Siirry pääsivulle
Welcome to Deloitte

If we have selected the wrong experience for you, please change it above.

The Critical Entities Resilience Directive: A Finnish Perspective on the Nordic Implications

The EU’s Critical Entities Resilience (CER) Directive requires organisations across 11 essential sectors to redesign how they manage risks. The directive also exposes a fundamental problem: most organisations manage risks in silos, and when crises hit, those silos become blind spots. This article explains why CER matters for Nordic organisations and why every organisation should adopt its principles.

A strategic advantage, not just a regulatory concern

The EU’s CER Directive represents the most significant shift in two decades in how critical infrastructure governance is embedded in the broader organisational context. By July 2026, EU Member States were required to formally designate critical entities across 11 essential sectors.

Unlike traditional cybersecurity or business continuity frameworks, CER mandates an all-hazards approach, integrating natural disasters, physical security, hybrid attacks and supply chain vulnerabilities into a single, comprehensive resilience plan.

Any organisation providing essential services beyond designated critical entities can leverage CER’s holistic approach to strengthen its resilience and stakeholder confidence. In our view, CER’s requirements should be seen as levers that enable any organisation to build robust capabilities to prepare for, manage and emerge stronger from disruptive events of all kinds in an increasingly challenging environment.

Organisations that move swiftly will integrate emerging risks into their risk management and resilience planning, examine alternative supply chains and establish robust governance arrangements before regulatory deadlines expire. Those adopting a “wait and see” approach will face operational disruptions, higher costs and competitive disadvantages.

Why traditional risk management falls short

Traditional critical infrastructure protection is no longer sufficient. What matters now is the resilience of the entire organisation. However, most organisations still manage risk through the following siloed functions:

  • IT and cybersecurity teams conduct cyber risk assessments
  • Operations teams manage business continuity
  • Physical security teams handle facility protection
  • Supply chain teams manage vendor risk
  • Compliance teams track regulatory obligations

Coordination across these functions can be challenging, and during a crisis, the gaps between siloed functions may create blind spots.

CER exposes this fragmentation by requiring a single, integrated risk assessment covering the following:

  • Natural hazards, including floods, storms and extreme weather
  • Physical threats, including sabotage and unauthorised access
  • Operational risks, including supply chain disruptions, personnel security and insider threats
  • Hybrid threats
  • Cross-sector dependencies and cascading failures

Unique advantages and challenges for Nordic organisations

CER requires organisations to develop a comprehensive resilience plan. This plan is a practical governance framework that validates the consistency, completeness, clarity and credibility of the organisation’s governance arrangements. A mature resilience plan integrates key capabilities across business continuity, crisis management and supply chain management. It provides clear roles for identifying, escalating, managing, responding to and resolving disruptive events of all kinds. Crucially, the resilience plan ensures that any risk assessment findings translate into concrete, regularly tested and continuously validated operational procedures.

For Nordic organisations, the resilience plan is a natural extension of existing governance strengths. Nordic organisations are well-positioned  to comply with and implement CER requirements due to their strong governance traditions, mature risk management practices, digital maturity and climate awareness. Additionally, the collaborative culture between public and private sectors enables stronger engagement with competent authorities.

  1. Governance accountability: Nordic countries emphasise clear accountability structures. This provides a foundation for CER governance but requires dedicated resilience leadership.
  2. An all-hazards threat landscape: Climate-related disruptions are increasingly common. Geopolitical tensions create hybrid threat scenarios. Supply chain dependencies on critical digital infrastructure are growing.
  3. Cross-border dependencies: Nordic organisations often operate across multiple EU Member States. A Finnish energy company may depend on Swedish hydropower. CER requires managing resilience obligations across multiple jurisdictions.
  4. Regulatory integration: CER overlaps significantly with NIS2 (cybersecurity), DORA (the financial sector) and climate disclosure requirements. Organisations must integrate these into a coherent compliance framework.
  5. Incident notification and transparency: CER mandates rapid incident reporting - initial notification within 24 hours of awareness and a detailed report within one month. This requirement applies uniformly across all Nordic countries and reinforces the region’s emphasis on governance accountability and cross-border coordination.

