Supervision of digital resilience is essential for the Netherlands due to our digitized economy and increasing geopolitical threats. The supervisors on this digital resilience have decided to collaborate more intensively for effective and efficient oversight.
The resilience of vital processes and sectors is crucial for trust in our digital society and economy. Therefore, companies and public institutions are legally required to protect themselves against external disruptions and must be able to recover quickly after an incident. New European guidelines have been established to enhance digital resilience throughout the EU. In the Netherlands, these guidelines are being implemented in the form of the Cybersecurity Act (Cbw) and the Act on the Resilience of Critical Entities (Wwke).
Efficient and Decisive Oversight
Different supervisors are designated for these laws across various sectors. Since a company may fall under multiple sectors, they may have to deal with several supervisors. The supervisors are joining forces to work on efficient and decisive oversight.
They are working on a work plan with ambitions in various areas, including the harmonization of assessment frameworks so that supervisors deal with companies in the same manner. Through this harmonization and greater uniformity, there is more clarity for companies and public institutions that must comply with these laws. Moreover, the supervisors are thus better able to jointly provide insights based on concrete inspection results regarding the state of digital resilience of vital processes and sectors in the Netherlands.
Arno Faassen (NVWA - division head Customer, Business and Consumer):
By working together, we strengthen each other and learn from each others knowledge and experience. Thus, we join forces to enhance the digital resilience of the Netherlands.
Information Exchange Between Supervisors
Each supervisor will, of course, continue to operate within their own legal role, basis, and responsibility. They will investigate where the overlap in tasks lies and which supervisor has which powers under the new legislation. Additionally, they will examine whether and how they can exchange information within the legal frameworks and will look into which existing methods the different supervisors use and can share, so they can learn from each other.
More Information on the Implementation of the Law
The European guidelines are currently being translated into Dutch legislation by the Ministry of Justice and Security. More about the implementation of the new legislation can be found on the NCTV website: Cybersecurity Act and Act on the Resilience of Critical Entities. For the Cbw, two tools have been developed; use the NIS2 Self-assessment tool to estimate whether the organization falls under the European directive (NIS2) and do the NIS2 Quickscan to learn how well the organization is prepared for the arrival of NIS2. The NIS2 Quickscan is particularly intended for ICT and cybersecurity specialists and responsible parties within organizations.
About the Directors Consultation on Digital Resilience Oversight (DTDW)
Since the introduction of the Network and Information Systems Security Act (Wbni), supervisors on cybersecurity of vital processes have already been collaborating in the Working Together on Digital Resilience Oversight (STDW) consultation. With the introduction of the Cbw and Wwke, the National Digital Infrastructure Inspectorate (RDI) has taken the initiative to intensify collaboration and has established the Directors Consultation on Digital Resilience Oversight. They focus on executing effective oversight on the digital resilience of vital processes. In this consultation, the following supervisors collaborate;
- Authority for Nuclear Safety and Radiation Protection (ANVS)
- Data Protection Authority (AP)
- De Nederlandsche Bank (DNB)
- Health and Youth Care Inspectorate (IGJ)
- Inspectorate for the Environment and Transport (ILT)
- Inspectorate of Justice and Security (Inspectie JenV)
- Inspectorate of Education (IvhO)
- Dutch Food and Consumer Product Safety Authority (NVWA)
- National Digital Infrastructure Inspectorate (RDI)
- State Supervision of Mines (SodM)