Resilt – From Resource to Wesource
← All news articles
August 21, 2026

Two resilience laws in force: what that means for your organisation

Since 15 August 2026 two laws affecting the resilience of organisations have been in force in the Netherlands: the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten, Wwke) and the Cybersecurity Act (Cyberbeveiligingswet, Cbw). The first is the Dutch implementation of the European CER Directive and covers physical and organisational resilience. The second implements NIS2 and covers digital resilience.

What the Wwke asks of you

Around 500 organisations will be designated as critical entities. Once designated, you have nine months to produce a risk assessment and ten months to put appropriate measures in place. Incidents with significant consequences must be reported within 24 hours.

What the Cybersecurity Act asks of you

The Cbw applies to organisations in eighteen sectors. You assess for yourself whether you fall under it, register in the national entity register, report incidents to the CSIRT, and make sure the board approves the measures and keeps its own knowledge up to date.

If both apply to you

Then both duties of care run alongside each other. The underlying analysis is largely the same: knowing what you depend on, what can fail and what you are doing about it. Do that once properly and you serve both frameworks, and ISO 22301 and the Denk Vooruit campaign along with them.

What Resilt does here

The Resilt Compass gives you the basis for your assessment: your dependencies, the threats bearing on them and the measures that follow, with a daily analysis and reports that show you are demonstrably in control. Alongside that we help with research, advice and support, and the Resilt Academy teaches your team to work with it.

See Compliance and policy delivery for the full explanation, or get in touch if you want to know where you stand.