If we have selected the wrong experience for you, please change it above.
The EU’s Critical Entities Resilience (CER) Directive requires organisations across 11 essential sectors to redesign how they manage risks. The directive also exposes a fundamental problem: most organisations manage risks in silos, and when crises hit, those silos become blind spots. This article explains why CER matters for Nordic organisations and why every organisation should adopt its principles.
The EU’s CER Directive represents the most significant shift in two decades in how critical infrastructure governance is embedded in the broader organisational context. By July 2026, EU Member States were required to formally designate critical entities across 11 essential sectors.
Unlike traditional cybersecurity or business continuity frameworks, CER mandates an all-hazards approach, integrating natural disasters, physical security, hybrid attacks and supply chain vulnerabilities into a single, comprehensive resilience plan.
Any organisation providing essential services beyond designated critical entities can leverage CER’s holistic approach to strengthen its resilience and stakeholder confidence. In our view, CER’s requirements should be seen as levers that enable any organisation to build robust capabilities to prepare for, manage and emerge stronger from disruptive events of all kinds in an increasingly challenging environment.
Organisations that move swiftly will integrate emerging risks into their risk management and resilience planning, examine alternative supply chains and establish robust governance arrangements before regulatory deadlines expire. Those adopting a “wait and see” approach will face operational disruptions, higher costs and competitive disadvantages.
Traditional critical infrastructure protection is no longer sufficient. What matters now is the resilience of the entire organisation. However, most organisations still manage risk through the following siloed functions:
Coordination across these functions can be challenging, and during a crisis, the gaps between siloed functions may create blind spots.
CER exposes this fragmentation by requiring a single, integrated risk assessment covering the following:
CER requires organisations to develop a comprehensive resilience plan. This plan is a practical governance framework that validates the consistency, completeness, clarity and credibility of the organisation’s governance arrangements. A mature resilience plan integrates key capabilities across business continuity, crisis management and supply chain management. It provides clear roles for identifying, escalating, managing, responding to and resolving disruptive events of all kinds. Crucially, the resilience plan ensures that any risk assessment findings translate into concrete, regularly tested and continuously validated operational procedures.
For Nordic organisations, the resilience plan is a natural extension of existing governance strengths. Nordic organisations are well-positioned to comply with and implement CER requirements due to their strong governance traditions, mature risk management practices, digital maturity and climate awareness. Additionally, the collaborative culture between public and private sectors enables stronger engagement with competent authorities.
In Finland, the deadline for identifying critical entities was 17 July 2026. The designated critical entities must complete risk assessments, draft their resilience plans and fulfil statutory compliance obligations within nine months of designation. Additionally, non-designated organisations who provide essential services should start by assessing their current risk management maturity.
The following sections provide deeper guidance on each requirement. Naturally, our team can help you get started.
Jouni Viljanen
jouni.viljanen@deloitte.fi
Antti Parviainen
antti.parviainen@deloitte.fi
Lauri Holmström
lauri.holmstrom@deloitte.fi