It is Tuesday morning, 07:42am. In the control room of a regional grid operator, an alert comes in: the customer portal is running slow and part of the monitoring system has dropped out, including telemetry from several unmanned substations. The SOC picks it up, examines the logs and considers the possibility of a cyber attack. The on-call CISO is informed and the incident-notification clock starts ticking, just in case.
Sixty kilometres away, a field technician reports something else that morning: at an unmanned substation, the perimeter fence is open and a control cabinet has been forced. Probably copper theft, he thinks (it happens). The report goes to facilities management; the police file a report.
Two reports, two systems, two managers. Both are handled according to their own playbook. That they occur at the same time, in the same area, goes unnoticed: the information sits in different heads, and no one has the task of comparing the two.
This scenario is fictitious, but the threat is anything but. That is precisely why two laws enter into force simultaneously on 15 August 2026: the Cyberbeveiligingswet (Cbw) and the Wet weerbaarheid kritieke entiteiten (Wwke). Together they form the legislature's response to a threat that ignores the boundary between digital and physical. Yet many organisations treat both laws as separate workstreams. This blog explains why that is a blind spot.
All eyes are on the Cbw, and understandably so. The law directly affects some 8,000 to 9,000 organisations, and many more indirectly through the supply chain. The fact that the Wwke enters into force on the very same day, however, is no coincidence. It is a deliberate choice by the European legislator: now that organisations work in hybrid ways, threats have become hybrid too.
The NIS2 Directive (implemented through the Cbw) and the CER Directive (implemented through the Wwke) are sister directives. Both strengthen the resilience of critical sectors: one digitally, the other physically.
The Cbw designates 18 critical sectors (17 from Annexes I and II, plus higher education). The Wwke covers 11. The overlap is substantial: energy, transport, drinking water, healthcare and government all fall under both regimes. There are, however, differences:
Scope: the Cbw focuses on cyber; the Wwke addresses physical security, personnel, continuity and supply-chain dependencies.
Application: under the Cbw you assess for yourself whether you fall within scope. Under the Wwke you are designated by the minister. Once designated, you automatically fall under the Cbw as well, regardless of organisation size.
Obligations: risk assessment, duty of care, incident reporting and supervision feature in both laws, each with its own deadlines and emphases.
Despite the overlap, the Wwke receives remarkably little attention. There are two reasons for this.
First, the law does not lend itself to product sales. As long as organisations have not been designated, the market does not know who the target audience is. Moreover, the Wwke concerns fencing, screening, crisisplans and redundant processes (less "sexy" than a dashboard or e-learning).
Second, NIS2 has an enormous marketing machine behind it: vendors, tooling, consultants and mandatory board-level training. Add to this that CISOs typically have a seat at the boardroom table, whereas the facilities manager or BCM-lead seldom does, and often lacks the expertise to implement the Wwke.
On top of that, many organisations believe they have already covered physical security. After all, physical measures are an explicit part of ISO 27001 and NEN 7510. In practice, however, that chapter is often placed out of scope with the argument: "physical means the data centre, and we have a supplier for that." That reasoning falls short. Your office needs to be secured too, as does your server room and your laptops. Cyber security is incomplete without physical risks, and that is written in black and white in the standards many organisations have followed for years. The Wwke simply makes that obligation more explicit and extends it to continuity, personnel and the supply chain.
The result: organisations build a splendid cyber house on a physically shaky foundation.
Current events underline why that separation is dangerous. Drone incidents at airports and power stations. Sabotage of cables and pipelines in the North Sea. State actors attacking both IT and OT. Insiders who exploit both physical and digital access.
Yet we continue to work in separate domains. The CISO sees the digital trail; the facilities manager sees the physical one. Meanwhile, incidents are deliberately timed to coincide, overloading detection and response. A digital disruption can trigger physical consequences, and vice versa.
An attacker does not think in chapters of legislation. Your defence should not do so either.
Opt for an integrated approach; it is more efficient even if you do not need to comply with both laws. Five concrete steps:
One integrated risk assessment covering both cyber and physical risks.
One governance structure: avoid separate Cbw and Wwke steering groups.
Joint incident response: cyber SOC and physical security on the same on-call rota.
Harmonised notification duties: prevent the same incident from being reported differently through two channels.
Broadened supply-chain analysis: supplier risks are never purely digital or purely physical.
15 August 2026 is not a cyber deadline. It is a resilience deadline. The question is not whether your organisation is Cbw and Wwke compliant. The question is whether your organisation will survive a coordinated, hybrid attack on 16 August 2026.
Would you like to know what NIS2 mean for your organisation in practice and how to comply with the requirements? During our NIS2-compliance training, you’ll gain practical guidance on how to translate these requirements into your organisation.