The time to act is now

In Finland, the deadline for identifying critical entities was 17 July 2026. The designated critical entities must complete risk assessments, draft their resilience plans and fulfil statutory compliance obligations within nine months of designation. Additionally, non-designated organisations who provide essential services should start by assessing their current risk management maturity.

The following sections provide deeper guidance on each requirement. Naturally, our team can help you get started.

CER mandates comprehensive risk assessment covering the following:

  1. Essential services identification: What services are critical to society?
  2. Dependency mapping: What organisations, systems or services does the organisation depend on?
  3. Threat assessment: What natural, cyber, physical and hybrid threats could disrupt services?
  4. Vulnerability evaluation: Where are organisational weaknesses?
  5. Impact estimation: What would be the consequences and recovery time?
  6. Risk prioritisation: Which risks pose the greatest threat?
  7. Resilience measures definition: What controls are needed?
  8. Documentation and reporting: Board and regulatory reporting

In modern enterprises, disruptions cause the greatest damage through the way failures cascade across interconnected systems and not necessarily through the initial disruptive event. This demands dedicated resilience leadership, whether established as a new executive role or assigned to an existing senior leader with appropriate authority and resources.

Resilience leadership must do the following:

  • Own the risk assessment process: Ensure comprehensive, current and credible assessments that capture systemic interdependencies
  • Coordinate horizontally across functions: Work across IT, operations, security, the supply chain and compliance to break down silos and build an organisational resilience mindset – not by creating a large, separate department, but by empowering existing teams to embed resilience into their operations
  • Report to the board: Ensure robust board-level oversight and strategic alignment
  • Engage with competent authorities: Serve as the primary regulatory contact
  • Drive continuous improvement: Ensure resilience measures are regularly tested, validated and adapted to emerging threats
  • Build adaptive capacity: Focus on developing organisational flexibility and the ability to respond effectively to disruptions of all kinds, rather than only predicting specific scenarios

The role requires strategic thinking, cross-functional leadership and the ability to foster a resilience mindset throughout the organisation. Critically, resilience leadership creates competitive advantage: organisations that embed this capability early will demonstrate stronger operational continuity, build stakeholder confidence and be better positioned to navigate future crises.

Rather than treating CER, NIS2, DORA and climate disclosure as separate compliance projects, organisations should build an integrated resilience and compliance framework that does the following:

  1. Consolidates risk assessment: A single comprehensive process addressing multiple regulations
  2. Integrates governance: Unified governance structures across regulations
  3. Aligns reporting: A single reporting framework for disclosure requirements
  4. Leverages investments: Resilience measures address requirements across multiple regulations

This integrated approach is more efficient, effective and sustainable than managing each regulation separately.

Deloitte helps through regulatory expertise and practical experience: 

1. Regulatory expertise

  • Deep understanding of the CER Directive and Nordic national implementations
  • Experience with NIS2, DORA and other critical infrastructure regulations
  • Relationships with competent authorities and industry peers

2. Practical experience

  • Experience across multiple sectors and countries
  • Benchmarking data on maturity levels and best practices
  • Proven methodologies for integrated risk assessment and governance

3. Cross-functional expertise

  • Cybersecurity, physical security and supply chain specialists
  • Organisational change and risk management experts
  • Integrated resilience framework design

Deloitte’s resilience and risk services include the following:

  • Assessment and roadmap: Evaluating the current resilience state, identifying gaps, defining a compliance timeline
  • Integrated risk assessment: A design methodology, conducting comprehensive assessment, mapping dependencies
  • Resilience plan development and leadership: Developing resilience strategies, designing governance structures, establishing resilience leadership, enabling board oversight
  • Resilience measures and implementation: Identifying and deploying controls, developing an implementation roadmap, supporting execution
  • Change management and training: Developing strategy, conducting executive education, building an organisational mindset
  • Regulatory engagement and continuous improvement: Supporting regulatory reporting, monitoring evolving guidance, driving continuous improvement
Contact Us:

Jouni Viljanen
jouni.viljanen@deloitte.fi

Antti Parviainen
antti.parviainen@deloitte.fi

Lauri Holmström
lauri.holmstrom@deloitte.fi

Enterprise Risk

Our Insights

Did you find this useful?

Thanks for your feedback