The CER Directive shifts the focus from identifying scope to demonstrating that essential services can withstand and recover from disruption. This shift from compliance on paper to resilience in practice involves the following considerations:
On Tuesday, 15 September 2026, KPMG held an exclusive event on the EU Critical Entities Resilience (CER) Directive and its implications for the Belgian regulatory landscape.
During this session, KPMG specialists provided an overview of the CER Directive and the latest developments regarding its implementation in Belgium, key insights into what obligations organizations will face and supervisory expectations, and concrete guidance on how to prepare for CER requirements. Experts in EU regulatory resilience and critical infrastructure security shared their perspectives on emerging resilience challenges, regulatory developments, and practical implementation considerations across sectors.
1. Designation determines obligations
Operating in a covered sector is only the starting point. Formal designation, based on the service provided and the impact of disruption, activates the CER obligations.
2. Readiness starts before notification
The implementation window is short. Organizations should clarify likely scope, accountable ownership, and available evidence before formal notification arrives.
3. Resilience must be all-hazards
The focus extends beyond cyber: natural, physical, human, and supply-chain threats all matter when they could interrupt an essential service.[
From awareness to operational readiness
What organizations can do now:
The strongest starting position is simple: know your critical service, its dependencies, its owner, and the evidence you can show.
How KPMG can help
KPMG supports organizations throughout their CER compliance journey, from initial readiness assessments to the implementation and testing of resilience capabilities.
Our services include:
1. Scope and assess
- CER applicability and readiness assessments
- All-hazards risk assessments and resilience gap analyses
2. Design and govern
- Governance, accountability, and operating model design
- Development of BCM Framework, including resilience plans and supporting procedures
- Incident management, escalation, and notification frameworks
3. Exercise and strengthen
- Crisis management and business continuity enhancement
- Tabletop exercises, simulations, and resilience testing
- Third-party and supply chain resilience assessments
4. Integrate requirements
- Integration of CER, NIS2, DORA, and broader operational resilience requirements into a coherent and efficient compliance framework
By combining regulatory expertise, resilience capabilities, and sector-specific experience, KPMG helps organizations move beyond compliance and build sustainable resilience in an increasingly complex and interconnected environment.
Spotlight on CER
In the meantime, you can stay informed via our articles on CER:
Stay informed
To be the first to know about CER updates and suggest topics you want covered, please subscribe to our KPMG newsletters.