5 Signs Your Organisation Is Not CER-Ready (And How to Fix It)
Most organisations underestimate what CER compliance actually requires. These five warning signs reveal the gaps before regulators do.
Most Organisations Are Not CER-Ready — Here's How to Tell
The CER Directive (EU 2022/2557) on the resilience of critical entities came into force in January 2023. Member states were required to transpose it by October 2024. Enforcement is now active.
Yet in our work with organisations across the EU, we consistently find the same gaps. Here are the five warning signs that your organisation is not CER-ready — and what to do about each one.
Sign 1: You Don't Know If You're a "Critical Entity"
The CER Directive applies to organisations formally designated as "critical entities" by their national competent authority. Designation is based on whether the organisation provides essential services in one of the eleven sectors covered by the Directive: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, and food.
The problem: Many organisations assume they are not designated because they haven't received formal notification. But designation processes vary by member state, and some national authorities are still working through their designation exercises.
What to do: Contact your national competent authority to confirm your designation status. If you operate across multiple member states, check with each relevant authority. Don't assume you're not in scope.
Sign 2: Your Risk Assessment Doesn't Cover All-Hazards
NIS2 requires a cybersecurity risk assessment. CER requires something broader: an all-hazards risk assessment covering natural hazards, man-made hazards (including accidents and terrorism), and cross-sector dependencies.
The problem: Most organisations have a cybersecurity risk register but not a comprehensive all-hazards risk assessment. The CER risk assessment must consider the potential cascading effects of disruption — what happens to other critical services if yours fails.
What to do: Extend your existing risk management framework to cover physical threats, insider threats, and cross-sector dependencies. The risk assessment must be documented, reviewed regularly, and available to the competent authority on request.
Sign 3: Your Incident Response Plan Doesn't Include CER Reporting
CER introduces its own incident reporting obligation. Critical entities must notify their national competent authority of incidents that significantly disrupt or have the potential to significantly disrupt the provision of essential services.
The problem: Most organisations have incident response plans built around NIS2 (cyber incidents) or GDPR (personal data breaches). CER adds a third reporting stream for physical and operational incidents — and the reporting thresholds and timelines differ from NIS2.
What to do: Review your incident response plan and add CER-specific reporting procedures. Map the reporting timelines and thresholds for each framework (NIS2, CER, GDPR) and ensure your incident response team knows which authority to notify for which type of incident.
Sign 4: You Haven't Addressed Insider Threat
The CER Directive explicitly requires critical entities to address insider threats. This includes the ability to conduct background checks on persons in sensitive roles — a requirement that many organisations have not yet implemented.
The problem: Background check requirements vary by member state (some have implemented them more strictly than others), and many organisations don't have a clear process for identifying which roles are "sensitive" under CER.
What to do: Work with your HR and legal teams to define which roles have access to critical systems or information that would make them "sensitive" under CER. Establish a background check process proportionate to the risk, and document it.
Sign 5: You Have No Relationship With Your National Competent Authority
Under CER, critical entities are expected to cooperate with their national competent authority. This includes participating in resilience testing exercises, sharing information about incidents, and engaging with national risk assessments.
The problem: Many organisations have no established relationship with their national competent authority for CER purposes. They don't know who their point of contact is, what information they're expected to share, or when exercises are planned.
What to do: Identify your national competent authority for CER (this may be different from your NIS2 authority). Establish a point of contact within your organisation for CER-related communications. Engage proactively — authorities respond better to organisations that demonstrate good faith compliance than to those who only appear when there's a problem.
The Bottom Line
CER compliance is not a one-time project — it's an ongoing programme of risk management, incident response, and regulatory engagement. The organisations that are genuinely CER-ready have integrated it into their broader resilience framework alongside NIS2, DORA, and their other regulatory obligations.
If you recognise your organisation in any of these warning signs, the time to act is now. Enforcement is active, and the consequences of a significant incident without demonstrable compliance are severe.
