NIS2 Article 3(1)(f): Critical Entity Designation Makes You Essential — CER Gives 10 Months, NIS2 Gives None
Article 3(1)(f) of NIS2 runs to a single line, and it can put a 40-person water utility into the same supervisory tier as a national grid operator. It does that by pointing at Article 2(3) — the only route into NIS2 that drops both the size test and the requirement to be an entity type listed in Annex I or II, and still lands you in the essential tier [1].
Member States had to identify their critical entities under the CER Directive by 17 July 2026 [2]. That deadline has passed, designation letters are landing, and the organisations receiving them are meeting two facts the market commentary tends to skip: the CER side of the obligation arrives with a 10-month runway, and the NIS2 side arrives with none.
Does This Apply to You? Three Questions
In plain terms: if your national authority has formally identified you as a critical entity under CER, you are an essential entity under NIS2 — the top supervisory tier — and your own size is irrelevant to that outcome.
| Question | Where the answer sits | What it decides |
|---|---|---|
| Has an authority formally identified you as a critical entity? | CER Article 6(2): you provide an essential service, you operate on that Member State’s territory, and an incident would have significant disruptive effects [2] | Whether route (f) fires at all. Identification is an act of the authority, not a self-assessment. |
| Have you been notified? | CER Article 6(3) — notification within one month of identification [2] | The date every clock starts running. |
| Does your size matter? | NIS2 Article 2(3): “Regardless of their size, this Directive applies to entities identified as critical entities under Directive (EU) 2022/2557” [1] | Nothing. A micro-enterprise designated under CER is an essential entity. |
Work that through a real shape. A municipal drinking-water utility with 40 staff is a small enterprise, so the ordinary NIS2 size test does not reach it — Article 2(1) only catches entities that qualify as medium-sized or larger [1]. Designate it because it is the sole supplier to a city of 200,000, and Article 2(3) puts it in scope while Article 3(1)(f) puts it in the essential tier in the same movement. It skips the important tier entirely; it never occupies it.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
Article 3(1)(f) Runs Through Article 2(3), Which Ignores the Annexes
This is the part usually described incorrectly. Read the scope paragraphs side by side in the consolidated NIS2 text and two of the four are built differently [1]:
- Article 2(1) — entities “of a type referred to in Annex I or II” that are at least medium-sized.
- Article 2(2) — “Regardless of their size”, entities “of a type referred to in Annex I or II” meeting one of points (a) to (f).
- Article 2(3) — “Regardless of their size, this Directive applies to entities identified as critical entities under Directive (EU) 2022/2557.” No Annex qualifier.
- Article 2(4) — same Annex-free construction, for entities providing domain name registration services.
Only 2(3) leads anywhere near the top tier. No route in Article 3(1) reaches domain name registration providers, which is why Article 3(3) has Member States list them separately from essential and important entities [1]. Article 2(3) is the one Annex-free route with an Article 3(1) route waiting for it.
Article 1(2)(b) confirms the omission is structural rather than sloppy drafting: the Directive sets obligations for “entities of a type referred to in Annex I or II as well as for entities identified as critical entities under Directive (EU) 2022/2557″ [1]. CER entities are a parallel class of addressee, sitting alongside the Annexes rather than inside them.
That has teeth, because the CER Annex holds two categories of entity that appear nowhere in NIS2 Annex I or II [1][2]:
| CER Annex category | Status in the NIS2 Annexes | Result of designation |
|---|---|---|
| Point 2(e) public transport — public service operators as defined in Regulation (EC) No 1370/2007 | Absent. NIS2 Annex I transport covers air, rail, water and road only, and road reaches road authorities and Intelligent Transport Systems operators, not bus or tram operators. | Essential entity under Article 3(1)(f), despite belonging to no NIS2 sector. |
| Point 5 health — holders of a distribution authorisation under Article 79 of Directive 2001/83/EC | Absent. NIS2 Annex I health reaches providers, EU reference laboratories, medicinal-product R&D, basic pharmaceutical manufacturers and public-health-emergency device manufacturers — not distributors. | Essential entity under Article 3(1)(f), despite belonging to no NIS2 sector. |
Ireland’s transposing instrument makes the first concrete. S.I. No. 559 of 2024 reproduces CER Annex entry 2(e) verbatim and appoints the National Transport Authority as its competent authority, with the Commission for Railway Regulation taking public transport provided on a railway [5]. A designated municipal bus operator is a NIS2 essential entity while sitting, on the face of the NIS2 Annexes, in no listed sector at all.
