Critical Entities Resilience

Compliance that actually
makes you ready.

The regulated pathway, served by the same practice.

Regulation now asks critical and important entities to prove resilience, not to assert it. The Critical Entities Resilience Directive requires designated operators to assess risk, plan for it, and validate that the plan holds. NIS2 extends the same demand to the security of essential and important services, and DORA imposes it on the financial sector's operational and ICT resilience, down to tested response. Stave answers all three with one practice rather than three separate compliance exercises.

This is not a separate service. It is the Expose, Build, Test spine set out in the sequence the Directive requires, for organisations whose reason for commissioning it is a designation and a statutory clock.

Start a conversation See the practice
The regulated pathway

The Expose, Build, Test spine is the CER pathway.

The Directive's phases are the same three stages in statutory clothing. Nothing new is added: the practice that makes an organisation ready is the practice that makes it compliant. A designated entity moves through four phases, and the artefact that satisfies the regulator is the one that makes leaders decide well.

01 Expose
Designation Readiness & Gap Assessment
Establish where designation obligations are met and where they are not, and where judgement would break under pressure. The gap is located before the regulator, or an adversary, finds it first.
02 Build
Risk Assessment
The risk analysis the Directive requires, developed as decisions that have to hold rather than a document to be filed. The relevant threats, the dependencies, and the remaining exposure, named plainly.
03 Build
Resilience Plan
The plan itself, including the implementation schedule that generic templates routinely omit. It typically falls due within a fixed window after the risk assessment is completed, often around twelve months.
04 Test
Exercise & Validation
The wargame. Recommended in some jurisdictions and statutory in others, where designated entities must exercise at least every two years. Preparedness proven under live adversarial conditions, and documented as evidence.
Three regimes, one practice

CER, NIS2 and DORA are coherent but distinct, and Stave treats them that way. The Critical Entities Resilience Directive concerns the physical and organisational resilience of critical entities. NIS2 concerns the security of the network and information systems behind essential and important services. DORA concerns operational and ICT resilience in the financial sector, down to threat-led testing.

They are not interchangeable, and merging them produces weaker work on all three. Stave keeps them distinct where they differ and serves them with the same spine where they align. CER remains the reference throughout; NIS2 and DORA are served by the same stages where they apply, and evidence built for one regime can be reused for another rather than commissioned three times.

The artefact that satisfies the regulator is the one that makes leaders decide well.

Timing and sequencing

In most jurisdictions the first three phases are compulsory under national transposition, while the exercise is recommended in some and mandated in others. Non-binding implementing guidance sits alongside the directive, and although it carries no legal force, supervisory authorities tend to apply it as the practical yardstick, which is why Stave builds to it.

Elsewhere all four phases are statutory, and designated entities must exercise at least every two years. The window matters more than it appears: a resilience plan typically falls due within around twelve months of completing the risk assessment, and the full path from designation to a validated plan can run to a year and a half or more once scoping, drafting and validation are sequenced. The earliest useful step is almost always a scoping workshop that locates the gap before the deadline does.

Designation is a reason to commission this work, not the only one. A large part of the exposure sits outside the regulated perimeter, in defence-adjacent suppliers, media organisations, hospitals and the mid-sized operators on whom designated entities quietly depend. The work is the same work.

Explore Practice
Contact

Every engagement starts with a conversation.

For an organisation that is designated, or expects to be, under CER, NIS2 or DORA, the earliest useful step is a scoping workshop that locates the gap before the deadline does.

LocationHelsinki, Finland