The Critical Entities Resilience Directive covers what NIS2 doesn’t: physical and operational resilience of the organisations society can’t do without, against sabotage, terrorism, natural disasters and everything else. In the Netherlands it lands as the Wet weerbaarheid kritieke entiteiten, in force 15 August 2026, alongside the Cyberbeveiligingswet.
You don’t self-select into CER. The responsible minister designates critical entities: in the Netherlands roughly 500 organisations across energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, government, space, nuclear, chemicals, water management, meteorology and food. Designation runs from 15 August 2026.
The multiplier: designated under the Wwke means automatically an essential entity under the Cyberbeveiligingswet. The heaviest cyber regime attaches by definition.
For most critical entities the essential service runs on OT. The cyber-physical slice of CER resilience is exactly the terrain of a IEC 62443 risk assessment: what happens to the service when the control system is the vector.
Only if designated by your minister. You’ll hear it formally. If you’re close to the line, the Cyberbeveiligingswet almost certainly reaches you first; start there.
Complementary by design: CER takes all-hazards resilience of the entity, NIS2 takes cybersecurity of network and information systems. In the Netherlands both arrive on 15 August 2026.
The risk-assessment discipline transfers one to one: scope, assess, measure, evidence. Start with the systems that carry the essential service.
Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.