The regulated pathway, served by the same practice.
Regulation now asks critical and important entities to prove resilience, not to assert it. The Critical Entities Resilience Directive requires designated operators to assess risk, plan for it, and validate that the plan holds. NIS2 extends the same demand to the security of essential and important services, and DORA imposes it on the financial sector's operational and ICT resilience, down to tested response. Stave answers all three with one practice rather than three separate compliance exercises.
This is not a separate service. It is the Expose, Build, Test spine set out in the sequence the Directive requires, for organisations whose reason for commissioning it is a designation and a statutory clock.
The Directive's phases are the same three stages in statutory clothing. Nothing new is added: the practice that makes an organisation ready is the practice that makes it compliant. A designated entity moves through four phases, and the artefact that satisfies the regulator is the one that makes leaders decide well.
CER, NIS2 and DORA are coherent but distinct, and Stave treats them that way. The Critical Entities Resilience Directive concerns the physical and organisational resilience of critical entities. NIS2 concerns the security of the network and information systems behind essential and important services. DORA concerns operational and ICT resilience in the financial sector, down to threat-led testing.
They are not interchangeable, and merging them produces weaker work on all three. Stave keeps them distinct where they differ and serves them with the same spine where they align. CER remains the reference throughout; NIS2 and DORA are served by the same stages where they apply, and evidence built for one regime can be reused for another rather than commissioned three times.
The artefact that satisfies the regulator is the one that makes leaders decide well.
In most jurisdictions the first three phases are compulsory under national transposition, while the exercise is recommended in some and mandated in others. Non-binding implementing guidance sits alongside the directive, and although it carries no legal force, supervisory authorities tend to apply it as the practical yardstick, which is why Stave builds to it.
Elsewhere all four phases are statutory, and designated entities must exercise at least every two years. The window matters more than it appears: a resilience plan typically falls due within around twelve months of completing the risk assessment, and the full path from designation to a validated plan can run to a year and a half or more once scoping, drafting and validation are sequenced. The earliest useful step is almost always a scoping workshop that locates the gap before the deadline does.
Designation is a reason to commission this work, not the only one. A large part of the exposure sits outside the regulated perimeter, in defence-adjacent suppliers, media organisations, hospitals and the mid-sized operators on whom designated entities quietly depend. The work is the same work.
Explore PracticeFor an organisation that is designated, or expects to be, under CER, NIS2 or DORA, the earliest useful step is a scoping workshop that locates the gap before the deadline does.