NIS2 vs CER Directive: What EU Organisations Must Do Now
Two landmark directives. Overlapping obligations. One compliance deadline. Here's how to navigate both without doubling your workload.
The Challenge: Two Directives, One Organisation
When the EU introduced the NIS2 Directive (EU 2022/2555) and the CER Directive (EU 2022/2557) in the same legislative package, it created a compliance challenge that most organisations are still working through: how do you satisfy two overlapping frameworks without building two separate compliance programmes?
At Tools of Tech, we work with organisations across the EU that are grappling with exactly this question. Here's what you need to know.
What NIS2 Requires
NIS2 expands the scope of the original NIS Directive significantly. It now covers essential entities (energy, transport, banking, health, digital infrastructure, public administration, space) and important entities (postal services, waste management, chemicals, food, manufacturing, digital providers, research).
The core obligations under NIS2 include:
- —Risk management measures — technical and organisational measures proportionate to the risk
- —Incident reporting — significant incidents must be reported to the national CSIRT within 24 hours (early warning), 72 hours (incident notification), and one month (final report)
- —Supply chain security — organisations must address cybersecurity risks in their supply chains
- —Management accountability — senior management must approve and oversee cybersecurity measures and can be held personally liable
Penalties for non-compliance reach €10 million or 2% of global annual turnover for essential entities.
What CER Requires
The CER Directive focuses on the physical resilience of critical entities — organisations identified by member states as essential for the provision of critical services. Where NIS2 is about cyber, CER is about all-hazards resilience: physical security, insider threats, business continuity, and crisis management.
Key CER obligations include:
- —Risk assessment — critical entities must conduct comprehensive risk assessments covering natural hazards, accidents, terrorism, and cascading failures
- —Resilience measures — physical and organisational measures to prevent, protect against, respond to, and recover from incidents
- —Incident reporting — significant incidents affecting the provision of essential services must be reported to competent authorities
- —Background checks — critical entities may conduct background checks on persons in sensitive roles
Where They Overlap — and Where They Don't
The most important thing to understand is that NIS2 and CER are designed to be complementary, not duplicative. The EU explicitly intended for organisations subject to both to integrate their compliance efforts.
Overlap areas:
- —Incident reporting obligations (though to different authorities)
- —Risk assessment requirements
- —Business continuity and crisis management
- —Supply chain and third-party risk
Key differences:
- —NIS2 is cyber-focused; CER covers all physical and logical threats
- —NIS2 applies to a broader set of sectors; CER applies only to entities formally designated as "critical" by member states
- —NIS2 is self-assessed; CER involves formal designation and oversight by national authorities
A Practical Compliance Approach
The most efficient path is to build a unified risk management framework that satisfies both directives simultaneously. At Tools of Tech, we recommend:
- 1.Start with a gap assessment — map your current controls against both NIS2 and CER requirements to identify what's missing
- 2.Unify your risk register — a single risk register covering cyber and physical threats serves both frameworks
- 3.Align your incident response — design your incident response procedures to capture the reporting requirements of both directives
- 4.Integrate supply chain assessments — a single third-party risk management process can satisfy both frameworks' supply chain requirements
The organisations that struggle most are those that treat NIS2 and CER as separate projects. The ones that succeed treat them as a single resilience programme with two reporting streams.
What Happens If You Don't Act
Both directives required transposition into national law by October 2024. Enforcement is now active across EU member states. The consequences of non-compliance go beyond financial penalties — organisations that suffer a significant incident without demonstrable compliance face reputational damage, regulatory scrutiny, and potential personal liability for senior management.
If your organisation is subject to NIS2, CER, or both, the time to act is now.
