Cybersecurity Act in effect: from established policy to practical application

Jasper Peterse

Jasper Peterse

August 18, 2026

min read

Linkedin

Share the article:

Cybersecurity Act in effect: from established policy to practical application

The Cyber Security Act (Cbw) and the Resilience of Critical Entities Act (Wwke) are now in effect. For many organizations, the foundation is already in place: policies have been drafted, risk analyses conducted, and processes documented within an Information Security Management System (ISMS).

That is exactly when the reality of implementation becomes clear. Many of those documented processes still rely on manual controls, physical identity checks, and administrative tasks. After all the preparations, you are compliant. But in daily operations, it primarily means extra work, every single day.

Two laws, one practical challenge

The Cbw sets requirements for managing risks related to system and data access. For critical entities, the Wwke goes a step further: it explicitly requires attention to the security of physical locations and due diligence regarding personnel with access to sensitive areas.

These two converge on one question: who is this person, and where are they allowed to go? In most organizations, this question is still answered manually. A receptionist checking an ID card. A list of registered contractors that someone has to cross-reference.

That is not a flaw in your policy. It is an operational challenge.

From administrative burden to automated assurance

Speed without compromise
Automated identity verification accelerates the onboarding of employees, contractors, and visitors, strictly within the frameworks you have established, not around them.

Demonstrably in control
The digital process automatically records who was verified, when, and what access they were granted. No need for retrospective reconstruction or digging through paper files when the auditor arrives.

Reduced operational pressure
Security teams and reception staff work via a single, consistent digital workflow instead of manual administration and fragmented checks.

How BPI Services can help

The Cbw and Wwke require a seamless connection between physical and digital security. We help organizations digitize their documented identity and access processes, ensuring that the frameworks in your ISMS are effortlessly upheld in daily practice. From automated identity verification to visitor registration and access management.

From duty of care to a workable process

The policy is ready and the framework is in place. The question for the coming period is how to set up those controlled processes as smartly and practically as possible, for your own staff and for everyone who enters your building.

Do you want to discover how to digitize and optimize your identity verification process? Then please contact us for a consultation.

Safety and compliance

Data is securely stored in Europe and processed in full compliance with GDPR regulations. Our software undergoes regular penetration testing and meets the highest security standards.

NEN 7510

We are NEN 7510 certified, the Dutch standard for information security in healthcare.

ISO 9001 & ISO 27001

Certified to ISO 9001 and ISO 27001. All data stored and processed within Europe, in accordance with the GDPR.

Schedule an appointment with David
Sales contact