Practice · Operational resilience & CER
Operational resilience & CER
Denmark’s CER-loven is in force and the authorities have identified their critical entities. For designated organisations the clocks are short: a full all-hazards risk assessment within nine months of notification, substantive obligations one month later — with inspections, audits and evidence demands behind them.
Strategys helps you prove which services must continue, what can stop them, how you will keep them running, and that your plans actually work — one governed evidence model across CER and NIS2, led by senior specialists who run the same discipline on their own operation.
Who it's for
Designated, in scope, or supplying those who are
Resilience regulation now reaches three groups at once: entities designated under CER-loven, the far larger population already covered by NIS2, and the suppliers both depend on. The common need is the same — controls that genuinely run, and evidence that survives an inspection.
-
You may be — or are — a critical entity
Organisations in the CER sectors (transport, health, water, food, public administration and more) facing designation under CER-loven: authorities identified their critical entities by 17 July 2026, and the compliance clocks start on notification.
-
NIS2 already applies
Thousands of Danish organisations are in NIS2 scope today, and most are still mid-implementation. A CER-designated entity automatically becomes an essential entity under NIS2 regardless of size — so the unfinished NIS2 work and the new CER obligations land on the same desk, at the same time.
-
You supply the critical entities
Suppliers to designated organisations inherit resilience requirements contractually: questionnaires, audit rights, availability and notification clauses, continuity testing. Staying an eligible supplier becomes a business-critical capability.
How we work
One assessment, two regimes, evidence first
We anchor every engagement to the national framework — SAMSIK’s cross-cutting guidance, the national strategy and the sector authority’s expectations — and build the evidence model once, so it serves CER, NIS2 and your auditors alike. Where the work meets security regulation or architecture, we pair this with our cybersecurity & compliance and enterprise architecture practices.
-
Turn the designation into a scoped programme
Take the authority’s decision or consultation letter and make it operational: establish precisely which legal entity, services, sites and infrastructure are in scope, brief management, and stand up programme governance with accountable owners — a one-to-three-week mobilisation.
-
Assess once, cover both regimes
One integrated gap assessment against CER, NIS2, ISO 27001 and ISO 22301-informed continuity practice — producing a scoped service map, compliance matrix, prioritised remediation plan and an evidence register that serves both authorities.
-
Map the essential service end to end
From essential service through business processes, sites, IT/OT systems, personnel, utilities and suppliers to dependent sectors — the validated dependency model CER’s all-hazards risk assessment requires, and the hardest artefact to build.
-
Make incidents reportable in 24 hours
Classification criteria, decision trees, escalation paths and pre-approved templates so the 24-hour initial notification and one-month detailed report are operational routine, coordinated across CER and NIS2 reporting duties.
-
Keep it audited, tested and current
Authorities can inspect, demand evidence and require independent audits — and the risk assessment recurs at least every four years. We leave a living evidence model and review cadence, not a binder.
Experience
We hold ourselves to the same evidence bar
Our own operation runs the discipline this practice sells: an ISO 27001-aligned, control-by-control self-assessed ISMS, a NIS2 self-assessment, sequential change management with rollback plans, quarterly backup-restore testing and documented incident routines. Our consultants bring programme, process and IT/OT experience from transport, life sciences, the public sector and manufacturing — and where a workstream needs physical-security engineering, large-scale exercises or specialised legal interpretation, we bring named partners rather than stretched claims.
FAQ
CER & resilience — questions we get
What is CER-loven and who does it affect?
CER-loven (Act No. 433 of 6 May 2025, in force 1 July 2025) implements the EU Critical Entities Resilience Directive in Denmark. It covers ten sectors — transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, central public administration, space and food — with energy handled under a separate preparedness act. Competent authorities identified their critical entities by 17 July 2026; designation is consequence-based, not size-based.
We have been notified as a critical entity — what are the deadlines?
From notification you have nine months to complete an all-hazards risk assessment and ten months until the substantive obligations apply — resilience measures, a documented resilience plan, incident reporting and supervision readiness. The risk assessment then recurs at least every four years. The window is workable, but only if scoping and governance start immediately.
How do CER and NIS2 fit together?
CER covers physical, operational and all-hazards resilience; NIS2 covers cyber and information-system risk. A CER-designated entity automatically becomes an essential entity under the Danish NIS2 Act regardless of size — so most designated organisations must run both. We build one governance and evidence model that serves both regimes, so nothing is assessed twice and nothing falls between them.
We are not finished with NIS2 — what does CER designation mean for us?
You are in the majority, and designation raises the stakes of that unfinished work rather than adding a parallel track. PwC’s Cybercrime Survey 2025 found that 13% of Danish organisations had fully implemented the NIS2 requirements while 73% were still underway — and under Danish law, a designated critical entity automatically becomes an essential entity under NIS2 regardless of size: the highest supervision tier, with proactive oversight. The practical answer is consolidation, not panic: one programme that completes the NIS2 work and delivers the CER risk assessment and resilience plan on the same evidence base, inside the same deadlines.
Do you deliver the physical security measures too?
Yes, as part of one accountable programme. Strategys leads the governance, programme management, dependency mapping and IT/OT integration, and delivers physical and perimeter security, large-scale crisis exercises and specialised legal interpretation together with named specialist partners. One programme, one point of accountability, and specialists on every leg of the work that demands them.
We are a supplier to a critical entity, not one ourselves — why does CER matter to us?
Because the requirements reach you through your customers’ contracts, and they are already moving: under NIS2’s supply-chain duty, Danish organisations are sending supplier security questionnaires and writing audit rights, notification duties and continuity-testing requirements into agreements today. CER designation raises what those customers must ask of you — resilience, recovery, even personnel screening. We help suppliers answer credibly and close the gaps that matter — we run the same discipline in our own group, so the questionnaires our clients face are ones we have answered ourselves.
What does an engagement look like in practice?
Focused and senior-light: a designation-response mobilisation of one to three weeks, an integrated CER/NIS2 readiness assessment of four to six weeks, or a defined dependency-mapping or incident-reporting build. Senior specialists, embedded or as a small team, across Denmark and the Nordics in Danish, English, Arabic, Urdu and other European languages.
Designated — or expecting to be?
Tell us where you stand: a notification letter, a consultation, a supplier questionnaire, or just a sector that is clearly in scope. We will talk you through what the deadlines mean for you and what a right-sized first step looks like.
Contact us