Skip to main content

      On Tuesday, 15 September 2026, KPMG held an exclusive event on the EU Critical Entities Resilience (CER) Directive and its implications for the Belgian regulatory landscape.

      During this session, KPMG specialists provided an overview of the CER Directive and the latest developments regarding its implementation in Belgium, key insights into what obligations organizations will face and supervisory expectations, and concrete guidance on how to prepare for CER requirements. Experts in EU regulatory resilience and critical infrastructure security shared their perspectives on emerging resilience challenges, regulatory developments, and practical implementation considerations across sectors.


      The CER Directive shifts the focus from identifying scope to demonstrating that essential services can withstand and recover from disruption. This shift from compliance on paper to resilience in practice involves the following considerations:

      Olivier Elst

      Partner | Advisory

      KPMG in Belgium

      1. Designation determines obligations

      Operating in a covered sector is only the starting point. Formal designation, based on the service provided and the impact of disruption, activates the CER obligations.

      2. Readiness starts before notification

      The implementation window is short. Organizations should clarify likely scope, accountable ownership, and available evidence before formal notification arrives.

      3. Resilience must be all-hazards

      The focus extends beyond cyber: natural, physical, human, and supply-chain threats all matter when they could interrupt an essential service.[

      From awareness to operational readiness

      What organizations can do now:

      • Map the essential service

        Connect the service provided to the sites, people, utilities, suppliers, and digital assets needed to deliver it. Identify alternatives and single points of failure.

      • Set clear accountability

        Establish one cross-functional owner, involve risk, operations, cyber, HR and compliance, and define a workable 24/7 contact model.

      • Reuse evidence and close the gaps

        Cross-map NIS2, DORA, ISO 22301, and continuity capabilities. Reuse what is relevant, then isolate the physical and operational measures that CER adds.

      • Make resilience continuous

        Exercise scenarios, test incident reporting and recovery, track remediation, and keep the resilience plan and supporting evidence current.


      The strongest starting position is simple: know your critical service, its dependencies, its owner, and the evidence you can show.

      How KPMG can help

      KPMG supports organizations throughout their CER compliance journey, from initial readiness assessments to the implementation and testing of resilience capabilities.

      Our services include:

      1. Scope and assess
      • CER applicability and readiness assessments
      • All-hazards risk assessments and resilience gap analyses
      2. Design and govern
      • Governance, accountability, and operating model design
      • Development of BCM Framework, including resilience plans and supporting procedures
      • Incident management, escalation, and notification frameworks
      3. Exercise and strengthen
      • Crisis management and business continuity enhancement
      • Tabletop exercises, simulations, and resilience testing
      • Third-party and supply chain resilience assessments
      4. Integrate requirements
      • Integration of CER, NIS2, DORA, and broader operational resilience requirements into a coherent and efficient compliance framework

      By combining regulatory expertise, resilience capabilities, and sector-specific experience, KPMG helps organizations move beyond compliance and build sustainable resilience in an increasingly complex and interconnected environment.



      Spotlight on CER

      In the meantime, you can stay informed via our articles on CER:

      An in-depth analysis of the new Critical Entities Resilience Directive and its impact on your organization.

      Strengthening the resilience of critical services across Europe

      Stay informed


      To be the first to know about CER updates and suggest topics you want covered, please subscribe to our KPMG newsletters.


      Enterprise risk & assurance

      Risk & regulatory services.
      Advisory risk