Critical Entities Resilience (CER) Directive

In scope of CER? Now what?

Cyber Security colleagues
The Belgian transposition of the Critical Entities Resilience (CER) Directive is now in force. 

As a designated critical entity, you must be able to withstand, respond to and recover from disruptions. These can come from natural hazards, technical failures, malicious acts or hybrid threats. 

CER builds on what you've likely already invested in: DORA, NIS2, business continuity, crisis management and/or risk management. The difference is scope. CER moves beyond cyber resilience alone. It asks for a broader, all-hazards approach. 

Designation is just the start. Next, you need to understand what the directive means in practice, what actions it requires, and where you can strengthen resilience across your business. 

Key CER milestones following your designation 

The CER Directive sets a number of milestones after designation. 

  • Critical Entity Point of Contact - within 6 months of notification 
  • All-Hazards Risk Assessment - within 9 months of notification 
  • Resilience Plan (WPE/PRE) - within 10 months of notification 
  • 24-hour Incident Notification - a continuous obligation 
  • Periodic Exercises and Simulations - following completion of the resilience plan 

How you become operationally resilient under the CER Directive 

Getting from designation to compliance takes a structured roadmap. It combines risk assessment, resilience planning, crisis preparedness and continuous improvement.

Here's how you can work through each stage together with BDO’s Risk experts: 

  • Assess your CER readiness: CER gap and maturity assessment 
  • Identify your critical risks and dependencies: all-hazards risk assessment 
  • Build your resilience capability: business & IT continuity strategy and planning 
  • Prepare for disruption: crisis and incident readiness 
  • Test and keep improving: exercises, testing and assurance

Regulatory expertise you can put to work 

Understanding the regulation is only part of the job. You need it translated into practical steps for your organisation. 

BDO's Risk Advisory professionals support public and private sector organisations across Belgium and Europe with operational resilience. From your first assessment through planning, implementation and testing, you get a partner who turns CER requirements into action you can execute. 

You benefit from expertise across risk management and regulations such as CER, DORANIS2 and ISO 22301, paired with hands-on delivery experience. The result is a pragmatic, business-driven approach. Resilience in practice, not just compliance on paper. 

Ready to start your CER journey? 

If you're a designated critical entity under the CER Directive, we're ready to help. Whether you need your all-hazards risk assessment, a resilience plan, or stronger crisis preparedness, get in touch to take the next step.