Skip to content
atlas

Don't confuse these

CER Directive vs NIS2 Directive

Why they differ

Adopted the same day as twins - NIS2 protects network and information systems, CER protects the physical ability of critical entities to keep running. Entities named under CER count as essential under NIS2.

CER Directive

Compliance & regulation

The EU law that makes the operators of vital services like power and water able to withstand floods, sabotage and other physical threats.

Formal

Directive (EU) 2022/2557, under which each member state names the critical entities in 11 sectors by 17 July 2026; those entities must assess their risks, take physical and organisational measures and report serious disruptions within 24 hours. Member states had to write it into national law by 17 October 2024; the Danish law applies from 1 July 2025.

In plain English

Protecting a dam is not only about who knows the control-room code - it is also the fence, the spare generator and the plan for the day the river rises.

In practice

A Danish energy company named as a critical entity maps risks such as storms and sabotage, adds fences, cameras and backup power at its key sites, screens staff in sensitive roles and rehearses restoring supply after a site is hit.

Why it matters

Society grinds to a halt when power, water, transport or hospitals fail, and a cut cable or a flooded pumping station does as much damage as a hacker; cyber rules alone leave that side uncovered.

NIS2 Directive

Compliance & regulation

The EU cybersecurity law that sets shared security duties for organisations in important and critical sectors.

Formal

Directive (EU) 2022/2555, to be written into national law by 17 October 2024, which obliges essential and important entities in 18 sectors to manage cyber risk, report significant incidents in stages and make their management body answerable.

In plain English

Like common building safety rules for the whole EU - every country must write them into its own law, and those who keep society running must build by them.

In practice

The board of a mid-sized Danish shipping company learns it falls under NIS2, so it approves a risk assessment, a routine for reporting incidents within 24 hours and security terms for its suppliers.

Why it matters

The first NIS rules covered too few sectors and were applied unevenly; NIS2 brings in thousands more organisations, fines of up to 10 million euro or 2% of turnover, and personal liability for leaders.

Shared connections

Atlas is in beta.