Cyber resilience beyond continuity
What NIS2, DORA and the CER Directive each ask of resilience, the objectives that come before plans, and the exercise a policy cannot replace.
Risk5 Sept 20269 min read
On this page
What it is
Resilience is the ability to keep serving through and after an event. Directive (EU) 2022/2557, the CER Directive, defines it directly. A critical entity's resilience is its ability to prevent, protect against, respond to, resist, mitigate, absorb, accommodate and recover from an incident 1.
Three EU acts each carry the idea. NIS2 lists business continuity, such as backup management and disaster recovery, and crisis management, among the cybersecurity risk-management measures 2. DORA requires an ICT business continuity policy inside the ICT risk management framework 3. The CER Directive requires measures to ensure resilience, including measures to recover from incidents 4.
One loop, not three silos. How much disruption the organisation tolerates is a governance decision, and DORA puts the impact tolerance for ICT disruptions in a strategy the management body sets and approves 5. Risk picks the scenarios and the recovery targets; compliance shows the tested evidence.
Who is in scope (decision test)
Five questions. The written answer is the record.
- An essential or important entity under NIS2? The continuity measure applies through the national act; the class test is in NIS2 for the security officer.
- A financial entity under DORA? Articles 11 and 12 apply directly, and response and recovery plans face independent internal audit review outside microenterprises 6.
- Identified as a critical entity under the CER Directive? Member States identify them for the Annex sectors by 17 July 2026, and notify each within a month 7. The notice, not the sector, is the trigger.
- Is a customer or a certification body asking for tested recovery? What is owed is an exercise record, not a plan.
- A product with a support period? The five-year support-period floor is in the CRA 8; see CRA obligations by product class.
| Outcome | What it means | Next step |
|---|---|---|
| One act applies | One set of recovery targets, one plan set, one calendar | Set tolerable disruption per service |
| Two or more apply | The duties overlap; clocks and addressees differ | One method, reporting duties mapped separately |
| None applies yet | Identification may arrive, and customers ask anyway | Run the risk assessment while it is cheap |
Resilience objectives before plans
DORA states the sequence plainly. The resilience strategy establishes the risk tolerance level for ICT risk in line with the risk appetite, and analyses the impact tolerance for ICT disruptions 9. Appetite work already done carries over: risk appetite and criteria.
Recovery targets follow that decision, not the estate. When setting recovery time and recovery point objectives per function, a financial entity takes account of the function's criticality and of the potential overall impact on market efficiency 10. In ISO/IEC 27002:2022 the ICT continuity requirements arrive from the business impact analysis. Prioritised activities are assigned a recovery time objective, and the information behind them a recovery point objective 11.
Then the scenario set, taken from the register rather than a template. Ransomware, supplier failure, loss of a cloud region, insider action and data corruption each break a different assumption. The CER Directive frames the same breadth as all relevant natural and man-made risks, including cross-sectoral or cross-border ones, and hybrid threats 12.
Read it as one loop. Governance sets the tolerance, risk turns it into targets and scenarios, and compliance demonstrates the tested result. ISO 31000:2018 puts monitoring and review at all stages of the process, with responsibilities clearly defined 13.
Obligations by act
| Act and article | What it asks | Artefact | Owner |
|---|---|---|---|
| NIS2 Art. 21(2)(c) | Business continuity, such as backup management and disaster recovery, and crisis management 2 | Continuity and crisis plans | Security officer |
| NIS2 Art. 21(2)(b), (e), (f) | Incident handling; vulnerability handling and disclosure in acquisition, development and maintenance; procedures assessing the measures' effectiveness 14 | Incident process; effectiveness review | Incident manager |
| NIS2 Art. 23 | Early warning within 24 hours, notification within 72 hours, final report a month later 15 | Reporting decision record | Reporting decision-maker |
| DORA Art. 6(8) | A resilience strategy stating risk tolerance and impact tolerance 9 | Approved strategy | Management body |
| DORA Art. 11 | Documented arrangements, plans, procedures and mechanisms; plans tested yearly and on substantive change 16 | Tested continuity and recovery plans | Continuity owner |
| DORA Art. 12 | Backup scope and minimum frequency; restoration from physically and logically segregated systems 17 | Restore-test record | ICT operations |
| DORA Art. 13 | Post-incident reviews after a major incident disrupts core activities, feeding the risk assessment 18 | Post-incident review | Control function |
| DORA Art. 24 to 26 | A testing programme in the framework; independent testers; threat-led testing every three years where identified 19 | Testing programme, coverage per function | Testing owner |
| CER Art. 12 | A risk assessment within nine months of the identification notice, then at least every four years 20 | Critical entity risk assessment | Risk owner |
| CER Art. 13 | Measures to prevent, protect physically, respond, recover, manage employee security and raise awareness 21 | Resilience plan or equivalent | Resilience owner |
| CER Art. 15 | Notification without undue delay; initial notification within 24 hours of awareness; detailed report within a month 22 | Notification record | Reporting decision-maker |
The DORA rows are summaries; the detail sits in DORA implementation, sections 3.5 and 3.7.
