By 17 July 2026, Belgian sectoral authorities were required to designate the critical entities under the Critical Entities Resilience (CER) Directive (EU) 2022/2557, with formal notification to those entities due a month later. For boards in strategic sectors, such as energy, banking, or digital infrastructure, the question is no longer whether they will be affected, but whether they are ready to take on the oversight this requires. 

The resilience of essential services, and the potential impact on society in case of disruption, have long been a concern for policymakers. Yet the way in which this concern is framed has evolved significantly over the past two decades. The transition from the European Critical Infrastructure Directive of 2008 to the CER Directive is more than a regulatory update: it signals a broader conceptual shift in how risk, disruption and business continuity are understood within the EU. 

For companies operating in strategic sectors, with many of them being listed, this evolution raises an important question: is resilience, long treated mainly as an operational matter, now becoming a governance issue? 

From a security paradigm to a resilience paradigm

The 2008 Directive emerged in a context dominated by concerns over terrorism and the protection of physical infrastructure. Its logic was clear: certain assets, such as power plants, energy networks and transport systems, were critical, and their disruption could have severe cross-border consequences. The objective was therefore to identify these assets at European level and improve their protection. 

Over time, however, this framework proved too narrow as the economy evolved. Essential services now depend on digital networks, financial infrastructure and healthcare systems, and the threat landscape has expanded well beyond terrorism. It also became clear that protecting individual infrastructure components does not necessarily guarantee the continuity of the services they support. A service can fail because of organisational weaknesses, supply chain disruptions or cascading effects across sectors, even when no single piece of “critical infrastructure” is directly attacked.The existing framework addressed the protection of assets, not the resilience of services. That gap is what the CER Directive was designed to close. 

The CER Directive: a change of perspective

The CER Directive shifts the organising principle from infrastructure to entities. Rather than defining a closed category of “essential services”, it establishes a mechanism through which Member States identify critical entities: organisations in eleven predefined sectors, such as energy, banking, transport, health, digital infrastructure, whose services are deemed essential and whose disruption would have a “significant” impact. 

The Directive deliberately avoids fixing “essential services” as a strict legal category. Instead, it treats the term as a functional reference point: services necessary for vital societal or economic activity, assessed against each Member State’s own risk landscape rather than defined once and for all. That flexibility is useful, but it also means a company cannot determine its own scope of application just by reading the Directive. It depends on how national authorities apply the designation criteria. 

Those criteria are impact-based rather than asset-based. Member States must weigh, among other things: the number of users depending on the service; how many other sectors rely on it; the entity’s market importance and the availability of alternatives; the geographical scope and likely duration of disruption; and interdependencies with other sectors and systems. The analysis is systemic rather than static. What matters is not whether an asset is important, but whether disrupting the service it supports would ripple significantly across the economy and society. 

This shift in designation logic mirrors a deeper shift in regulatory philosophy. Where the 2008 framework aimed to prevent or mitigate specific threats, the CER Directive takes an “all-hazards” approach: it assumes disruptions will happen, and focuses on an entity’s capacity to prevent, absorb, adapt to and recover from them. Critical entities must assess risks, put in place appropriate technical and organisational measures, ensure business continuity, and report significant incidents to the competent authorities. 

Resilience, in this sense, is not a state a company achieves once. It is a capability that has to be continuously developed and embedded in the organisation. 

The role of Member States: discretion and divergence

Member States sit at the centre of the CER framework. They are responsible for conducting national risk assessments, designating critical entities and supervising compliance. This decentralised design reflects real differences in national systems and risk environments, but it also introduces variability in how the Directive gets applied. 

As there are no quantitative thresholds and the designation criteria are qualitative, two Member States can reasonably reach different conclusions about which entities are “critical” for essentially the same activity. For companies operating across borders, that can produce asymmetries in regulatory exposure, with some services being treated as critical in one country but not in its neighbour. 

The practical implication is that companies should not wait for a threshold or a checklist. They should proactively assess whether their activities, given their nature and impact, are likely to fall within scope, rather than assuming the question will be answered for them. 

Where does Belgium stand?

Belgium’s law transposing the CER Directive was adopted on 19 December 2025 and published in the Belgian Official Gazette on 19 January 2026, repealing the previous 2011 law on the protection of critical infrastructure. It applies across eleven sectors, from energy and transport to banking, digital infrastructure, water, health, space and food production. Each sector is overseen by its own sectoral authority and requires the competent national authority to adopt a resilience strategy setting the country’s priorities and coordination with NIS2. 

The timeline is tight. Sectoral authorities had until 17 July 2026 to designate critical entities in their sector; formal notification to those entities was duewithin a month, by 17 August 2026. From notification, designated entities face short deadlines: six months to appoint a point of contact, nine months to complete a risk analysis, and ten months to implement the measures in their resilience plan. Entities already designated as critical infrastructure under the 2011 regime carry over automatically into the new status as of 17 July 2026, while remaining subject to certain transitional obligations from the old law until 17 May 2027. The legislative phase is now complete. What remains is the identification and designation, risk analysis, and resilience planning, all against those deadlines. 

Non-compliance is not a paperwork risk. Administrative fines can reach €125,000 per infringement, and criminal penalties, including imprisonment, apply for serious breaches of the internal resilience measures. Sectoral inspectors also hold broad powers of control, including unannounced access to an entity’s premises and documents, including the resilience plan itself. 

What this means for boards

The CER Directive does not directly address corporate governance structures. It imposes obligations on “entities”, not on boards or directors. Yet, risk assessment, resilience planning and continuity management are not purely technical functions. They involve strategic choices, resource allocationand the prioritisation of risks – including trade-offs between efficiency and redundancy, and between short-term performance and long-term robustness. These are inherently board-level questions. 

Three consequences follow for boards in critical sectors: 

  • Resilience becomes a standing board agenda item, not a subject raised only in a crisis. 

  • Oversight responsibilities widen beyond financial and compliance risk to a broader set of operational and systemic risks. Boards need to check that their existing monitoring frameworks actually capture these dimensions. 

  • Regulatory regimes start overlapping in ways that demand coordination. CER sits alongside NIS2 (cybersecurity) and CSRD (sustainability reporting), and the three now share real terrain: NIS2 and CER both impose incident-reporting duties that can be triggered by the same event, and CSRD’s resilience and risk-management disclosures increasingly draw on the same underlying risk analysis that a CER resilience plan requires. A board that treats these as three separate compliance tracks, run by three separate teams, will end up duplicating work and risking inconsistent disclosures. The more defensible approach is a single integrated risk-governance framework that feeds all three. 

For boards in potentially affected sectors, the practical starting point is less of a checklist than a set of questions to put to management and to the board itself: 

  1. Have we confirmed our exposure? Check with management whether the company has been or is likely to be notified. 

  1. Who owns CER at board level? Identify where CER risk analysis, NIS2 obligations and CSRD disclosures already share data or processes anddecide who owns it at board level. Some sectors also benefit from an equivalence mechanism that can lighten certain CER obligations where an equivalent sectoral regime already applies. 

  1. Is resilience currently visible to the board? If disruption risk only surfaces as a line item within a cybersecurity or audit update, the board may be missing the broader picture the CER Directive is designed to capture. 

  1. Do directors have what they need to challenge the resilience plan? A resilience plan drafted by management should be something the board can meaningfully question - on trade-offs, on assumptions, and on what “significant impact” means for their organisation. 

In that sense, the CER Directive redefines the underlying question for boards: not how to prevent disruption, but how to keep functioning through it. 

GUBERNA will continue to follow how CER, NIS2 and CSRD obligations converge at board level, and what that convergence means for how boards organise their risk oversight.