Back to briefings
    Briefing

    Cyber resilience beyond continuity

    What NIS2, DORA and the CER Directive each ask of resilience, the objectives that come before plans, and the exercise a policy cannot replace.

    Risk5 Sept 20269 min read

    Directive (EU) 2022/2555Directive (EU) 2022/2557ISO 31000:2018ISO/IEC 27001:2022ISO/IEC 27002:2022NIST CSWP 29Regulation (EU) 2022/2554
    On this page

    What it is

    Resilience is the ability to keep serving through and after an event. Directive (EU) 2022/2557, the CER Directive, defines it directly. A critical entity's resilience is its ability to prevent, protect against, respond to, resist, mitigate, absorb, accommodate and recover from an incident 1.

    Three EU acts each carry the idea. NIS2 lists business continuity, such as backup management and disaster recovery, and crisis management, among the cybersecurity risk-management measures 2. DORA requires an ICT business continuity policy inside the ICT risk management framework 3. The CER Directive requires measures to ensure resilience, including measures to recover from incidents 4.

    One loop, not three silos. How much disruption the organisation tolerates is a governance decision, and DORA puts the impact tolerance for ICT disruptions in a strategy the management body sets and approves 5. Risk picks the scenarios and the recovery targets; compliance shows the tested evidence.

    Who is in scope (decision test)

    Five questions. The written answer is the record.

    1. An essential or important entity under NIS2? The continuity measure applies through the national act; the class test is in NIS2 for the security officer.
    2. A financial entity under DORA? Articles 11 and 12 apply directly, and response and recovery plans face independent internal audit review outside microenterprises 6.
    3. Identified as a critical entity under the CER Directive? Member States identify them for the Annex sectors by 17 July 2026, and notify each within a month 7. The notice, not the sector, is the trigger.
    4. Is a customer or a certification body asking for tested recovery? What is owed is an exercise record, not a plan.
    5. A product with a support period? The five-year support-period floor is in the CRA 8; see CRA obligations by product class.
    OutcomeWhat it meansNext step
    One act appliesOne set of recovery targets, one plan set, one calendarSet tolerable disruption per service
    Two or more applyThe duties overlap; clocks and addressees differOne method, reporting duties mapped separately
    None applies yetIdentification may arrive, and customers ask anywayRun the risk assessment while it is cheap

    Resilience objectives before plans

    DORA states the sequence plainly. The resilience strategy establishes the risk tolerance level for ICT risk in line with the risk appetite, and analyses the impact tolerance for ICT disruptions 9. Appetite work already done carries over: risk appetite and criteria.

    Recovery targets follow that decision, not the estate. When setting recovery time and recovery point objectives per function, a financial entity takes account of the function's criticality and of the potential overall impact on market efficiency 10. In ISO/IEC 27002:2022 the ICT continuity requirements arrive from the business impact analysis. Prioritised activities are assigned a recovery time objective, and the information behind them a recovery point objective 11.

    Then the scenario set, taken from the register rather than a template. Ransomware, supplier failure, loss of a cloud region, insider action and data corruption each break a different assumption. The CER Directive frames the same breadth as all relevant natural and man-made risks, including cross-sectoral or cross-border ones, and hybrid threats 12.

    Read it as one loop. Governance sets the tolerance, risk turns it into targets and scenarios, and compliance demonstrates the tested result. ISO 31000:2018 puts monitoring and review at all stages of the process, with responsibilities clearly defined 13.

    Obligations by act

    Act and articleWhat it asksArtefactOwner
    NIS2 Art. 21(2)(c)Business continuity, such as backup management and disaster recovery, and crisis management 2Continuity and crisis plansSecurity officer
    NIS2 Art. 21(2)(b), (e), (f)Incident handling; vulnerability handling and disclosure in acquisition, development and maintenance; procedures assessing the measures' effectiveness 14Incident process; effectiveness reviewIncident manager
    NIS2 Art. 23Early warning within 24 hours, notification within 72 hours, final report a month later 15Reporting decision recordReporting decision-maker
    DORA Art. 6(8)A resilience strategy stating risk tolerance and impact tolerance 9Approved strategyManagement body
    DORA Art. 11Documented arrangements, plans, procedures and mechanisms; plans tested yearly and on substantive change 16Tested continuity and recovery plansContinuity owner
    DORA Art. 12Backup scope and minimum frequency; restoration from physically and logically segregated systems 17Restore-test recordICT operations
    DORA Art. 13Post-incident reviews after a major incident disrupts core activities, feeding the risk assessment 18Post-incident reviewControl function
    DORA Art. 24 to 26A testing programme in the framework; independent testers; threat-led testing every three years where identified 19Testing programme, coverage per functionTesting owner
    CER Art. 12A risk assessment within nine months of the identification notice, then at least every four years 20Critical entity risk assessmentRisk owner
    CER Art. 13Measures to prevent, protect physically, respond, recover, manage employee security and raise awareness 21Resilience plan or equivalentResilience owner
    CER Art. 15Notification without undue delay; initial notification within 24 hours of awareness; detailed report within a month 22Notification recordReporting decision-maker

