Independent knowledge collective for digital infrastructure in real estate
IT-Label

Request an IT-Label

Leave your details and we will get in touch to walk through the process.

Classifications IT1+ – IT1 – IT2 – IT3 – IT4 – IT5

NIS2 and real estate: how resilient is your building?

The Cyber Security Act does not stop at the laptop, it continues into the server room of your building.

Insights··8 min read
NIS2 and real estate: how resilient is your building?

Key Takeaways

  • The Dutch Cyber Security Act, the implementation of the European NIS2 directive, brings with it a duty of care, a registration obligation, a reporting obligation and board-level responsibility, among other things.
  • The duty of care does not only concern network and information systems, but also the physical environment in which those systems are located.
  • Many building-bound digital risks remain invisible because no one investigates them at the time of purchase or leasing, while energy and construction are checked as a matter of course.
  • With a Digital Due Diligence, IT-Label makes clear what a building can digitally handle and who is responsible for what.
  • The IT-Label is not an NIS2 certification and does not guarantee legal compliance, but it does help make building-bound risks a topic for discussion.

The firewall is in order. MFA is switched on. Employees receive annual security training. But the door to the server room? It just stands open, with three different parties walking in and out for various reasons. In many buildings this is not the exception, it is the normal state of affairs.

Cybersecurity is almost always approached from the software side: firewalls, passwords, cloud environments and employee behavior. That is understandable, but it is not the whole story. An organization's digital infrastructure sits somewhere, literally. In a patch cabinet, a technical room, a bundle of cabling and a connection entering the building. That physical layer rarely receives the same attention.

With the arrival of the Dutch Cyber Security Act, that blind spot becomes more relevant. The central question of this article is therefore simple: NIS2 does not stop at your laptop, so how digitally resilient is the building your organization works in?

What the Cyber Security Act broadly requires

The Dutch Cyber Security Act is the national implementation of the European NIS2 directive and has been in force since 15 August 2026. The act applies to organizations in sectors designated as essential or important. Not every business falls under it, and it is wise to consult the official information from the Dutch government and the NCSC to determine whether your organization falls within scope.

For organizations that do fall under the act, several core obligations come into view. In short, these involve a duty of care, a registration obligation, a reporting obligation for incidents and board-level responsibility. The latter stands out: digital resilience explicitly becomes a topic for the board, not just for the IT department.

Regarding the duty of care, the NCSC mentions risk analysis, incident response, preparation for outages, secure supply chains, security of network and information systems, access control and asset management, among other things. And here lies the core issue for the real estate sector: the NCSC does not speak only of the systems themselves, but also of the physical environment in which those systems are located.

Where the act touches the building

You can configure your firewall perfectly, but what good does that do if someone can physically reach your switch, server, fiber connection or patch cabinet? Access control and asset management are about more than a login screen. They also concern who can open a door and exactly what equipment is hanging in a technical room.

In practice, we encounter situations in buildings that suddenly carry different weight from this perspective:

  • A server room accessible to multiple parties, without any record of who was in there and when.
  • Patch cabinets that cannot be locked, or whose key is held by everyone.
  • Old switches, routers or 4G/5G modems that no one remembers the ownership of.
  • Building management systems and cameras that are externally accessible and sit on the same network as the business operations.
  • Unregistered IoT equipment quietly communicating with the internet.
  • A single internet connection without redundancy, outdated CAT cabling, or a network structure no one can chart anymore.
  • Fiber connections where it is unclear who the owner or manager is.

What these examples have in common is that they rarely appear in documentation. There is no up-to-date map of the network components, and responsibilities between landlord, tenant, property manager and IT supplier are not clearly assigned. A technical room where a malicious actor can easily reach network hardware is not a theoretical risk then, it is an open back door.

The best firewall in the country stops no one who can simply push open the door to the server room.

