Wwke and data centres — critical-entity obligations for digital infrastructure
Data centres already run mature access control — the Wwke makes physical resilience a statutory duty and pairs it with the Cyberbeveiligingswet. What changes and what to do now.
Digital infrastructure is one of the sectors designated under the Wet weerbaarheid kritieke entiteiten (Wwke), in force since 15 August 2026, and the EU CER framework it implements counts data-centre services within that sector. A data-centre operator designated as a critical entity must complete an all-hazards risk assessment within nine months of notification, implement proportionate technical, organisational and physical measures within ten months, and report incidents that disrupt or could significantly disrupt essential services within 24 hours — statutory physical duties that run in parallel with the cyber regime of the Cyberbeveiligingswet.
Why data centres sit inside the Wwke
The Wwke implements the EU CER-richtlijn, and digital infrastructure is among its designated sectors — the CER framework's digital-infrastructure sector covers, among others, providers of data-centre services. Roughly 500 Dutch organisations across all sectors are expected to fall under the law, designated individually by the responsible ministry. The point that matters for data-centre operators: this is the physical counterpart to the cyber rules. A Wwke-designated critical entity is automatically an essential entity under the Cyberbeveiligingswet, so the two regimes arrive together — one for the systems, one for the sites, the people and everything else the all-hazards standard covers.
Mature access control is not the same as statutory resilience
Data centres already run some of the most disciplined access control in private industry — mantraps, biometrics, visitor regimes, camera coverage. The Wwke changes the frame in three ways:
- From practice to legal obligation — the risk assessment, the measure set and the reporting duty become statutory, with the competent authority entitled to evidence rather than assurances.
- From access control to all-hazards — the assessment must cover deliberate physical attack, sabotage, insider action, natural hazards and dependency risk (power, cooling, connectivity, suppliers), not only who gets through the door.
- From incident handling to a 24-hour reporting clock — incidents that disrupt or could significantly disrupt essential services must reach the competent authority within 24 hours, which presupposes detection, verification and a decision point that works at 03:00.
The espionage dimension deserves specific attention. The AIVD reported in July 2026 that the Netherlands is a target of a Russian espionage operation exploiting internet-connected cameras — infrastructure most facilities operate in quantity. A defensible assessment treats installed technology, decision-making spaces and vendor access as part of the threat surface; where the risk profile warrants it, technical surveillance counter-measures belong in the measure set.
The compliance window, in sequence
Notification of designation starts the clock: nine months to the completed risk assessment, ten months to proportionate measures. The assessment is the schedule-critical document — build it early and to the all-hazards standard, and the measures deadline becomes a planning exercise. The methodology is covered in our guide to the all-hazards risk assessment.
What to do now
Map essential services to sites, systems, people and suppliers; assess against the full threat picture rather than the badge-reader perimeter; close the gaps in priority order. Mission Support supports digital-infrastructure operators with threat-led physical security assessment and protective design, counter-espionage sweeps and validation exercises, delivered by operators with governmental and defence backgrounds. For the regime as a whole, see the Wwke obligations explained.
Last reviewed: 25 August 2026. Orientation summary, not legal advice — the statutory text and your competent authority's guidance govern.
Frequently Asked
Request a Resilience Consultation
Operational engagements start with a vetted conversation. Mission Support responds inside one working day for governmental and Tier-1 enquiries.
Continue to service briefWwke en datacenters — verplichtingen voor digitale infrastructuur
Datacenters draaien al volwassen toegangscontrole — de Wwke maakt fysieke weerbaarheid een wettelijke plicht, parallel aan de Cyberbeveiligingswet. Wat er verandert en wat u nu doet.
Read next