    The DORA rows are summaries; the detail sits in DORA implementation, sections 3.5 and 3.7.

    Dates (verified)

    DateWhat happensSource
    2024-10-17NIS2 transposition deadline23
    2024-10-17CER measures adopted and published24
    2024-10-18NIS2 applies; Directive (EU) 2016/1148 repealed25
    2024-10-18CER applies; Directive 2008/114/EC repealed26
    2025-01-17DORA applies27
    2026-07-17CER identification of critical entities28
    2027-01-01Sweden's bill proposes effect for its CER act29

    The cybersecurity half of that December 2022 package is further along than the physical half in Sweden; the Swedish position is in the radar row.

    Mapping to ISO/IEC 27002 and NIST CSF 2.0

    Control numbers are shared with ISO/IEC 27001:2022 Annex A, and titles are cited from ISO/IEC 27002:2022 30. Category names and identifiers are as printed 31. The last column is the one worth reading.

    ObligationAnnex A / ISO/IEC 27002:2022NIST CSF 2.0What only an exercise proves
    Hold security at an appropriate level while disrupted5.29 Information security during disruptionPR.IR Technology Infrastructure ResilienceCompensating controls held while the primary ones were down
    Derive ICT continuity from the impact analysis5.30 ICT readiness for business continuityRC.RP Incident Recovery Plan ExecutionThe recovery time objective was met, and measured
    Back up, and restore from the backup8.13 Information backupRC.RP-03A restore ran from segregated systems, timed and checked
    Carry redundancy where availability requires it8.14 Redundancy of information processing facilitiesPR.IR-03Failover was exercised, not assumed
    Respond, escalate, invoke the plans5.24 to 5.26, incident planning, assessment and responseRS.MA Incident ManagementEscalation reached a decision-maker at night
    Communicate while recovering5.26, escalation including crisis management activitiesRC.CO Incident Recovery CommunicationCustomers and the authority heard one account
    Learn from what happened5.27 Learning from information security incidentsID.IM ImprovementOne improvement changed a control, not a document

    A certified management system already carries the spine. ISO/IEC 27001:2022 names clause 6.1 "Actions to address risks and opportunities" and clause 8.1 "Operational planning and control". It names clause 9.1 "Monitoring, measurement, analysis and evaluation" and clause 10.2 "Nonconformity and corrective action" 32. Where continuity itself is the subject, the management-system standard is ISO 22301:2019 33.

    Next 90 days

    WeekActionOwnerOutput
    1-2Run the five-question test, each answer citedSecurity officerScope memo
    1-2State tolerable disruption per service, and have it approvedManagement bodyApproved tolerance statement
    3-4Set a recovery time and recovery point objective per prioritised serviceContinuity ownerObjectives register
    3-4Choose five scenarios from the register, one per assumptionRisk ownerScenario set
    5-6Run one timed restore from segregated systemsICT operationsRestore-test record
    7-9Exercise one scenario end to end, timing recovery against the objectiveIncident managerExercise record with intervals
    9-10Run the reporting clocks inside that exerciseReporting decision-makerTimed reporting decision
    11-12Put the tested result and residual gaps to the approving bodySecurity officerMinuted review, actions dated

    The clocks and the two intervals worth measuring are in incident governance, section 3.10. Supplier failure as a scenario connects to third-party risk lifecycle.

    References

    1. Directive (EU) 2022/2555 (NIS2). CELEX 32022L2555. https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng
    2. Regulation (EU) 2022/2554 (DORA). CELEX 32022R2554. https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng
    3. Directive (EU) 2022/2557 (CER). CELEX 32022L2557. https://eur-lex.europa.eu/eli/dir/2022/2557/oj/eng
    4. Regulation (EU) 2024/2847 (CRA). CELEX 32024R2847. https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng
    5. ISO/IEC 27002:2022. https://www.iso.org/standard/75652.html
    6. ISO/IEC 27001:2022. https://www.iso.org/standard/27001
    7. ISO 31000:2018. https://www.iso.org/standard/65694.html
    8. ISO 22301:2019. https://www.iso.org/standard/75106.html
    9. NIST. Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. https://doi.org/10.6028/NIST.CSWP.29
    10. Sveriges riksdag. Prop. 2025/26:303. https://www.riksdagen.se/sv/dokument-och-lagar/dokument/proposition/en-ny-lag-for-okad-motstandskraft-hos-kritiska_hd03303/

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.

