CER Directive or Critical Entities Resilience

CER Act or Critical Entities Resilience: where to start, and what your company gains from it

 

Belgium transposed the European directive on the resilience of critical entities with the law of December 19, 2025. Since July 17, 2026, sectoral authorities have been identifying the relevant companies. The day the notification arrives, a ten-month window opens to build the system.

Ten months is ample time when you know where to start. And the required work produces much more than a regulatory file: it embeds an everyday operational capability within the company.

Here is how to approach this project.

What the CER Act establishes:

The law places the service at the center. It requires you to demonstrate that your essential service continues to be provided when an event occurs: a flood, a power outage, a supplier failure, an intrusion, or a hybrid attack combining multiple vectors simultaneously.

Eleven sectors are covered: energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, public administration, space, and food production and distribution.

The National Crisis Center coordinates the framework at the federal level. Sectoral authorities then identify, designate, and support critical entities.

Three elements structure the approach:

  1. Designation is based on precise criteria: the nature of the service provided, the number of users relying on it, the geographical area affected in the event of a disruption, cross-border impact, and dependencies on other sectors.
  2. Deadlines begin upon your notification. Any time available before that date is yours to leverage, and that is where confidence is built.
  3. The framework provides for administrative fines ranging from 500 to 125,000 euros depending on the breach, as well as criminal penalties. All the more reason to address the topic proactively, at your own pace.

What your company gains from it:

Compliance is the starting point. The real value lies elsewhere, and it is measurable.

Your incidents last less time and cost less. An organization that knows how to decide quickly, degrade operations in the correct order, and restart cleanly shortens every event. This preserves revenue and saves executive bandwidth.

Your reliability becomes a competitive advantage. Supplier questionnaires and tenders now incorporate continuity, recovery times, and fallback sites. A solid response sets you apart at the point of purchase decision.

Your financing and insurance terms improve. Investors and insurers assess the maturity of your risk management. A documented and exercised system can be defended with supporting data.

Your relationship with the regulator becomes straightforward. You enter discussions with an up-to-date mapping, an active risk analysis, and an applied plan. Inspections then proceed as technical conversations.

Your company becomes more attractive. Teams stay with organizations that protect them, know what to do on a Sunday at 2 a.m., and have demonstrated it at least once.

First question: where do you stand?

Three situations, and all three warrant a conscious decision.

You are designated as a critical entity. Legal obligations apply, along with associated deadlines and audits. Operators already recognized under the previous critical infrastructure law automatically transition to the new regime.

You supply a designated entity. Your client must assess its dependencies and demonstrate its service continuity. They will ask you about your continuity plan, recovery times, fallback sites, and critical subcontractors. This requirement comes through supplier questionnaires and contractual clauses. It is already in effect in the pharmaceutical and port sectors, and it rewards those who answer accurately.

You observe the development from a distance. The regulatory trajectory remains valuable to follow. NIS2 for cyber, CER for physical and organizational resilience, DORA for finance: the resilience requirement is steadily cascading down the entire value chain. Anticipating puts you ahead.

The timeline once notification is received:

  • 1 month: the authority notifies you of your critical entity status.
  • 6 months: you designate a 24/7 point of contact and submit the list of your critical infrastructures.
  • 9 months: your risk assessment is completed.
  • 10 months: obligations apply in full and your resilience plan is operational.
  • 24 hours: the notification deadline for a significant incident, followed by a detailed report within one month.

The 24-hour deadline warrants particular attention. It assumes that someone in your organization can identify a notifiable incident on a Sunday at 2 a.m., knows who to call, and has the authority to do so immediately. This decision-making chain can be built, and it can be built quickly once addressed.

Five steps to get started:

1. Map your essential services. Start from what you deliver and what happens in the event of a disruption. Then trace back to the people, systems, sites, and suppliers that make this service possible. This service-based approach immediately reveals your real points of dependency.

2. Conduct an all-hazards risk analysis. The law requires covering natural hazards, human-caused accidents, deliberate acts, and hybrid threats, as well as examining combinations and cascading effects. A flood that cuts off power, halts a control system, and immobilizes a supply chain: Wallonia experienced this in July 2021, making the exercise very tangible.

3. Write a plan that can be read at 3 a.m. A useful resilience plan fits into a few actionable pages: who decides, who replaces the decision-maker, at what threshold to alert, which activities to maintain as a priority, how to restart. Concision is an operational quality here.

4. Bring physical and cyber under a single governance. One committee, one dependency mapping, one jointly arbitrated budget. Your NIS2 teams and your security teams gain efficiency as soon as they share the same vision of risk.

5. Test. A three-hour exercise with the executive committee uncovers what a three-week document audit leaves in the dark, while building the reflexes you are aiming to establish.

Three choices that sustain the system:

Treat CER for what it is. NIS2 secures digital assets; CER covers the failure of a sole supplier, the simultaneous unavailability of your key executives, or a site inaccessible for six days. The two frameworks complement and reinforce each other.

Build with your teams. A consultant provides the methodology, analysis, and structure. Your teams provide field knowledge and become the owners of the system. This ownership is what makes the plan usable when the day comes.

Exercise regularly. A practiced plan becomes a collective reflex. This is the moment when compliance turns into capability.

The test that matters.

Take your current plan. Choose a plausible scenario: your main supplier stops operating for seven days, or your primary site becomes inaccessible tomorrow morning.

Ask three questions to your executive committee:

  • Who makes the decision within the hour, and who makes it if that person is traveling?
  • What are the three activities we prioritize maintaining, and in what order do we adjust the rest?
  • How do we notify the authority within 24 hours with accurate information?

Three clear answers confirm that your system holds. Three hesitant answers point precisely to where efforts must be directed. In either case, you know what to do on Monday morning.

Let's talk

I assist Belgian and European organizations with operational resilience: maturity assessment across the four pillars of leadership, structure, culture, and skills, risk analysis, crisis and business continuity plans, exercises, and CER support. 

Crises strike without warning. You can prepare for them, tailored to your scale, pace, and resources.

Let us start with an initial 30-minute, no-obligation discussion.

Contact me at kairys-eu.org

Leave a comment

Your email address will not be published. Required fields are marked *

Back to top