Designated Under CER, Exempt From CER: Banking, Market Infrastructure and Digital Infrastructure
The sharpest asymmetry sits in CER Article 8. Member States must ensure that Article 11 and Chapters III, IV and VI of CER — the resilience measures, the incident reporting, the supervision and enforcement regime — do not apply to critical entities identified in Annex points 3 (banking), 4 (financial market infrastructure) and 8 (digital infrastructure). Article 6(3) requires the Member State to tell those entities in writing that they carry no Chapter III or IV obligations [2].
Article 8 does not switch off Article 6. Those entities are still identified as critical entities, so NIS2 Article 2(3) and Article 3(1)(f) still fire. For these three sectors, CER designation functions almost entirely as a NIS2 status trigger.
ComReg, Ireland’s CER authority for digital infrastructure, states both halves plainly: an identified entity “will be considered an essential entity under the NIS2 Directive”, and “the obligations in Article 11 and Chapters III, IV and VI of the CER Directive should not apply to entities belonging to the Digital Infrastructure sector” [3]. Together those describe an entity designated as critical, exempt from the resilience regime the designation was built for, and upgraded to the strictest NIS2 tier as a result.
For most digital infrastructure operators the upgrade changes little, since DNS providers, TLD registries and qualified trust service providers are already essential under Article 3(1)(b) whatever their size [1]. For a cloud, data centre or content delivery network provider below the medium-sized threshold, it changes everything.
10 Months for Physical Resilience, None for Article 21
CER builds in a runway. NIS2 does not. Neither directive says this in one place, so here are both clocks measured from the same event — the Article 6(3) notification landing on your desk.
| From notification | CER obligation | NIS2 obligation |
|---|---|---|
| Day 0 | None yet. Chapter III has not started. | Essential entity status attaches. Article 21 risk-management measures and Article 23 reporting apply [1]. |
| On entering scope | — | Article 3(4): registration details owed to the competent authority. No deadline is set for the first submission, but later changes must be notified “within two weeks of the date of the change” [1]. |
| 9 months | Article 12(1): critical entity risk assessment due [2]. | — |
| 10 months | Article 6(3): Chapter III resilience measures begin to apply [2]. | — |
The NIS2 column has no runway because nothing in the directive creates one. A full-text search of Directive (EU) 2022/2555 returns no transitional provision of any kind for entities entering scope after 18 October 2024, the date from which Article 41 required Member States to apply their transposing measures [1]. Scope is assessed continuously, not granted in cohorts. DLA Piper’s July 2026 note lands in the same place from the other direction: “most critical entities will have ten months before the CER’s substantive resilience obligations begin to apply to them” — ten months is a CER concession, not a compliance holiday [6].
The budgeting implication runs against intuition. The physical-resilience programme, usually the larger capital item, is the one with a schedule. The cybersecurity programme, which many designated entities assume they can sequence afterwards, is the one already live.
The Notification Chain: Who Tells Whom, and What You Owe Next
Designation does not stay between you and one regulator. Four provisions wire the regimes together, and each moves information about you without your involvement.
- CER Article 6(4) — your CER authority notifies the NIS2 competent authority of your identity within one month of identification, flagging points 3, 4 and 8 entities with no Chapter III or IV obligations [2].
- NIS2 Article 13(5) — the two sets of authorities exchange information regularly, specifically “with regard to the identification of critical entities” [1].
- NIS2 Article 23(10) — when a designated entity files a significant incident report, the CSIRT or competent authority forwards information about it to the CER authority [1]. One report, two regulators informed.
- NIS2 Article 32(9) — your CER authority “may request the competent authorities under this Directive to exercise their supervisory and enforcement powers” against you [1]. A physical-resilience regulator can route a concern into the cybersecurity enforcement regime.
Forwarding is not the same as a single filing. Timelex’s analysis of the Belgian regime describes the position for an operator caught by both: a significant incident “triggers parallel notification obligations with different recipients, different content requirements and different deadlines” [7]. CER Article 15(1) asks for an initial notification within 24 hours and a detailed report within one month; the NIS2 reporting sequence under Article 23(4) is a 24-hour early warning, a 72-hour incident notification and a final report within one month [1][2]. The 72-hour stage exists only on the NIS2 side.
What that means depends on your seat. A compliance officer should record the notification date the day it arrives, since both clocks and any later enforcement argument run from it. A CISO should treat Article 21 as live from that date and prioritise what the essential tier’s proactive supervision tends to test first. An SME owner or board member should note that the same designation moves the organisation into the higher NIS2 penalty tier and attaches management accountability under Article 20 — neither negotiable by reference to headcount.
The Transposition Gap: Where the Bridge Has Only One Half Built
A directive does not impose obligations on a company directly; it obliges the Member State to legislate, and the national law is what binds you. That distinction is usually academic. Right now it is not.
