Critical Entities Resilience Directive (CER)
Table of Contents
Chapter I – GENERAL PROVISIONS
Chapter II – NATIONAL FRAMEWORKS ON THE RESILIENCE OF CRITICAL ENTITIES
Chapter III – RESILIENCE OF CRITICAL ENTITIES
Chapter IV – CRITICAL ENTITIES OF PARTICULAR EUROPEAN SIGNIFICANCE
Chapter V – COOPERATION AND REPORTING
Chapter VI – SUPERVISION AND ENFORCEMENT
Chapter VII – DELEGATED AND IMPLEMENTING ACTS
Chapter VIII – FINAL PROVISIONS
Recitals (45)
Annexes
Recital 28
(28) Critical entities should have a comprehensive understanding of the relevant risks to which they are exposed and a duty to analyse those risks. To that end, they should carry out risk assessments whenever necessary in view of their particular circumstances and the evolution of those risks and, in any event, every four years, in order to assess all relevant risks that could disrupt the provision of their essential services (‘critical entity risk assessment’). Where critical entities have carried out other risk assessments or drawn up documents pursuant to obligations laid down in other legal acts that are relevant for their critical entity risk assessment, they should be able to use those assessments and documents to meet the requirements set out in this Directive concerning critical entity risk assessments. A competent authority should be able to declare that an existing risk assessment carried out by a critical entity that addresses the relevant risks and the relevant extent of dependence is compliant, in whole or in part, with the obligations laid down in this Directive.