// Sub-Gates
The domain determination sequence.
-
01 · Critical Entity Identification · Art. 6
Checks the modelled status of identification as a critical entity by the competent member state.
-
02 · Critical Entity Risk Assessment · Art. 12
Risk assessment including relevant dependencies on essential services from other sectors.
-
03 · Resilience Measures · Art. 13
Appropriate and proportionate technical, security-related and organisational resilience measures.
-
04 · Background Checks · Art. 14
Background-check procedures for relevant sensitive roles or access.
-
05 · Incident Notification · Art. 15
Determined notification conditions for significant security incidents.
-
06 · Cross-Border Coordination · Art. 11
Active only where a corresponding cross-border critical-entity constellation is actually relevant.
CER IS NOT SIMPLY “PHYSICAL NIS2.”
NIS2 addresses the cyber/digital resilience domain. gateCER addresses the physical resilience domain of critical entities. Both are complementary, legally distinct domains, not an equivalence.
This page uses exclusively the corrected Art. 6/11/12/13/14/15 structure. Earlier, no-longer-applicable references (including EU 2024/2897, a differing article mapping, and “Board Accountability” as a sub-gate) have been removed.
Explore execution authorization →