Since August 15, 2026, two new laws have been in force that affect thousands of Dutch organizations: the Cybersecurity Act (Cbw) and the Critical Entities Resilience Act (Wwke). Together, they require you to get both your digital and your physical resilience demonstrably in order. The Cbw is the Dutch implementation of the European NIS2 Directive and focuses on digital security. The Wwke stems from the CER Directive and is specifically about physical protection against so-called all-hazard threats: from sabotage and attacks to extreme weather. The question is no longer whether you comply with the law, but whether your security holds up the moment someone really puts it to the test.
What exactly is changing?
The figures show the scale. Around 8,000 companies and institutions fall under the Cybersecurity Act. The 500 most essential ones, think drinking water, energy, and digital infrastructure, count as “critical entities” and have to meet the highest standards. For those essential institutions, the fines for failing to meet the duty of care and the notification obligation run up to 10 million euros or 2 percent of global annual turnover, whichever is higher.
Four obligations stand out:
- Registration obligation: the organizations involved register in the national entity register, managed by the NCSC.
- Duty of care: you take demonstrably appropriate technical and organizational measures to manage risks.
- Notification obligation: you report a significant incident to the NCSC immediately, and a physical disruption of essential service delivery within 24 hours.
- Board-level responsibility: ultimate responsibility rests explicitly with the board. Directors approve measures, oversee their implementation, and are legally required to complete training so they can assess security levels on their merits.
That last point is new and far-reaching. Cybersecurity is no longer an IT topic you delegate. It’s on the boardroom table, with personal consequences.
Physical security: the topic that was underestimated for too long
The current affairs program Nieuwsuur devoted a broadcast to it earlier this week, and the picture is confronting. Red teams, security specialists who try to get in for a fee, are busier than ever thanks to the new legislation. Their findings are sobering. A copied pass, a fake identity, or just a convincing story at reception often turns out to be enough. One of the companies interviewed got into a care institution by guessing obvious passwords, after which it could take over cameras and watch into patient rooms.
The common thread in that broadcast: we’re too naive in the Netherlands. The threat from state actors is growing, while the taken-for-granted backing of allies is shrinking. And the weakest link often isn’t in the technology, but in the person at the front desk who simply lets someone in.
That’s exactly why the Wwke pulls physical resilience up to the same level as digital. Grounds, installations, and access have to be demonstrably protected. The question is no longer whether you have a camera system, but whether your entire chain of physical barriers holds up when someone deliberately tries to get through it.
The chain is your new perimeter
One part of the legislation that’s easy to overlook: the security of your supply chain. You can have your own systems perfectly in order and still be vulnerable through a supplier, caterer, or maintenance party with access to your grounds or network. It’s precisely the companies in that chain that now face these obligations for the first time, and not everyone has the knowledge or the resources to pick that up right away.
How we help organizations: from measure to proof
We’re glad to think through the full breadth of (cyber) security with you, with one clear conviction: a measure you haven’t tested is an assumption. The law calls for demonstrable resilience, and demonstrable means proven under realistic conditions.
We work along two tracks that reinforce each other.
We select the right technology. Physical security starts with seeing what’s happening, everywhere, at all times. We help you choose and set up access and camera technology that fits your risk profile, such as the cloud-based video security platform from Verkada. Not a standalone box by the entrance, but one coherent overview across all your locations, where access, footage, and events come together. Technology is the means here, not the end. It’s about the certainty that you know what’s going on before it becomes an incident.
We test whether it really works. Technology alone is no proof. That’s why we have the actual resilience assessed independently with physical penetration tests, carried out by specialists from Strix Consulting. Just like the red teams from the Nieuwsuur broadcast, they try to get past your physical measures: through access, through processes, through people. What they find, you translate straight into concrete improvements. That way you know not only that your measures hold up on paper, but that they hold up when it counts.
From assumption to proof. From separate measures to demonstrable resilience. That’s what the law asks for, and what we build together with you.
What does this mean for your organization?
If you fall under the Cbw or the Wwke, the first step is an honest risk analysis: where are your digital and physical vulnerabilities, and what’s the societal impact if something goes wrong? From that picture, you put appropriate measures in place, record who’s responsible for what, and make sure the board can engage with the substance. And you test. Because compliance without testing is hoping it’s all fine.
We help you through that entire process, from technology choice to independent penetration test, so you can demonstrably comply with confidence..
Meer nieuws