Dates (verified)
| Date | What happens | Source |
|---|---|---|
| 2024-10-17 | NIS2 transposition deadline | 23 |
| 2024-10-17 | CER measures adopted and published | 24 |
| 2024-10-18 | NIS2 applies; Directive (EU) 2016/1148 repealed | 25 |
| 2024-10-18 | CER applies; Directive 2008/114/EC repealed | 26 |
| 2025-01-17 | DORA applies | 27 |
| 2026-07-17 | CER identification of critical entities | 28 |
| 2027-01-01 | Sweden's bill proposes effect for its CER act | 29 |
The cybersecurity half of that December 2022 package is further along than the physical half in Sweden; the Swedish position is in the radar row.
Mapping to ISO/IEC 27002 and NIST CSF 2.0
Control numbers are shared with ISO/IEC 27001:2022 Annex A, and titles are cited from ISO/IEC 27002:2022 30. Category names and identifiers are as printed 31. The last column is the one worth reading.
| Obligation | Annex A / ISO/IEC 27002:2022 | NIST CSF 2.0 | What only an exercise proves |
|---|---|---|---|
| Hold security at an appropriate level while disrupted | 5.29 Information security during disruption | PR.IR Technology Infrastructure Resilience | Compensating controls held while the primary ones were down |
| Derive ICT continuity from the impact analysis | 5.30 ICT readiness for business continuity | RC.RP Incident Recovery Plan Execution | The recovery time objective was met, and measured |
| Back up, and restore from the backup | 8.13 Information backup | RC.RP-03 | A restore ran from segregated systems, timed and checked |
| Carry redundancy where availability requires it | 8.14 Redundancy of information processing facilities | PR.IR-03 | Failover was exercised, not assumed |
| Respond, escalate, invoke the plans | 5.24 to 5.26, incident planning, assessment and response | RS.MA Incident Management | Escalation reached a decision-maker at night |
| Communicate while recovering | 5.26, escalation including crisis management activities | RC.CO Incident Recovery Communication | Customers and the authority heard one account |
| Learn from what happened | 5.27 Learning from information security incidents | ID.IM Improvement | One improvement changed a control, not a document |
A certified management system already carries the spine. ISO/IEC 27001:2022 names clause 6.1 "Actions to address risks and opportunities" and clause 8.1 "Operational planning and control". It names clause 9.1 "Monitoring, measurement, analysis and evaluation" and clause 10.2 "Nonconformity and corrective action" 32. Where continuity itself is the subject, the management-system standard is ISO 22301:2019 33.
Next 90 days
| Week | Action | Owner | Output |
|---|---|---|---|
| 1-2 | Run the five-question test, each answer cited | Security officer | Scope memo |
| 1-2 | State tolerable disruption per service, and have it approved | Management body | Approved tolerance statement |
| 3-4 | Set a recovery time and recovery point objective per prioritised service | Continuity owner | Objectives register |
| 3-4 | Choose five scenarios from the register, one per assumption | Risk owner | Scenario set |
| 5-6 | Run one timed restore from segregated systems | ICT operations | Restore-test record |
| 7-9 | Exercise one scenario end to end, timing recovery against the objective | Incident manager | Exercise record with intervals |
| 9-10 | Run the reporting clocks inside that exercise | Reporting decision-maker | Timed reporting decision |
| 11-12 | Put the tested result and residual gaps to the approving body | Security officer | Minuted review, actions dated |
The clocks and the two intervals worth measuring are in incident governance, section 3.10. Supplier failure as a scenario connects to third-party risk lifecycle.
