How similar are NIS2 and the Critical Entities Resilience Act?

NIS2 and the Critical Entities Resilience Act (CER) are two closely connected pillars of the EU’s drive to make essential services more secure and resilient from 2026 onwards. Both target organisations that provide critical services to the economy and society, such as energy, transport, healthcare, digital infrastructure, and public administration. While NIS2 focuses on cybersecurity, CER looks at overall resilience against all types of disruption, including physical attacks, natural disasters, and system failures. Together, they form a more complete picture of what “critical infrastructure protection” means in today’s environment.
The scope of NIS2 and CER overlaps heavily. NIS2 defines “essential” and “important” entities, whereas CER speaks about “critical entities,” but in practice many organisations will be in scope of both. The underlying logic is similar: the more essential your services and the greater the potential impact of a disruption, the higher the expectations placed on you. Both directives are risk-based and proportionate, meaning requirements scale with the size, role, and risk exposure of the entity.
Governance and accountability are central to both. NIS2 and CER explicitly require involvement from top management and place clear responsibility on boards and executive teams. Compliance cannot be delegated solely to IT, security, or operations; it must be overseen at the highest level. Authorities can impose sanctions for non-compliance, which reinforces that resilience and cybersecurity are strategic issues that belong in corporate governance, not just in technical teams.
The types of measures required also show clear similarities. NIS2 expects organisations to implement cybersecurity risk management, incident detection and response, secure supply chains, and business continuity measures. CER requires a broader “all-hazards” resilience approach, including physical security, redundancy of critical assets, crisis management processes, and dependency management (for example, reliance on key suppliers or other critical entities). Common themes include risk assessments, continuity planning, training, and structured incident and crisis response.
Both directives also introduce stronger expectations around incident handling and cooperation with authorities. Under NIS2, significant cyber incidents must be reported within defined timelines, and organisations must have capabilities to detect and manage such incidents. Under CER, entities must be prepared for any major disruption and coordinate with relevant national authorities and stakeholders. In both frameworks, the emphasis is on early detection, clear roles, effective communication, and continuous improvement after an incident.
A practical, high-level approach to compliance is to build a single, integrated resilience programme that covers both NIS2 and CER. Start by mapping your regulatory exposure: confirm whether you are in scope of NIS2, CER, or both. Next, perform a combined risk and gap assessment across cyber, physical, and operational resilience. Use this to design a unified framework for governance, risk management, business continuity, incident and crisis management, and supplier risk. Align this framework with recognised standards (such as ISO 27001 and ISO 22301) to structure your controls and documentation. Finally, create a clear implementation roadmap with priorities, timelines, and responsibilities, and ensure regular reporting to the board so that resilience remains a visible and managed strategic topic rather than a one-off compliance task.
Author: Neil Redmond, Director Cyber Security at PWC
From Classroom to Career: Preparing Our BBS Students for the Workplace 