Resilt – From Resource to Wesource
Compliance and policy delivery

Meeting the duty of care, from the Wwke to ISO 22301

Since 15 August 2026, two laws have been in force: the Cybersecurity Act, the Dutch implementation of NIS2, and the Wwke, the Dutch Critical Entities Resilience Act, which implements the European CER Directive. Here you can read what they ask of you, how they relate to ISO 22301 and the Denk Vooruit campaign, and what the Resilt Compass™ does within that.

What applies since 15 August 2026

Two laws in force at the same time, with different scopes but the same foundation: knowing what you depend on, knowing what can go wrong, taking measures and being able to demonstrate it.

Wwke

The Wwke

The Dutch implementation of the European CER Directive (Critical Entities Resilience Directive, CERD). Around 500 organisations will be designated as a critical entity by their responsible ministry. Once designated, you have nine months for the risk assessment, ten months for appropriate technical, organisational and physical measures, and you report disruptive incidents within 24 hours.

NIS2

The Cybersecurity Act

The Dutch implementation of NIS2, covering essential and important services in eighteen sectors. You determine for yourself whether you fall under it, register in the national entity register, take appropriate measures for your network and information systems, and report significant incidents to your CSIRT. The board approves the measures and completes training for that purpose.

Both

Do both apply to you

Then it is not double the work. The risk assessment, the measures and the notification chain come from the same basis. You set it up once and report per framework.

Resilt does not certify, does not audit, does not give legal advice and does not report on your behalf. The Compass supplies the file and tracks the deadline, you submit it.

Four frameworks, one approach

The Compliance tier of the Resilt Compass is built on the four frameworks that run into each other in practice. You work in one environment and report per framework.

Wwke and CERD

Designated critical entities

Dependencies and valued assets as the basis for the risk assessment, measures as tasks with an owner, the notification chain tracked and the file demonstrable. More detail on the page about the Wwke.

NIS2

Digital duty of care

The same cycle, with the digital threat layer added: malware, data breaches, targeted attacks, denial of service, supply chain attacks and phishing. Reporting to the standards the regulator expects.

ISO 22301

Business continuity management

Impact analysis, continuity plans with a template, exercises and the trail that shows they are being maintained. Paper becomes practice because the plan moves with what changes in your environment.

Denk Vooruit

Policy delivery in your area

For municipalities, safety regions and business associations that bring the national campaign to their area: the playbook that entrepreneurs complete, the workshop, the e-learning and Denk Vooruit for collectives.

In procurement by critical entities, the GDPR, BIO 2.0, ISO 27001 and the CRA also come into play. The data processing agreement and its annexes belong to the Enterprise tier.

How the Compass supports the duty of care

The Compass follows the ISAFE method. Each step delivers part of the evidence you need for the regulator.

Identify

The basis for your assessment

Services, locations, assets, suppliers and dependencies in view, supplemented from the Resilt Database. Without that overview, a well founded risk assessment is not possible.

Signal

Visibility of threats and outages

Disruptions and threats linked to your own objects, so you notice what affects you and not only what is happening somewhere.

Alert

Reporting on time

Support with the notification chain and the deadlines, so a notification goes out on time and the file is correct.

Fortify

Measures that actually happen

Appropriate measures as tasks with an owner and a date, plus continuity plans that stay current.

Evolve

Demonstrably in control

Exercising, evaluating, building scenarios and benchmarking against comparable organisations, anonymised and aggregated.

Knowledge and guidance are part of it: the Resilt Academy for your team, and research, advice and support if you would rather start together with us.

Be ready before the clock starts

Have you been designated as a critical entity, or do you expect to be? Book a call and we will go through the deadlines and the first steps together.

Book a call