Resilience Plan Lint (CER Directive)

Checks critical infrastructure risk assessment and resilience plan Markdown against EU CER Directive 2022/2557 Art. 12-15: 24-hour notice, one-month report, 9-month and 4-year cycle, all hazards. Runs entirely in your browser — nothing is uploaded.

Full version: scan every plan in the workspace at once and export a dated gap report for the auditor file. Get the full version — $29 · $29 once · one licence key per person or team seat. An online CER Directive course costs $297; it does not check your plan.

Same engine as the VS Code extension, byte for byte.

Get the complete version $29

This page is the working piece. The full pack has everything below.

Critical infrastructure risk assessment and resilience plan checks against EU CER Directive 2022/2557 Art. 12-15: initial incident notice within 24 hours, detailed report within one month, f

An online CER Directive trained-professional course costs $297; it teaches Articles 12-15 but does not check your plan.

Buy the full version — $29
Want the full version?
Enter your email and we send the download link.
ENDEJAESPT

Find a tool

· ReadyStack

Worked example

Real numbers from this tool, line by line.

Resilience Plan Lint (CER Directive)

Six findings came back when Resilience Plan Lint read a sample water utility resilience plan. The plan was written for an EU critical entity under the CER Directive and was notified on 2026-08-14. Five of the findings are errors and one is a warning. If you are the security or compliance lead at a designated energy, water, transport or health operator in Germany, the Netherlands, France or any other member state, those six lines are the ones the competent authority will read first.

Why now: member states had to identify their critical entities by 17 July 2026. A critical entity must complete its first risk assessment within nine months of the designation notice. For a notice dated 2026-08-14, that is 2027-05-14. The sample plan targets 2027-06-30, which is six weeks late.

Here is what the lint returned on the sample file, line by line:

Plan saysCER requires
72 hours initial notice24 hours (Art. 15)
Detailed report in 60 daysOne month (Art. 15)
Review every five yearsAt least every four years
First assessment 2027-06-30Due 2027-05-14 (nine months)
No public health hazardAll hazards (Art. 12)
No liaison officerNamed contact (Art. 13)

The 72-hour line is the most common mistake, and it has a clear origin. NIS2 incident reporting has three steps: a 24-hour early warning, a 72-hour incident notification and a one-month final report. CER Article 15 has two steps: an initial notification no later than 24 hours after becoming aware, and a detailed report no later than one month after that. Teams that already run a NIS2 process often copy it into the resilience plan, and the 72-hour step comes with it. For CER, that first notice is 48 hours late.

The lint uses nine rules, one per requirement in Articles 12 to 15:

The deadline rule reads the dates in the plan itself. If the plan says "Designation notified: 2026-08-14", the rule adds nine calendar months. If the plan's own completion date falls after that, the line is flagged. If there is no completion date and the deadline has already passed on the day you run the check, the plan is flagged as overdue. On the build date, 2026-09-27, the sample deadline has not passed yet, so the only date finding is the late target.

How to use it: paste the plan Markdown into the free web page, or open the file in VS Code and run the check command. Each finding shows the line, the article and the fix. The free check covers one file with no limit on runs. The full version scans every plan in a workspace at once and exports a dated gap report for the auditor file.

For comparison, an online CER Directive trained-professional course costs $297. It teaches the articles, but it does not read your plan.

The lint reads text. It cannot judge whether your fences are high enough. It only checks that the plan covers each Article 12 to 15 element and that the deadlines match the directive.

15 seconds — what it actually does

Questions people ask

What does Resilience Plan Lint check?

Resilience Plan Lint reads a critical entity's risk assessment or resilience plan written in Markdown. It checks the plan against EU CER Directive 2022/2557 Articles 12 to 15 with nine rules: the 24-hour initial incident notice, the one-month detailed report, the first assessment within nine months of designation, a review at least every four years, all hazard categories, sector dependencies, the liaison officer and the Article 13 measures.

Who is Resilience Plan Lint for?

It is for security, risk and compliance leads at organisations that EU member states designate as critical entities under the CER Directive. That includes energy, water, transport, health and digital infrastructure operators. It suits anyone who keeps the risk assessment and resilience plan as text files and must show the competent authority that every Article 12 to 15 element is covered.

Why not just use a NIS2 template or a chatbot?

NIS2 incident reporting has a 24-hour early warning, a 72-hour notification and a one-month final report. The CER Directive, Article 15, has only an initial notice within 24 hours and a detailed report within one month. Plans built from NIS2 templates often promise 72 hours as the first notice, and general chatbots repeat that mix-up. The lint flags that exact line.

What is free and what does the full version add?

The free version checks one plan file at a time, in VS Code or in the browser. It shows every finding with its line, article and fix, with no limit on runs. The full version costs $29 once, with one licence key per person or team seat. It scans every plan in the workspace in one pass and exports a dated gap report for the auditor file.

How does the cost compare with other options?

An online CER Directive trained-professional course costs $297. It teaches what Articles 12 to 15 require, but it does not read your plan. Resilience Plan Lint checks the plan itself for free, line by line. The $29 full version adds workspace-wide scans and an exportable gap report, and it is a one-time payment, not a subscription.

Why not just ask ChatGPT or another AI chat?

A general AI chat answers from training data with a cutoff date, cannot read your repository and names no rule version. Resilience Plan Lint (CER Directive) checks the file you open against 9 rules, each naming its legal or official basis, from a rule set dated 2026-09-27, and points at the exact line with the fix. For a filing, an audit or a client you need that dated result on your own files.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.