBW, DORA, or both) apply to each entity before 15 August 2026, since there’s no transition period once the CBW takes effect [3].
CISO or IT security lead: if your institution is genuinely DORA-covered, your Article 21-equivalent obligations are already satisfied through DORA’s ICT risk framework — but confirm that in writing rather than assuming it, and build incident-response playbooks around DORA’s tighter 4-hour classification clock, not the CBW’s 24-hour one, since that’s the timeline your entity actually reports on [7].
Board or C-suite: ask directly which reporting track and which supervisor attach to your institution, and get the answer documented in board minutes. Board members face CBW training obligations regardless of DORA status, and “we’re a bank, so DORA covers everything” is not a defensible answer if a subsidiary or intermediary in your group turns out to be residual-NIS2 [3].
SME owner or smaller entity — a small insurance intermediary or sub-threshold fund manager: DORA’s Article 2(3) exemption was written with you in mind, and that’s precisely why it doesn’t reduce your workload. If you cross the CBW’s size threshold, you inherit full NIS2-equivalent obligations with none of DORA’s displacement working in your favour [1][11].
Compliance Checklist
- Classify now: run the two-question test per legal entity and record which supervisor(s) and reporting track apply.
- Register before 15 August 2026: the CBW enters into force with no grace period; DORA coverage doesn’t exempt an entity from the CBW’s registration duty [3]. Our Netherlands penalties guide covers the CBW’s three-tier fine structure and current enforcement-gap status.
- If residual-NIS2: implement the Article 21-equivalent risk-management measure set and build the 24-hour/72-hour/1-month reporting workflow to both NCSC-NL and DNB or AFM.
- If DORA-covered: confirm ICT risk-framework documentation is current, and if designated for TLPT, confirm your first three-year testing cycle is scheduled within the 2025–2027 window [10].
Frequently Asked Questions
Does DORA replace the CBW entirely for every Dutch financial firm? No. It displaces the CBW’s risk-management and incident-notification rules only for the entity types DORA Article 2(1) actually lists, and the CBW’s registration duty likely still applies on top [1][2].
My insurance intermediary business is small — does that mean less regulation? Not automatically. DORA’s Article 2(3) exemption for micro/SME insurance intermediaries removes you from DORA’s scope, but if you meet the CBW’s own size threshold, you fall back to full NIS2-equivalent obligations with no DORA relief [1][11].
Who do I report a significant incident to if I’m not sure which category I’m in? Report to your sector supervisor (DNB or AFM) and to NCSC-NL in parallel until your classification is documented — the CBW’s dual-reporting design means both bodies expect to hear from in-scope financial entities [3][4][5].
Legal Disclaimer
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- DORA (Regulation (EU) 2022/2554), Article 2 — digital-operational-resilience-act.com, Article 2 (scope list and Article 2(3) exemptions)
- NIS2 Directive, Article 4 — nis-2-directive.com, Article 4 (sector-specific Union acts / lex specialis equivalence test)
- Clyde & Co, “Dutch Cybersecurity Act enters into force on 15 August 2026” — clydeco.com (entry-into-force date, obligations, penalties, board training)
- “Cybersecurity Act (Cbw): the Dutch NIS2 law” — Secure Audit (secureaudit.nl), knowledge base (DNB’s dual role, incident timeline, penalty tiers)
- NCSC-NL, “Statutory mandate” — ncsc.nl (legal basis, CSIRT role, cross-border contact point)
- NCSC-NL, “Report an incident to NCSC-NL” — ncsc.nl (significant-incident definition, reporting channels)
- Cyadviso, “DORA Reporting in the Netherlands: DNB and AFM Guide for Financial Entities” — cyadviso.com (twin-peaks supervisory split, DORA incident timeline)
- Rabobank, “DORA — Digital Operational Resilience Act” (rabobank.nl/en/business/support/dora; self-disclosed compliance status)
- QA Financial, “DORA preparations at ING Group in full swing as 2025 nears” — qa-financial.com
- Regulation-DORA.eu, “DORA for Banks: ECB Supervision, TLPT & ICT Roadmap” — regulation-dora.eu (credit-institution scope, TLPT, SREP integration)
- RDI (Rijksinspectie Digitale Infrastructuur), “Wat betekent de Cyberbeveiligingswet voor u?” — rdi.nl (size threshold, entity classification)
- De Nederlandsche Bank, “Supervision of financial institutions” (dnb.nl/en/reliable-financial-sector/supervision-of-financial-institutions/; 1,200-institution figure)
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
