
NIS2 Covers Cyber. The CER Directive Covers the Rest of the Failure
The Critical Entities Resilience Directive extends Europe’s resilience programme beyond networks and information systems. Organisations that stop at NIS2 may be securing only one part of the service.
NIS2 has become the best-known European resilience law. It addresses cybersecurity risk management, incident reporting, governance and supply-chain security across essential and important sectors.
Alongside it sits Directive (EU) 2022/2557 on the resilience of critical entities, usually called the CER Directive. Member States were required to transpose it by 17 October 2024 and apply their measures from 18 October 2024.
The two directives are related, but they are not duplicates. NIS2 focuses on network and information systems. CER takes an all-hazards view of the essential service itself.
A cyber-secure service can still fail
An electricity operator may have mature endpoint security and still lose a substation to flooding. A data centre can pass a penetration test and remain dependent on a single power route. A hospital can protect patient systems while lacking personnel, water or physical access after a regional emergency.
CER requires relevant risks to be considered across natural and human-made events. The directive expressly includes accidents, natural disasters, public-health emergencies, hybrid threats, sabotage and terrorism. It also asks organisations to consider cross-sector and cross-border dependencies.
That changes the unit of analysis. The protected object is not simply a server, facility or supplier. It is the continued provision of an essential service.
Who becomes a critical entity?
Member States identify critical entities using national risk assessments and the criteria in the directive. Covered sectors include energy, transport, banking, financial-market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space and certain food activities.
Identification is therefore not identical to self-assessing whether NIS2 applies. A competent authority notifies an entity that it has been identified under the national framework. Member States were required to adopt resilience strategies by 17 January 2026 and identify critical entities by 17 July 2026.
Once notified, a critical entity must conduct its own assessment within the applicable period and revisit it when necessary, at least every four years.
What operational resilience means
Required measures must be appropriate and proportionate to the identified risks. In practice, that can include:
- physical protection of premises and critical infrastructure;
- disaster-risk reduction and climate resilience;
- crisis management and recovery procedures;
- alternative supply chains and backup capacity;
- personnel security and access controls;
- staff awareness and training;
- arrangements for dependencies on other essential services.
These controls should connect to existing security, continuity, emergency-management and safety programmes. Creating a separate CER binder would miss the point.
Incident reporting also extends beyond cyber
Critical entities must notify significant disruptive incidents without undue delay. Unless operationally unable, the initial notification is due no later than 24 hours after awareness, followed where relevant by a detailed report within one month.
The reporting test considers factors such as users affected, duration and geographic area. This demands an escalation process that can recognise service disruption regardless of whether the original cause was ransomware, fire, civil disturbance or equipment failure.
Build one dependency model
The most useful joint response to NIS2 and CER is a single service-dependency model. For every essential service, map:
- Information systems and communications.
- Facilities, power, cooling and environmental controls.
- People, skills and privileged roles.
- Critical suppliers and geographic concentrations.
- Upstream and downstream essential services.
- Detection, decision and reporting routes.
- Minimum service levels and recovery priorities.
This model prevents cyber teams from assuming facilities will remain available and continuity teams from assuming the technology layer will recover itself.
The management question
Resilience regulation is moving away from isolated compliance domains. Boards and executives need to know not only whether controls exist, but whether the organisation can keep delivering the service when several controls fail together.
NIS2 asks whether digital risk is governed. CER asks whether the entity can absorb and recover from disruption across the full system. Organisations subject to both should be able to answer those questions with the same evidence.
Official sources
- Directive (EU) 2022/2557 on the resilience of critical entities
- EUR-Lex summary: Making critical entities more resilient
This article provides general information and is not legal advice.
Continue the series: European National Cyber & Digital Law Series index



