What do NIS2 and the EU CER Directive mean in practice for energy and utility operators?
NIS2 sets cyber security and incident reporting requirements for the network and information systems that essential and important services depend on. The CER Directive sets a parallel physical resilience obligation for the entities delivering those same essential services. Most energy and utility operators are in scope of both, and management bears direct accountability under each. Check whether the critical service register used for your CER assessment is the same one used for NIS2: if it is not, a service can be flagged critical under one directive and miss the corresponding measures under the other.
Published · Updated
Maximilian Bazzi, Founder and CEOWhat NIS2 actually requires
NIS2 applies to operators of essential and important services, which includes most energy and utility operators, and requires a documented risk management approach for network and information systems, incident reporting within tight timelines, and supply chain security measures covering critical suppliers. It replaces and extends the original NIS Directive with a wider sector scope and more specific timelines.
What the CER Directive adds
The CER Directive covers the same critical sectors from a physical resilience angle: business continuity, crisis management, physical protection of critical infrastructure, and a resilience assessment that identifies which services are critical and what disruption they can tolerate. Where NIS2 asks whether your systems can be compromised, CER asks whether your operations can be disrupted, physically or otherwise, and still recover.
Why operators usually need to satisfy both at once
An energy or utility operator's essential service typically depends on both network and information systems in scope of NIS2 and physical assets and operations in scope of CER. Treating them as two unrelated compliance projects means assessing the same critical service twice, once for cyber resilience and once for physical resilience, usually against two different registers of what is critical.
Where teams commonly run into difficulty
The most common gap is a critical service register that exists for one directive but not the other, so a service identified as critical under CER is not necessarily flagged for the cyber resilience measures NIS2 expects, or the reverse. Incident reporting is a second common gap: the timelines differ, and a single incident can trigger obligations under both directives with different deadlines.
How Bazzi Consulting helps
We build one critical service and function register that supports both NIS2 and CER assessments, so the same underlying resilience work is not done twice. See risk and resilience advisory.