    Sources

    1. 1EU Publications Office CELEX 32022L2557 Art. 2(2) · verified 2026-09-05
    2. 2EU Publications Office CELEX 32022L2555 Art. 21(2)(c) · verified 2026-09-05
    3. 3EU Publications Office CELEX 32022R2554 Art. 11(1) · verified 2026-09-05
    4. 4EU Publications Office CELEX 32022L2557 Art. 13(1) · verified 2026-09-05
    5. 5EU Publications Office CELEX 32022R2554 Art. 6(8) and Art. 5(2)(d) · verified 2026-09-05
    6. 6EU Publications Office CELEX 32022R2554 Art. 11(3) · verified 2026-09-05
    7. 7EU Publications Office CELEX 32022L2557 Art. 6(1) and 6(3) · verified 2026-09-05
    8. 8EU Publications Office CELEX 32024R2847 Art. 13(8), 13(9) and Annex I Part II · verified 2026-09-04
    9. 9EU Publications Office CELEX 32022R2554 Art. 6(8) · verified 2026-09-05
    10. 10EU Publications Office CELEX 32022R2554 Art. 12(6) · verified 2026-09-05
    11. 11ISO/IEC 27002:2022 control 5.30, licensed copy · verified 2026-09-05
    12. 12EU Publications Office CELEX 32022L2557 Art. 12(2) · verified 2026-09-05
    13. 13ISO 31000:2018 clause 6.6, licensed copy · verified 2026-09-05
    14. 14EU Publications Office CELEX 32022L2555 Art. 21(2)(b), 21(2)(e) and 21(2)(f) · verified 2026-09-05
    15. 15EU Publications Office CELEX 32022L2555 Art. 23(4) · verified 2026-09-05
    16. 16EU Publications Office CELEX 32022R2554 Art. 11(2) and 11(6) · verified 2026-09-05
    17. 17EU Publications Office CELEX 32022R2554 Art. 12(1) and 12(3) · verified 2026-09-05
    18. 18EU Publications Office CELEX 32022R2554 Art. 13(2) and 13(3) · verified 2026-09-05
    19. 19EU Publications Office CELEX 32022R2554 Art. 24(1), 24(4) and Art. 26(1) · verified 2026-09-05
    20. 20EU Publications Office CELEX 32022L2557 Art. 12(1) · verified 2026-09-05
    21. 21EU Publications Office CELEX 32022L2557 Art. 13(1) and 13(2) · verified 2026-09-05
    22. 22EU Publications Office CELEX 32022L2557 Art. 15(1) · verified 2026-09-05
    23. 23EUR-Lex CELEX 32022L2555 Art. 41(1) and 21(5) · verified 2026-09-03
    24. 24EU Publications Office CELEX 32022L2557 Art. 26(1) · verified 2026-09-05
    25. 25EUR-Lex CELEX 32022L2555 Art. 41(1) and 44 · verified 2026-09-03
    26. 26EU Publications Office CELEX 32022L2557 Art. 26(1) and Art. 27 · verified 2026-09-05
    27. 27EU Publications Office CELEX 32022R2554 Art. 64 · verified 2026-09-05
    28. 28EU Publications Office CELEX 32022L2557 Art. 6(1) · verified 2026-09-05
    29. 29Regeringskansliet press release and prop. 2025/26:303 · verified 2026-09-03
    30. 30ISO/IEC 27002:2022 controls 5.24 to 5.27, 5.29, 5.30, 8.13 and 8.14, licensed copy · verified 2026-09-05
    31. 31NIST CSWP 29 Appendix A PR.IR, PR.IR-03, RS.MA, RC.RP, RC.RP-03, RC.CO and ID.IM, nvlpubs.nist.gov · verified 2026-09-05
    32. 32ISO/IEC 27001:2022 clauses 6.1, 8.1, 9.1 and 10.2, iso.org/obp · verified 2026-09-03
    33. 33ISO 22301:2019, iso.org · verified 2026-09-03