Two directives, one question: show that your organisation learns.
NIS2 and CER now apply. You have long been learning from exercises and incidents — what is missing is the picture of where the crisis organisation stands, and the proof that it learns. Both come out of one quality management system: the same yardstick for exercise and real response, one dossier, in your own language.
Each member state transposes these directives into national law — in the Netherlands the Cyberbeveiligingswet, in force since 15 August 2026.
Two hours at the table: plenty of picture, few decisions.
Same pattern: everyone weighs in, no one guards the structure.
The picture phase bleeds into decision-making — decisions go unmade.
action item · retested in the autumn exerciseCyber (NIS2) and physical resilience (CER) ask for the same learning cycle. One working method, one dossier — not two administrations.
An OT outage is handled and reported by the book. Three months later the regulator asks: "what did that outage change in your organisation?" The answer sits scattered across inboxes, an evaluation document and management minutes. You did learn — you just cannot show it.
Three requirements that are not about technology
Not an evaluation tool, but the quality management system of your crisis organisation: you know where it stands, and you can show that it learns.
evaluate against one yardstick · recurring threads with follow-through · readiness from exercise and response data
The software records it; senior consultants embed the working method.