Since 15 August 2026, two laws have been in force: the Cybersecurity Act, the Dutch implementation of NIS2, and the Wwke, the Dutch Critical Entities Resilience Act, which implements the European CER Directive. Here you can read what they ask of you, how they relate to ISO 22301 and the Denk Vooruit campaign, and what the Resilt Compass™ does within that.
Two laws in force at the same time, with different scopes but the same foundation: knowing what you depend on, knowing what can go wrong, taking measures and being able to demonstrate it.
The Dutch implementation of the European CER Directive (Critical Entities Resilience Directive, CERD). Around 500 organisations will be designated as a critical entity by their responsible ministry. Once designated, you have nine months for the risk assessment, ten months for appropriate technical, organisational and physical measures, and you report disruptive incidents within 24 hours.
The Dutch implementation of NIS2, covering essential and important services in eighteen sectors. You determine for yourself whether you fall under it, register in the national entity register, take appropriate measures for your network and information systems, and report significant incidents to your CSIRT. The board approves the measures and completes training for that purpose.
Then it is not double the work. The risk assessment, the measures and the notification chain come from the same basis. You set it up once and report per framework.
Resilt does not certify, does not audit, does not give legal advice and does not report on your behalf. The Compass supplies the file and tracks the deadline, you submit it.
The Compliance tier of the Resilt Compass is built on the four frameworks that run into each other in practice. You work in one environment and report per framework.
Dependencies and valued assets as the basis for the risk assessment, measures as tasks with an owner, the notification chain tracked and the file demonstrable. More detail on the page about the Wwke.
The same cycle, with the digital threat layer added: malware, data breaches, targeted attacks, denial of service, supply chain attacks and phishing. Reporting to the standards the regulator expects.
Impact analysis, continuity plans with a template, exercises and the trail that shows they are being maintained. Paper becomes practice because the plan moves with what changes in your environment.
For municipalities, safety regions and business associations that bring the national campaign to their area: the playbook that entrepreneurs complete, the workshop, the e-learning and Denk Vooruit for collectives.
In procurement by critical entities, the GDPR, BIO 2.0, ISO 27001 and the CRA also come into play. The data processing agreement and its annexes belong to the Enterprise tier.
The Compass follows the ISAFE method. Each step delivers part of the evidence you need for the regulator.
Services, locations, assets, suppliers and dependencies in view, supplemented from the Resilt Database. Without that overview, a well founded risk assessment is not possible.
Disruptions and threats linked to your own objects, so you notice what affects you and not only what is happening somewhere.
Support with the notification chain and the deadlines, so a notification goes out on time and the file is correct.
Appropriate measures as tasks with an owner and a date, plus continuity plans that stay current.
Exercising, evaluating, building scenarios and benchmarking against comparable organisations, anonymised and aggregated.
Knowledge and guidance are part of it: the Resilt Academy for your team, and research, advice and support if you would rather start together with us.
Have you been designated as a critical entity, or do you expect to be? Book a call and we will go through the deadlines and the first steps together.
Book a call