The Digital Security Act: 7 requirements your business should implement

Back to Blog

The Digital Security Act in practice: 7 key areas your business should address

The Digital Security Act and the digital security regulations set out specific cyber security requirements for organisations providing critical services and digital operations. The regulations came into force on 1 October 2025, introducing requirements for management systems, risk assessments, security measures, incident response, and incident notification.

But where do you start?

We have analysed the Digital Security Act and its regulations, breaking the requirements down into 30 practical controls that you can easily track. Although the regulatory framework is extensive, much of the security work will feel familiar.

Here are seven areas we recommend starting with.

1. Clarify if your business is covered – and to what extent

The first step is to clarify whether the Digital Security Act applies to your organisation, and which services, systems, and business areas are in scope.

The act applies to providers of essential services in sectors such as energy, transport, healthcare, water supply, banking, financial market infrastructure, and digital infrastructure. It also covers specific providers of digital services. The digital security regulations define this scope in more detail.

For businesses within the scope, documenting this footprint is essential. Which services do you deliver? Which IT systems and suppliers do these services depend on? Which parts of your infrastructure are critical to operations?

This mapping forms the foundation for the rest of your security efforts.

2. Establish a digital security management system

The digital security regulations require providers of essential services to establish and maintain a security management system that covers digital security.

This should not be treated as a standalone security project run on the side. The management system must be integrated into your overall corporate governance.

Roles and responsibilities must be clearly defined and documented. Management must approve the system and review it at least once a year.

In practice, this means setting up:

  • clear roles and responsibilities

  • policies and governing documents

  • routines for monitoring and following up on security work

  • strong management buy-in

  • regular reviews and continuous improvement

In other words, your security efforts must be manageable, documented, and trackable over time.

3. Carry out risk assessments – and use them to prioritise

Risk assessments are a core requirement of the digital security regulations.

A risk assessment should be more than just a list of generic cyber threats. Your business needs to understand which specific incidents could impact your services, where your vulnerabilities lie, what the business consequences would be, and what dependencies you have.

This involves maintaining a clear overview of:

  • networks and information systems

  • relevant threats and incidents

  • vulnerabilities

  • potential business impact

  • dependencies on systems, people, and suppliers

The risk assessment should then be used to prioritise your security measures.

This is a crucial point. The goal is not simply to show a risk assessment during an audit. It must actively drive decisions on how your business manages risk.

4. Get the security basics in place

The digital security regulations require organisational, technical, physical, and personnel-related security measures.

On the technology side, this involves several standard practices that anyone working in information security will recognise.

Examples include:

  • access control and management

  • strong authentication

  • network segmentation

  • patching and vulnerability management

  • backup and disaster recovery

  • logging

  • security monitoring

  • capacity and resilience planning

The specific measures required depend on your risk profile. This is why risk assessments and security measures must be closely linked.

Securing the basics also involves people and organisation. Training, awareness programmes, clear accountability, confidentiality, and relevant staff processes are all part of the mix.

5. Keep control of suppliers and dependencies

Modern businesses rarely deliver services entirely on their own.

Cloud services, data centres, software vendors, consultants, and other third parties are often critical to keeping your services running. A security failure at a supplier can quickly become your own security incident.

Your business must map out key supplier dependencies and assess the associated risks.

This involves:

  • identifying critical suppliers

  • assessing supply chain risk

  • setting appropriate security requirements in contracts

  • monitoring and auditing compliance with these requirements

  • understanding dependencies and concentration risk

  • planning for the loss of critical suppliers

Supplier management should be an integrated part of your overall risk management, not a one-off exercise done only during procurement.

6. Prepare your business for when things go wrong

Good digital security is not just about preventing incidents.

Your business must also be able to detect, handle, and recover from them when they happen.

The digital security regulations mandate incident response and business continuity planning. In practice, this means your organisation needs an incident response plan, defined roles and responsibilities, clear communication channels, and recovery plans.

And these plans must be tested.

It is far easier to work out who does what before your systems go offline than during a live security incident.

7. Know your notification and reporting duties

The Digital Security Act and its regulations also introduce mandatory reporting for security incidents.

Your organisation must determine in advance which types of incidents trigger reporting duties, who is responsible for making this assessment, who needs to be notified, and how the necessary details will be gathered.

The same applies to your obligation to provide information to the authorities.

This should be built directly into your incident response plans – not something you start researching during a major crisis.

The Digital Security Act is about more than just compliance

The real benefit of the Digital Security Act and its regulations is that most of the work delivers value far beyond simple compliance.

An organisation that implements solid management systems, risk assessments, baseline security, supplier management, and incident response plans has also built a strong foundation for systematic information security.

This makes it much easier to adopt other security standards and frameworks.

There is significant overlap between the requirements of the Digital Security Act and frameworks like ISO/IEC 27001. While compliance with the Act does not automatically grant ISO 27001 certification, your documentation, risk assessments, management processes, and security controls can easily be reused.

As a result, your efforts yield multiple benefits: better visibility of business risks and dependencies, a more structured approach to security, stronger incident response, and a head start if you choose to pursue other standards or certifications later.

The Digital Security Act as a framework in Cyrigo

We have translated the Digital Security Act and its regulations into an actionable operational framework within Cyrigo.

The framework consists of 30 controls that allow you to track compliance, linking regulatory requirements directly to your policies, risk assessments, security measures, and other evidence of compliance.

The goal is not to generate endless compliance paperwork. It is to make it easy to see which requirements apply, what is already in place, and where your business still has work to do.

If your organisation is working on compliance with the Digital Security Act, you can read more about how Cyrigo supports security management, risk assessments, and compliance, or get in touch to see the framework in action.

Back to Blog