Ireland transposed CER on time — the Minister for Defence signed the European Union (Resilience of Critical Entities) Regulations 2024 in October 2024, and the designation machinery has run since, with a competent authority named for each of the eleven sectors [4]. Ireland has not transposed NIS2. On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify transposing measures, asking for a lump sum and daily penalties until they do [8].
S.I. No. 559/2024 defines the “NIS 2 Directive” but contains no essential-entity provision, because that is not a CER instrument’s job [5]. An Irish entity designated in July 2026 therefore acquires a status under an article that has no Irish law to land in yet. Belgium, which has transposed, shows the finished shape: Timelex records that the Belgian NIS2 Act makes CER designation trigger essential entity status “by operation of law … without any separate assessment” [7].
The honest reading is narrower than “you are automatically essential across the EU”. The date your Article 21 obligations become enforceable is set by your Member State’s NIS2 law — and Germany and the Czech Republic are expected to run self-assessment rather than designation regimes, which changes how you learn you are in scope [6]. Two things hold at once: the outcome of designation is not discretionary, and when it bites is a question of national law. Neither is a reason to wait, since the referrals put late transposition in months rather than years.
Frequently Asked Questions
If we are designated under CER, do we still check the NIS2 size thresholds?
No. Article 2(3) applies “regardless of their size” and Article 3(1)(f) makes the result essential rather than important [1]. The size test in Article 2(1) is a separate route into scope, not a filter applied on top of designation.
Our sector is not in NIS2 Annex I or II. Can we really be an essential entity?
Yes, if you are identified as a critical entity. Article 2(3) omits the “of a type referred to in Annex I or II” wording that Articles 2(1) and 2(2) both carry, and Article 1(2)(b) treats CER entities as a separate addressee class [1]. Public transport operators and holders of a medicinal-product distribution authorisation are where this shows up in practice.
Does becoming a NIS2 essential entity make us a CER critical entity?
No. The bridge runs one way. Article 3(1)(f) reads across from a CER identification into NIS2; nothing in CER converts NIS2 status into a designation, which under CER Article 6(2) requires an act of the Member State applying its own criteria [1][2].
What happens to our status if we are later de-designated?
CER Article 6(5) requires the Member State to notify an entity that it is no longer critical, and Chapter III obligations cease from receipt [2]. Route (f) depends on being identified, so it falls away — but only that route. If you also meet Article 3(1)(a) on size or another route you stay essential on that basis, and Article 3(2) still makes any Annex I or II entity important by default [1]. De-designation is not an exit from NIS2.
Key Takeaways
- Article 3(1)(f) works through Article 2(3), the only Annex-free scope route with an Article 3(1) route waiting for it — which is why entities in no NIS2 sector can still become essential.
- Banking, financial market infrastructure and digital infrastructure entities can be designated under CER, exempted from CER Chapters III, IV and VI by Article 8, and upgraded to NIS2 essential all at once.
- CER gives you 10 months to Chapter III and 9 months to your risk assessment. NIS2 has no transitional provision, so Articles 21 and 23 are live from designation.
- Four provisions — CER 6(4) and NIS2 13(5), 23(10) and 32(9) — connect the two regulators, including a route for your CER authority to ask the NIS2 authority to enforce against you.
- The outcome of designation is not discretionary; the date it becomes enforceable is set by your Member State’s NIS2 law.
Sources
- Directive (EU) 2022/2555 (NIS2) — Articles 1(2), 2, 3, 13(5), 21, 23, 32(9), 41 and Annexes I and II. EUR-Lex, CELEX 32022L2555 (linked above).
- Directive (EU) 2022/2557 (CER) — Articles 2(1), 6, 7(1), 8, 12(1), 15(1) and Annex. EUR-Lex, CELEX 32022L2557.
- “CER FAQs” — ComReg, Ireland’s CER competent authority for digital infrastructure (linked above).
- “Critical Entities Resilience (CER) Regulations” — Office of Emergency Planning, gov.ie, updated 17 August 2026 (linked above).
- European Union (Resilience of Critical Entities) Regulations 2024, S.I. No. 559 of 2024 — Irish Statute Book (linked above).
- “CER Directive enters a new phase as ‘critical entity’ designation deadline arrives” — DLA Piper, 17 July 2026.
- “One Incident, Two Regulators, Two Regimes” — Timelex.
- “Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice” — European Commission, IP/26/1499, 8 July 2026 (linked above).
Related reading: the seven routes into Article 3(1) covers routes (a) to (g) and the size test in full, NIS2 and CER compared covers running both programmes together, and the NIS2 transport guide carries sector detail for designated operators.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
