Want to know more? Download our factsheet

Do you want to know exactly whether CER/Wwke applies to your organization, which obligations apply, and how you can prepare now? Download our factsheet for a clear explanation of all the rules, obligations, and the timeline.

Download factsheet
CERWwke factsheet visual (ENG)

What is the Critical Entities Resilience Act (Wwke)?

The Wwke is the Dutch implementation of the European CER Directive (Directive (EU) 2022/2557 on the resilience of critical entities). The Act aims to maintain vital societal functions and economic activities by strengthening the resilience of critical entities and their ability to provide essential services.

The Wwke is the physical counterpart to the Cybersecurity Act (Cbw/NIS2): while the Cbw focuses on digital resilience, the Wwke addresses all other risks and threats, such as natural disasters, sabotage, terrorism and hybrid threats. The Wwke expressly does not apply to matters covered by the Cybersecurity Act.

Who does it apply to?

The Wwke applies to critical entities: entities designated as such by the competent authority because they provide one or more essential services within one of the sectors listed in the Annex to the Act.

Under the CER Directive on which the Wwke is based, an entity is designated as a critical entity when:

1. It provides an essential service in a sector listed in the Annex;

2. It operates on Dutch territory; and

3.  An incident would have a significant disruptive effect on the provision of one or more essential services in the Netherlands or other Member States.

There are a few exceptions. Read more about this in our factsheet.

CER/Wwke

Incident notification obligation

Critical entities report significant incidents to the competent authority. An incident is significant when it significantly disrupts or could significantly disrupt the provision of essential services. The specific thresholds and notification deadlines will be further specified by governmental decree or ministerial regulation.

Note: If an incident also constitutes a cyber incident, there may also be a notification obligation under the Cybersecurity Act. In the case of a data breach, the notification obligation to the Dutch Data Protection Authority (AP) applies as well.

When does the Wwke take effect?

The Dutch implementation of the European CER Directive, the Critical Entities Resilience Act (Wwke), will come into effect on August 15.

The main obligations for critical entities

1. Risk assessment

Organizations have to carry out a risk assessment of all relevant (non-cyber) risks that could disrupt essential services.

2. Resilience measures

Organizations have to take appropriate and proportionate technical, security and organisational measures to prevent, protect, respond, withstand, mitigate, recover and adapt.

3. Incident notification

Organizations have to report incidents that significantly disrupt or could significantly disrupt the provision of essential services.

4. Background checks

Organizations have to carry out background checks for certain positions (where provided for in further regulations).

5. Contact person

Organizations have to designate a liaison officer to the competent authority.

Would you like more information or do you have questions?

Leave a message via the form. One of our legal advisors will then contact you.


When you submit a request to us, we always start with a no-obligation introductory meeting: by phone, at our office, or at your location.

Submit your details