Critical Entities Resilience Directive (CER)
Table of Contents
Chapter I – GENERAL PROVISIONS
Chapter II – NATIONAL FRAMEWORKS ON THE RESILIENCE OF CRITICAL ENTITIES
Chapter III – RESILIENCE OF CRITICAL ENTITIES
Chapter IV – CRITICAL ENTITIES OF PARTICULAR EUROPEAN SIGNIFICANCE
Chapter V – COOPERATION AND REPORTING
Chapter VI – SUPERVISION AND ENFORCEMENT
Chapter VII – DELEGATED AND IMPLEMENTING ACTS
Chapter VIII – FINAL PROVISIONS
Recitals (45)
Annexes
Recital 40
(40) Member States should ensure that their competent authorities have certain specific powers for the proper application and enforcement of this Directive in relation to critical entities, where those entities fall under their jurisdiction as specified in this Directive. Those powers should include, in particular, the power to conduct inspections and audits, the power to supervise, the power to require critical entities to provide information and evidence relating to the measures they have taken to comply with their obligations and, where necessary, the power to issue orders to remedy identified infringements. When issuing such orders, Member States should not require measures which go beyond what is necessary and proportionate to ensure the compliance of the critical entity concerned, taking account of, in particular, the seriousness of the infringement and the economic capacity of the critical entity concerned. More generally, those powers should be accompanied by appropriate and effective safeguards to be specified in national law in accordance with the Charter of Fundamental Rights of the European Union. When assessing the compliance of a critical entity with its obligations as laid down in this Directive, the competent authorities under this Directive should be able to request the competent authorities under NIS2 Directive (Network and Information Security) to exercise their supervisory and enforcement powers in relation to an entity under that Directive that has been identified as a critical entity under this Directive. The competent authorities under this Directive and the competent authorities under NIS2 Directive (Network and Information Security) should cooperate and exchange information for that purpose.