Protect your business against physical and digital risks
Does your business provide services that have an essential role in the functioning of society or the economy? If so, you must protect your business against digital and physical threats, such as cybercrime, terrorist offences, or natural disasters.
Essential services
If your business comes to a standstill, for example because you have been hacked by cybercriminals, this can have serious consequences for society.
For example, if you have:
- a transport company that supplies supermarkets,
- a waste management company, or
- a metalworking company that supplies parts to larger machine manufacturers.
If your business belongs to an essential sector, you must comply with the requirements for physical and digital security. These requirements are set out in the Cybersecurity Act (Cyberbeveiligingswet, Cbw, in Dutch), the Network and Information Security directive (NIS2), the Critical Entities Resilience Act ( (Wet weerbaarheid kritieke entiteiten, Wwke, in Dutch), and the Critical Entities Resilience directive (CER directive).
When must you secure your business digitally?
Your business must comply with the digital security obligations if it:
- is a medium-sized organisation with 50–249 employees, has an annual turnover of between €10 million and €50 million, and a balance sheet total of between €10 million and €43 million, or
- is a large organisation with more than 250 employees, has a net turnover of more than €50 million and a balance sheet total of more than €43 million, or
- is a micro or small business that provides public electronic communications networks or services, provides trust services, provides domain name registration services, or operates a top-level domain name registry within the European Union.
Digital security is mainly about improving cyber security and protecting information. If your business has obligations under the Cybersecurity Act, it is classified as providing essential or important services. How strictly your business will be supervised depends on which of these 2 categories it belongs to. Whether your business is seen as essential or important depends on the sector to which it belongs.
Please note: Even if your micro or small business is not in a sector that is automatically covered by the Cybersecurity Act, the minister responsible can still decide that the rules apply to your business. In that case, you must meet the obligations. This can happen if a risk assessment finds that your services are vital to society or the economy. You will be notified if this is the case.
What should you do to ensure digital security?
If your business must comply with digital security obligations under the Cybersecurity Act, these include the following:
You must register with the National Cybersecurity Centre (NCSC, in Dutch) and keep your registration details up to date.
You must take suitable measures to manage risks to the security of your network and information systems (in Dutch). This includes carrying out a risk assessment. Responsibility lies with the organisation’s board. Board members must undergo training to ensure they have sufficient knowledge and skills regarding cyber security risks.
You must report serious incidents to the Cyber Security Incident Response Team (CSIRT, in Dutch) and the supervising authority as soon as possible, at most within 24 hours. Serious incidents are incidents that can significantly disrupt the provision of the essential services, can cause financial loss, or can cause significant damage to other organisations. You have to report via the MijnNCSC-portal (in Dutch). You need eHerkenning to log in.
Find a full overview of the digital security obligations at the National Coordinator for Counterterrorism and Security (Nationaal Coördinator Terrorismebestrijding en Veiligheid, NCTV, in Dutch).
Digital security monitoring
If your company is an important entity, you will only be inspected after an incident, or if there are indications that you have failed to comply with your obligations. Are you classified as an essential entity? In that case, the supervising authority will carry out proactive monitoring, even if there has been no incident or if there are no indications of misconduct.
The supervising authorities can differ by sector. Find out who is your supervising authority and in which situations this happens via the NCTV’s decision tree (in Dutch).
When should you physically secure your business?
Does your organisation provide services that are essential to the proper functioning of society or the economy? If your organisation operates within a critical sector (in Dutch), the responsible ministry may classify it as an critical entity. This means that your organisation has specific obligations to ensure that society or the economy is not put at risk in the event of a physical threat. If your business is classified as a critical entity, the relevant ministry will contact you.
Your company may be required to comply with physical security obligations if:
- energy
- drinking water
- transport
- digitale infrastructure
- food industry
- healthcare
- financial market infrastructure
- wastewater
- government services
- banking sector
- space activities
Please note: If the Ministry designates your company as a critical entity under the Critical Entities Resilience Act, your company is automatically also an essential entity under the Cybersecurity Act.
What do you need to ensure physical security?
If your organisation is classified as a critical entity under the Critical Entities Resilience Act, you have obligations to ensure physical security. Among others, you must:
Within 9 months of being designated, you must carry out and document your own risk assessment. This must cover all significant threats that could disrupt your service provision. These include terrorist offences, natural disasters, or public health emergencies.
Within 10 months of designation, you must take measures to enhance the physical security of your service. Among others, you must ensure the physical protection of buildings and critical infrastructure. You must prevent incidents from occurring, mitigate their consequences and, if an incident does occur, restore the service.
You must report incidents to the supervising authority as soon as possible. It concerns incidents that can significantly disrupt the provision of the critical service. You report this via the MijnNCSC-portal (in Dutch). Your report must clearly state the nature of the incident, as well as its impact, cause, and potential consequences.
View all physical security obligations on the NCTV website (in Dutch).
Monitoring physical security
The responsible ministries appoint supervisors to monitor the compliance of critical entities with their physical security obligations (in Dutch).
Amendments
The information on this page can change due to:
- Cybersecurity obligations for more companies in critical sectors (NIS2)Effective date: 15 August 2026
- CER directive protects critical infrastructure against physical risksEffective date: 15 August 2026