The Wwke is the Dutch implementation of the European CER Directive (Directive (EU) 2022/2557 on the resilience of critical entities). The Act aims to maintain vital societal functions and economic activities by strengthening the resilience of critical entities and their ability to provide essential services.
Do you want to know exactly whether CER/Wwke applies to your organization, which obligations apply, and how you can prepare now? Download our factsheet for a clear explanation of all the rules, obligations, and the timeline.
Download factsheetThe Wwke is the Dutch implementation of the European CER Directive (Directive (EU) 2022/2557 on the resilience of critical entities). The Act aims to maintain vital societal functions and economic activities by strengthening the resilience of critical entities and their ability to provide essential services.
The Wwke is the physical counterpart to the Cybersecurity Act (Cbw/NIS2): while the Cbw focuses on digital resilience, the Wwke addresses all other risks and threats, such as natural disasters, sabotage, terrorism and hybrid threats. The Wwke expressly does not apply to matters covered by the Cybersecurity Act.
The Wwke applies to critical entities: entities designated as such by the competent authority because they provide one or more essential services within one of the sectors listed in the Annex to the Act.
Under the CER Directive on which the Wwke is based, an entity is designated as a critical entity when:
1. It provides an essential service in a sector listed in the Annex;
2. It operates on Dutch territory; and
3. An incident would have a significant disruptive effect on the provision of one or more essential services in the Netherlands or other Member States.
There are a few exceptions. Read more about this in our factsheet.
Critical entities report significant incidents to the competent authority. An incident is significant when it significantly disrupts or could significantly disrupt the provision of essential services. The specific thresholds and notification deadlines will be further specified by governmental decree or ministerial regulation.
Note: If an incident also constitutes a cyber incident, there may also be a notification obligation under the Cybersecurity Act. In the case of a data breach, the notification obligation to the Dutch Data Protection Authority (AP) applies as well.
The Dutch implementation of the European CER Directive, the Critical Entities Resilience Act (Wwke), will come into effect on August 15.
Organizations have to carry out a risk assessment of all relevant (non-cyber) risks that could disrupt essential services.
Organizations have to take appropriate and proportionate technical, security and organisational measures to prevent, protect, respond, withstand, mitigate, recover and adapt.
Organizations have to report incidents that significantly disrupt or could significantly disrupt the provision of essential services.
Organizations have to carry out background checks for certain positions (where provided for in further regulations).
Organizations have to designate a liaison officer to the competent authority.