What is CERT-WM?

CERT-WM (CERT Watermanagement) is the joint cyber security team of the 21 Dutch water boards (waterschappen), hosted by Het Waterschapshuis and, since 15 August 2026, the legally designated CSIRT for the water boards under the Dutch Cybersecurity Act. The team warns about vulnerabilities, advises during incidents and can be reached around the clock when the digital control of pumping stations, weirs or wastewater treatment plants is at risk. For what a CERT or CSIRT is in general, see those articles; this one covers the specific role CERT-WM plays in Dutch water management.


🕰️ How did CERT-WM come about?

CERT-WM was established on 1 October 2016, with Het Waterschapshuis (the water boards’ shared ICT organisation) and Rijkswaterstaat (the national public works and water agency) as host organisations. It grew out of the joint information security programme the water boards had been running since 2013, and by 1 January 2017 every water board was connected.

Year Milestone
2016 Founded on 1 October by Het Waterschapshuis and Rijkswaterstaat
2017 All water boards connected (1 January)
2018 Listed in the Trusted Introducer directory of European CSIRTs (31 January)
2018–2026 Designated CSIRT for the water boards under the Wbni, the Dutch NIS1 law
2023 The Ministry of Infrastructure and Water Management explores a wider “CERT Water” for water boards, Rijkswaterstaat and drinking water companies
2024 Trusted Introducer accreditation (3 December)
2026 Designation as CSIRT under the Cybersecurity Act (15 August) and admission to FIRST

The link with Rijkswaterstaat remains: CERT-WM works closely with the Rijkswaterstaat Security Operations Centre and is funded by Het Waterschapshuis, with Rijkswaterstaat as sponsor.


🧱 Who does CERT-WM serve?

CERT-WM’s constituency consists of the 21 water boards, plus Het Waterschapshuis, the Dutch Association of Water Boards (Unie van Waterschappen) and a few service providers and knowledge institutes in the sector. The team covers national water management and wastewater treatment; drinking water companies are explicitly outside its scope.

Rijkswaterstaat is a partner and co-founder, but not part of the statutory constituency: for Rijkswaterstaat and the drinking water companies, the NCSC is the CSIRT. A water board also falls into several sectors of the act at once: flood defence and water management, transport (road management), wastewater and public administration. CERT-WM acts as CSIRT for the water boards in all of those roles. For the wider sector picture, see Water Sector OT Security.


⚖️ Is CERT-WM a legally designated CSIRT?

Yes. Article 2(1) of the Cybersecurity Decree designates the Minister of Justice and Security as CSIRT, which in practice means the NCSC. Article 2(2) lets a sector minister appoint a different body for a given sector. The Minister of Infrastructure and Water Management did exactly that in Article 3 of the Cybersecurity Regulation IenW (Government Gazette 2026, no. 24093): CERT-WM becomes the CSIRT for the water boards.

The designation comes with obligations:

  • Annual report — by 31 December each year CERT-WM reports to the minister on how it carried out its CSIRT tasks
  • Maturity — the team must operate at least at intermediate level of the Security Incident Management Maturity Model (SIM3)
  • Audit — an independent, qualified expert assesses that level, and the audit report may be no more than three years old
  • Improvement plan — if the level slips, CERT-WM submits an improvement plan to the minister

According to CERT-WM itself, this makes the water boards the first, and so far the only, sector with its own legally recognised sectoral CSIRT. In healthcare, Z-CERT had not yet been formally designated when the act took effect: the health minister intends to do so, but until then the NCSC acts as CSIRT.


🔧 Which services does CERT-WM provide?

Service What it involves
Security advisories Tailored warnings about vulnerabilities and patches, based on threat intelligence
Incident advice Triage, classification and coordination; CERT-WM acts as a third-line partner alongside the water board’s own IT and OT teams
On-call service Reachable 24/7 for urgent situations; otherwise office hours on working days from 08:30 to 17:00
CVD reports Handling vulnerability reports about water board systems through coordinated vulnerability disclosure
Vulnerability scanning Scanning and monitoring of the constituency’s internet-facing systems
Forensic investigation Forensic analysis and malware analysis after an incident
Open standards monitoring Checking how open standards are applied on constituency systems
Secure communication and information Contact lists, encrypted exchange, knowledge sharing and developing detection use cases for SOCs

CERT-WM is therefore not a full OT SOC watching every water board’s networks around the clock; it provides expertise, warnings and coordination on top of each water board’s own monitoring.


🏭 Why does OT knowledge matter so much for CERT-WM?