Why this is a real estate matter

When leasing or buying a building, extensive research is carried out. The energy label, fire safety, installations, construction and technical condition are all reviewed. What is almost never examined is what the building can digitally handle. Yet an organization that cannot connect to cloud applications, telephony, payment systems or production environments can be partially or fully at a standstill within minutes.

For many organizations, internet and digital infrastructure have become just as essential as electricity and water. Still, the server room rarely appears on the technical due diligence checklist. This creates a gap between what an organization legally and operationally needs, and what is actually present in the building.

IT-Label therefore believes that digital infrastructure should become part of the technical due diligence process when purchasing, leasing and redeveloping commercial real estate. This raises several questions that would otherwise go unanswered:

  • What are you actually buying or renting digitally, and what can the building digitally handle?
  • Is the building AI-proof, and can the infrastructure support the organization's future data consumption?
  • How quickly can a business become operational again when network hardware, cabling or internet connections fail or are sabotaged?
  • Who is responsible for which part of the digital infrastructure: the tenant or the landlord?

That last question belongs in the demarcation list between parties. In many lease agreements, however, the division of responsibilities around IT is not explicitly arranged, creating uncertainty at precisely the moment it matters most.

Curious about your building's IT-label?

Discover how your property scores on digital infrastructure.

Request IT-label

Continuity as part of the duty of care

The duty of care requires, among other things, preparation for outages and incident response. Translated to a building, this means: if the only internet connection fails, or if someone can physically reach the network hardware, how long will the organization be at a standstill? And do you know this in advance, or do you find out only during the incident?

Continuity is not an abstract concept. It is the difference between an outage absorbed within a few minutes by a second connection, and an outage that costs half a day of production or service delivery. Redundancy, documented cabling and lockable technical rooms are therefore not only IT matters but also building matters.

Asset management, also part of the duty of care, starts with knowing what you have. As long as no one can indicate which equipment is permanently connected to the internet and who owns it, a serious risk analysis is difficult to carry out. The physical layer of the building is the starting point here.

Making visible what is now invisible

The IT-Label is an independent classification methodology that makes the digital quality of a building transparent. You could think of it as a digital MOT for the building: a structured way to record what is present, what it can handle and where the points of attention lie. The result is a digital delivery level, expressed as a classification ranging from IT1+ PREMIUM to IT5 SHELL.

In its assessment, IT-Label looks at fiber and internet connections, redundancy, network cabling, WiFi infrastructure, patch and server rooms, physical security, network equipment, access control, cameras, building-bound digital systems, documentation, division of responsibilities and future readiness, among other things. These are exactly the elements that in daily practice are rarely recorded in one place.

It is important to be clear: the IT-Label is not an NIS2 certification and does not guarantee that an organization complies with the Cyber Security Act. Legal compliance is the responsibility of the organization itself, to be verified against official sources. What the IT-Label does do is make building-bound digital risks visible, so that landlords, tenants and advisors can make better agreements about them. In this way, the digital building layer becomes a topic parties can consciously decide on.

Who this is relevant for

This is explicitly not a topic for the IT manager alone. Property owners, asset managers, property managers, technical managers, real estate agents, facility managers, tenants, boards and advisors are all affected by it. A few questions make this concrete: who actually checks the digital infrastructure before a tenant signs? Does the owner know which digital systems are permanently connected to the internet? And can we, in 2026, still speak of a future-proof building without looking at digital resilience?

The next step

NIS2 turns digital resilience into a board-level matter. IT-Label adds a real estate question alongside it: how digitally resilient is the building in which that organization has to function? Both questions reinforce each other, and both start with insight.

A good first step is an IT-Label pre-inspection or a Digital Due Diligence, which maps the building-bound digital infrastructure before you sign, buy or redevelop. Property owners, tenants and advisors can find more information about the IT-Label, the pre-inspection and Digital Due Diligence at www.it-label.com.

Together we make visible what is currently still invisible.

Share this article

Have a question?

Contact us for more information about the IT-label.

Get in touch