Critical Entities Resilience Directive (CER)
Table of Contents
Chapter I – GENERAL PROVISIONS
Chapter II – NATIONAL FRAMEWORKS ON THE RESILIENCE OF CRITICAL ENTITIES
Chapter III – RESILIENCE OF CRITICAL ENTITIES
Chapter IV – CRITICAL ENTITIES OF PARTICULAR EUROPEAN SIGNIFICANCE
Chapter V – COOPERATION AND REPORTING
Chapter VI – SUPERVISION AND ENFORCEMENT
Chapter VII – DELEGATED AND IMPLEMENTING ACTS
Chapter VIII – FINAL PROVISIONS
Recitals (45)
Annexes
Recital 13
(13) With a view to ensuring a comprehensive approach to the resilience of critical entities, each Member State should have in place a strategy for enhancing the resilience of critical entities (the ‘strategy’). The strategy should set out the strategic objectives and policy measures to be implemented. In the interests of coherence and efficiency, the strategy should be designed to seamlessly integrate existing policies, building, wherever possible, upon relevant existing national and sectoral strategies, plans or similar documents. In order to achieve a comprehensive approach, Member States should ensure that their strategies provide for a policy framework for enhanced coordination between the competent authorities under this Directive and the competent authorities under NIS2 Directive (Network and Information Security) in the context of information sharing on cybersecurity risks, cyber threats and cyber incidents and non-cyber risks, threats and incidents and in the context of the exercise of supervisory tasks. When putting in place their strategies, Member States should take due account of the hybrid nature of threats to critical entities.