References
- Directive (EU) 2022/2555 (NIS2). CELEX 32022L2555. https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng
- Regulation (EU) 2022/2554 (DORA). CELEX 32022R2554. https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng
- Directive (EU) 2022/2557 (CER). CELEX 32022L2557. https://eur-lex.europa.eu/eli/dir/2022/2557/oj/eng
- Regulation (EU) 2024/2847 (CRA). CELEX 32024R2847. https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng
- ISO/IEC 27002:2022. https://www.iso.org/standard/75652.html
- ISO/IEC 27001:2022. https://www.iso.org/standard/27001
- ISO 31000:2018. https://www.iso.org/standard/65694.html
- ISO 22301:2019. https://www.iso.org/standard/75106.html
- NIST. Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. https://doi.org/10.6028/NIST.CSWP.29
- Sveriges riksdag. Prop. 2025/26:303. https://www.riksdagen.se/sv/dokument-och-lagar/dokument/proposition/en-ny-lag-for-okad-motstandskraft-hos-kritiska_hd03303/
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.
Sources
- 1EU Publications Office CELEX 32022L2557 Art. 2(2) · verified 2026-09-05
- 2EU Publications Office CELEX 32022L2555 Art. 21(2)(c) · verified 2026-09-05
- 3EU Publications Office CELEX 32022R2554 Art. 11(1) · verified 2026-09-05
- 4EU Publications Office CELEX 32022L2557 Art. 13(1) · verified 2026-09-05
- 5EU Publications Office CELEX 32022R2554 Art. 6(8) and Art. 5(2)(d) · verified 2026-09-05
- 6EU Publications Office CELEX 32022R2554 Art. 11(3) · verified 2026-09-05
- 7EU Publications Office CELEX 32022L2557 Art. 6(1) and 6(3) · verified 2026-09-05
- 8EU Publications Office CELEX 32024R2847 Art. 13(8), 13(9) and Annex I Part II · verified 2026-09-04
- 9EU Publications Office CELEX 32022R2554 Art. 6(8) · verified 2026-09-05
- 10EU Publications Office CELEX 32022R2554 Art. 12(6) · verified 2026-09-05
- 11ISO/IEC 27002:2022 control 5.30, licensed copy · verified 2026-09-05
- 12EU Publications Office CELEX 32022L2557 Art. 12(2) · verified 2026-09-05
- 13ISO 31000:2018 clause 6.6, licensed copy · verified 2026-09-05
- 14EU Publications Office CELEX 32022L2555 Art. 21(2)(b), 21(2)(e) and 21(2)(f) · verified 2026-09-05
- 15EU Publications Office CELEX 32022L2555 Art. 23(4) · verified 2026-09-05
- 16EU Publications Office CELEX 32022R2554 Art. 11(2) and 11(6) · verified 2026-09-05
- 17EU Publications Office CELEX 32022R2554 Art. 12(1) and 12(3) · verified 2026-09-05
- 18EU Publications Office CELEX 32022R2554 Art. 13(2) and 13(3) · verified 2026-09-05
- 19EU Publications Office CELEX 32022R2554 Art. 24(1), 24(4) and Art. 26(1) · verified 2026-09-05
- 20EU Publications Office CELEX 32022L2557 Art. 12(1) · verified 2026-09-05
- 21EU Publications Office CELEX 32022L2557 Art. 13(1) and 13(2) · verified 2026-09-05
- 22EU Publications Office CELEX 32022L2557 Art. 15(1) · verified 2026-09-05
- 23EUR-Lex CELEX 32022L2555 Art. 41(1) and 21(5) · verified 2026-09-03
- 24EU Publications Office CELEX 32022L2557 Art. 26(1) · verified 2026-09-05
- 25EUR-Lex CELEX 32022L2555 Art. 41(1) and 44 · verified 2026-09-03
- 26EU Publications Office CELEX 32022L2557 Art. 26(1) and Art. 27 · verified 2026-09-05
- 27EU Publications Office CELEX 32022R2554 Art. 64 · verified 2026-09-05
- 28EU Publications Office CELEX 32022L2557 Art. 6(1) · verified 2026-09-05
- 29Regeringskansliet press release and prop. 2025/26:303 · verified 2026-09-03
- 30ISO/IEC 27002:2022 controls 5.24 to 5.27, 5.29, 5.30, 8.13 and 8.14, licensed copy · verified 2026-09-05
- 31NIST CSWP 29 Appendix A PR.IR, PR.IR-03, RS.MA, RC.RP, RC.RP-03, RC.CO and ID.IM, nvlpubs.nist.gov · verified 2026-09-05
- 32ISO/IEC 27001:2022 clauses 6.1, 8.1, 9.1 and 10.2, iso.org/obp · verified 2026-09-03
- 33ISO 22301:2019, iso.org · verified 2026-09-03