Critical Entities Resilience Directive (CER)
Table of Contents
Chapter I – GENERAL PROVISIONS
Chapter II – NATIONAL FRAMEWORKS ON THE RESILIENCE OF CRITICAL ENTITIES
Chapter III – RESILIENCE OF CRITICAL ENTITIES
Chapter IV – CRITICAL ENTITIES OF PARTICULAR EUROPEAN SIGNIFICANCE
Chapter V – COOPERATION AND REPORTING
Chapter VI – SUPERVISION AND ENFORCEMENT
Chapter VII – DELEGATED AND IMPLEMENTING ACTS
Chapter VIII – FINAL PROVISIONS
Recitals (45)
Annexes
Recital 20
(20) NIS2 Directive (Network and Information Security) requires entities belonging to the digital infrastructure sector, which might be identified as critical entities under this Directive, to take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems and to notify significant incidents and cyber threats. Since threats to the security of network and information systems can have different origins, NIS2 Directive (Network and Information Security) applies an all-hazards approach that includes the resilience of network and information systems, as well as the physical components and environment of those systems. Given that the requirements laid down in NIS2 Directive (Network and Information Security) in that regard are at least equivalent to the corresponding obligations laid down in this Directive, the obligations laid down in Article 11 and Chapters III, IV and VI of this Directive should not apply to entities belonging to the digital infrastructure sector in order to avoid duplication and unnecessary administrative burden. However, considering the importance of the services provided by entities belonging to the digital infrastructure sector to critical entities belonging to all other sectors, Member States should identify, based on the criteria and using the procedure provided for in this Directive, entities belonging to the digital infrastructure sector as critical entities. Consequently, the strategies, the Member State risk assessments and the support measures set out in Chapter II of this Directive should apply. Member States should be able to adopt or maintain provisions of national law to achieve a higher level of resilience for those critical entities, provided that those provisions are consistent with applicable Union law.