A water board controls hundreds of remote sites through SCADA, PLCs and telemetry. An attack that stops pumps or mis-steers a weir directly threatens flood protection and wastewater treatment. When explaining the designation, the ministry pointed to exactly that sector knowledge: CERT-WM understands the structures and processes of the water sector, so scarce process automation expertise stays within the sector.

The team aligns with the CSIR, the cyber security implementation guideline that Rijkswaterstaat and Het Waterschapshuis wrote together on the basis of the BIO and IEC 62443. It was written for assets such as pumping stations, treatment plants, bridges and locks; version 3.0 widens its scope to all partners in the national Water Governance Agreement (Bestuursakkoord Water) and other public bodies that use process automation. Threats such as CyberAv3ngers, who took over internet-connected PLCs at water utilities in 2023, show why that OT focus is not theoretical.


🔄 How does CERT-WM compare with the NCSC, Z-CERT and a commercial SOC?

Feature CERT-WM NCSC Z-CERT Commercial SOC
Constituency 21 water boards Central government and most sectors Healthcare institutions Paying customers
Legal status (Aug 2026) Designated CSIRT for water boards Default CSIRT under the act Designation intended, not yet formal None
Joining No sign-up needed; CSIRT by designation CSIRT by default where no other is designated Voluntary membership Contractual
Own 24/7 monitoring No; supports and coordinates No No Yes, core product
OT sector knowledge Pumping stations, locks, treatment plants Generic Medical equipment Varies

A commercial SOC and CERT-WM complement each other: the SOC detects, CERT-WM interprets, warns the sector and liaises with the NCSC.


🛠️ How does a water board work with CERT-WM during an incident?

Take an example: at night, the SCADA control centre sees unexplained control commands being sent to a sewage pumping station.

  1. Detect and interpret — the on-call engineer or the water board’s SOC spots the anomaly and starts the internal incident response process
  2. Engage CERT-WM — when primary processes are directly affected, you call the on-call service; CERT-WM helps with triage and matches indicators against what is happening elsewhere in the sector
  3. Contain — switch the pumping station to local control, isolate the connection and preserve logs for forensic investigation
  4. Assess significance — for the water board subsector (public administration sector), an incident is significant if it leads or may lead to at least four hours of service disruption, financial consequences the budget cannot absorb, or serious injury or death
  5. Report — you report a significant incident through the central reporting point: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month (see Cybersecurity Act Incident Reporting)
  6. Warn the sector — CERT-WM shares relevant indicators with the other water boards and liaises with the NCSC
  7. Learn — review the incident and rehearse the scenario in a tabletop exercise

❓ Frequently asked questions

What is CERT-WM?

CERT-WM (CERT Watermanagement) is the cyber security team of the Dutch water boards, founded on 1 October 2016 and hosted by Het Waterschapshuis. CERT-WM issues vulnerability warnings, supports incident handling and has been the legally designated CSIRT for the water boards since 15 August 2026.

Who is CERT-WM for?

CERT-WM serves the 21 Dutch water boards, together with Het Waterschapshuis, the Unie van Waterschappen and a few service providers in the sector. Drinking water companies and Rijkswaterstaat are not covered by CERT-WM; for them the NCSC is the CSIRT.

Is it mandatory to join CERT-WM?

A water board does not have to sign up separately: the Cybersecurity Regulation IenW designates CERT-WM as CSIRT for all water boards. The reporting obligation of the Cybersecurity Act does apply to each water board itself, and significant incidents are reported through the central reporting point.

What is the difference between CERT-WM and the NCSC?

CERT-WM is the sectoral CSIRT for the Dutch water boards, with specific knowledge of pumping stations, locks and treatment plants. The NCSC is the default CSIRT for most other organisations under the Cybersecurity Act, including Rijkswaterstaat and the drinking water companies. CERT-WM and the NCSC exchange threat intelligence and coordinate during major incidents.

How does a water board contact CERT-WM?

During office hours a water board contacts CERT-WM through the regular channels listed on the team’s website. For urgent incidents that directly affect primary processes, CERT-WM is available 24/7 through its on-call service. Record those contact details in your incident response plan in advance.

Which requirements must CERT-WM meet?

As a designated CSIRT, CERT-WM must reach at least the intermediate level of the SIM3 maturity model, demonstrated by an independent audit no more than three years old. CERT-WM also reports to the Minister of Infrastructure and Water Management every year by 31 December.


📌 In summary

CERT-WM has been the cyber security team of the 21 Dutch water boards since 2016 and, since 15 August 2026, their legally designated CSIRT under the Cybersecurity Act. The team combines advisories, incident support and a 24/7 on-call service with knowledge of the OT behind pumping stations, locks and treatment plants, while the NCSC remains the CSIRT for Rijkswaterstaat and the drinking water companies.