HEALTHCARE SECTOR · Q2 2026

The Inspectorate already knows you are not ready.

Soon it will have the authority to act on it.

Q2 2026 · 4 min read ·

The Inspectorate already knows you are not ready.

Under the forthcoming Cyberbeveiligingswet (CbW), the Health and Youth Care Inspectorate (IGJ) gains a second mandate: oversight of the digital resilience of healthcare institutions — alongside its existing oversight of patient safety.

According to the explanatory memorandum to the Cyberbeveiligingsregeling in de Zorg (footnote 7), the IGJ is designated as the supervisor of digital resilience, in addition to its role in the field of patient safety and quality of care.

01 — From guideline to yardstick

NEN 7510 was a guideline. Under the CbW it becomes the yardstick. The difference is fundamental: between “we work with it” and “we can demonstrate that we comply with it”. The IGJ will concretely assess your documentation, risk analyses and the follow-up on them.

02 — Proactive supervision, without an incident

Supervision becomes proactive: the IGJ need not wait for a data breach or incident. As an essential entity — more than 250 employees or more than €50 million in turnover — you can expect an unannounced inspection visit.

03 — The board itself in the spotlight

The board must itself have demonstrable knowledge of cybersecurity. A training obligation applies within two years of the law taking effect, along with personal liability in cases of gross negligence. Note: a standard D&O policy does not automatically cover this.

Why this is different: one supervisor, two mandates

Mandate 1 — already active

  • Patient safety
  • Quality of care

Mandate 2 — new under the CbW

  • Digital resilience
  • Demonstrable compliance (NEN 7510)

The moment both mandates converge in a single inspection visit is not a risk — it is inevitable.

The question for your board meeting

If the Inspectorate comes calling this autumn — can you then show that you are ready? Who is solving this? And: is that person already in place?

How VigIT People helps

We help healthcare institutions, government bodies and regulated organisations secure the security leaders who make the difference — before the regulator comes knocking.

Get in touch

Source: Explanatory memorandum to the Cyberbeveiligingsregeling in de Zorg (CrbZ) — internetconsultatie.nl/cyberbeveiligingsregelingzorg