The Digital Security Act: 7 requirements your business should implement
Back to Blog
The Digital Security Act in practice: 7 key areas your business should address
The Digital Security Act and the digital security regulations set out specific cyber security requirements for organisations providing critical services and digital operations. The regulations came into force on 1 October 2025, introducing requirements for management systems, risk assessments, security measures, incident response, and incident notification.
But where do you start?
We have analysed the Digital Security Act and its regulations, breaking the requirements down into 30 practical controls that you can easily track. Although the regulatory framework is extensive, much of the security work will feel familiar.
Here are seven areas we recommend starting with.
1. Clarify if your business is covered – and to what extent
The first step is to clarify whether the Digital Security Act applies to your organisation, and which services, systems, and business areas are in scope.
The act applies to providers of essential services in sectors such as energy, transport, healthcare, water supply, banking, financial market infrastructure, and digital infrastructure. It also covers specific providers of digital services. The digital security regulations define this scope in more detail.
For businesses within the scope, documenting this footprint is essential. Which services do you deliver? Which IT systems and suppliers do these services depend on? Which parts of your infrastructure are critical to operations?
This mapping forms the foundation for the rest of your security efforts.
2. Establish a digital security management system
The digital security regulations require providers of essential services to establish and maintain a security management system that covers digital security.
This should not be treated as a standalone security project run on the side. The management system must be integrated into your overall corporate governance.
Roles and responsibilities must be clearly defined and documented. Management must approve the system and review it at least once a year.
In practice, this means setting up:
clear roles and responsibilities
policies and governing documents
routines for monitoring and following up on security work
strong management buy-in
regular reviews and continuous improvement
In other words, your security efforts must be manageable, documented, and trackable over time.
3. Carry out risk assessments – and use them to prioritise
Risk assessments are a core requirement of the digital security regulations.
A risk assessment should be more than just a list of generic cyber threats. Your business needs to understand which specific incidents could impact your services, where your vulnerabilities lie, what the business consequences would be, and what dependencies you have.
This involves maintaining a clear overview of:
networks and information systems
relevant threats and incidents
vulnerabilities
potential business impact
dependencies on systems, people, and suppliers
The risk assessment should then be used to prioritise your security measures.
This is a crucial point. The goal is not simply to show a risk assessment during an audit. It must actively drive decisions on how your business manages risk.
4. Get the security basics in place
The digital security regulations require organisational, technical, physical, and personnel-related security measures.
On the technology side, this involves several standard practices that anyone working in information security will recognise.
Examples include:
access control and management
strong authentication
network segmentation
patching and vulnerability management
backup and disaster recovery
logging
security monitoring
capacity and resilience planning
The specific measures required depend on your risk profile. This is why risk assessments and security measures must be closely linked.
Securing the basics also involves people and organisation. Training, awareness programmes, clear accountability, confidentiality, and relevant staff processes are all part of the mix.
5. Keep control of suppliers and dependencies
Modern businesses rarely deliver services entirely on their own.
Cloud services, data centres, software vendors, consultants, and other third parties are often critical to keeping your services running. A security failure at a supplier can quickly become your own security incident.
Your business must map out key supplier dependencies and assess the associated risks.
This involves:
identifying critical suppliers
assessing supply chain risk
setting appropriate security requirements in contracts
monitoring and auditing compliance with these requirements
understanding dependencies and concentration risk
planning for the loss of critical suppliers
Supplier management should be an integrated part of your overall risk management, not a one-off exercise done only during procurement.
6. Prepare your business for when things go wrong
Good digital security is not just about preventing incidents.
Your business must also be able to detect, handle, and recover from them when they happen.
The digital security regulations mandate incident response and business continuity planning. In practice, this means your organisation needs an incident response plan, defined roles and responsibilities, clear communication channels, and recovery plans.
And these plans must be tested.
It is far easier to work out who does what before your systems go offline than during a live security incident.
7. Know your notification and reporting duties
The Digital Security Act and its regulations also introduce mandatory reporting for security incidents.
Your organisation must determine in advance which types of incidents trigger reporting duties, who is responsible for making this assessment, who needs to be notified, and how the necessary details will be gathered.
The same applies to your obligation to provide information to the authorities.
This should be built directly into your incident response plans – not something you start researching during a major crisis.
The Digital Security Act is about more than just compliance
The real benefit of the Digital Security Act and its regulations is that most of the work delivers value far beyond simple compliance.
An organisation that implements solid management systems, risk assessments, baseline security, supplier management, and incident response plans has also built a strong foundation for systematic information security.
This makes it much easier to adopt other security standards and frameworks.
There is significant overlap between the requirements of the Digital Security Act and frameworks like ISO/IEC 27001. While compliance with the Act does not automatically grant ISO 27001 certification, your documentation, risk assessments, management processes, and security controls can easily be reused.
As a result, your efforts yield multiple benefits: better visibility of business risks and dependencies, a more structured approach to security, stronger incident response, and a head start if you choose to pursue other standards or certifications later.
The Digital Security Act as a framework in Cyrigo
We have translated the Digital Security Act and its regulations into an actionable operational framework within Cyrigo.
The framework consists of 30 controls that allow you to track compliance, linking regulatory requirements directly to your policies, risk assessments, security measures, and other evidence of compliance.
The goal is not to generate endless compliance paperwork. It is to make it easy to see which requirements apply, what is already in place, and where your business still has work to do.
If your organisation is working on compliance with the Digital Security Act, you can read more about how Cyrigo supports security management, risk assessments, and compliance, or get in touch to see the framework in action.
Back to Blog