Digital Basic Security for SMEs Certification Mark (English)
Laatst gewijzigd op: 26-08-2026Make sure your basic digital security is in order.
Many SMEs depend on external IT service providers. But how do you know whether your IT service provider applies the right security measures?
The Digital Basic Security for SMEs Certification Mark (Keurmerk Digitale Basisveiligheid MKB) helps businesses make that assessment. The certification mark was developed following a motion in the Dutch House of Representatives, known as the Rajkowski motion, which called for greater support for SMEs in improving their cybersecurity. The certification mark shows which IT service providers are able to implement the security measures set out in the Risicoklassenindeling Digitale Veiligheid (RKIDV), the Dutch digital security risk classification tool, correctly and professionally.
In the video below, Member of Parliament Queeny Rajkowski explains the background to Digital Basic Security for SMEs.
Based on the Risicoklassenindeling Digitale Veiligheid (RKIDV)
The certification mark is aligned with the security measures in the Risicoklassenindeling Digitale Veiligheid (RKIDV). This Dutch digital security risk classification tool is based on the five basic principles of Het Nationaal Cyber Security Centrum (NCSC). It shows which risk category applies to your business and which security measures are appropriate.
You can have these measures implemented by an IT service provider that holds the Digital Basic Security for SMEs Certification Mark, so you can stay focused on running your business.
Want to know your company’s risk of a cyber incident?
Complete the RKIDV on the NCSC website. By answering nine questions, you can immediately see which risk category applies to your business and which security measures are recommended.
Certification of service providers
How can IT service providers get their services certified?
The process starts by expressing your interest to one of the certification bodies with which the CCV has a licensing agreement. These certification bodies are authorised to assess the service against the requirements set out in the certification scheme.
IT service providers can prepare for the audit by incorporating all requirements for the service and the quality management system from the certification scheme into their working methods. This increases the likelihood of a successful audit.
What does the certification mark mean for providers and customers?
The certification mark shows that the IT service provider’s service meets clearly defined quality requirements that have been independently assessed.
By holding the certification mark, IT service providers demonstrate that they are able to implement the security measures set out in the RKIDV correctly. This gives customers greater clarity about what they can expect from the service.
For SMEs, the certification mark makes it easier to compare providers. Once certified services are available, businesses can use hetccv.nl/bedrijven to find IT service providers offering services under the Digital Basic Security for SMEs Certification Mark.
This helps businesses make an informed choice and gives them confidence that the RKIDV measures are implemented professionally and in accordance with defined quality requirements.
The NCSC’s five basic principles
The RKIDV is based on the NCSC’s five basic principles for digital security:
- Identify risks: Risk management helps you understand which systems and assets you have, which threats they may face and which risks you are prepared to accept.
- Promote secure behaviour: Make employees aware of risks and train them to respond to incidents. It is also important to create a culture in which people feel safe reporting incidents when something goes wrong.
- Protect systems, applications and devices: Software often contains more functionality than an organisation needs. Unnecessary functionality can give attackers more opportunities to gain access.
- Manage access to data and services: To minimise the risk of accidents and misuse, employees within your organisation and external partners should only have the access they need for their work and only for as long as that access is required. This is known as the principle of least privilege.
- Prepare for incidents: Pay attention to business continuity, contingency and recovery plans, incident response plans and backup strategies.
Source: NCSC
The Centre for Crime Prevention and Safety (the CCV) in Utrecht manages the certification scheme. The Cybersecurity Committee of Stakeholders has issued a positive recommendation on the adoption and publication of this certification scheme.
Questions? Contact us at basisoporde@hetccv.nl.
See also: digital resilience and the Cybersecurity Act
An IT service provider can help you implement appropriate security measures. But digital resilience also requires attention to vulnerabilities, threats and potential incidents.
Read this article to find out how other CCV cybersecurity certification marks and tools can contribute to your organisation’s digital resilience and, where relevant, support your preparations for the Cybersecurity Act.