CER Directive

← All instruments
in forcehorizontal
Type
directive
Layer
horizontal
Status
in force
In force
2023-01-16
Key date
2026-07-17 identify critical entities
Last verified
2026-07-16

CER Directive — NIS2’s physical twin

Directive (EU) 2022/2557 on the resilience of critical entities. Where NIS2 protects network and information systems, CER protects the same critical operators against physical and all-hazards threats — natural disasters, terrorism, sabotage, insider threats, public-health emergencies. The two were adopted the same day precisely because cyber and physical resilience are inseparable.

Purpose

Ensure that entities providing essential services can prevent, resist, absorb and recover from disruptions of any kind — not just cyber. Replaces the 2008 European Critical Infrastructure Directive with a far broader, service-based approach.

Scope — 11 sectors

Energy; transport; banking; financial market infrastructure; health; drinking water; waste water; digital infrastructure; public administration; space; and production, processing & distribution of food. Member States run risk assessments and then identify the specific critical entities within these sectors (deadline 17 July 2026), applying the directive’s criteria (an entity provides an essential service; its disruption would have significant disruptive effects).

Core obligations

On Member States

  • A national strategy for the resilience of critical entities.
  • A national risk assessment (by 17 Jan 2026 and every 4 years) feeding the identification of critical entities.
  • Designate competent authorities and a single point of contact; support entities (guidance, exercises, information).

On identified critical entities

  • Resilience measures (Art. 13): physical protection of premises, prevention/ mitigation of incidents, business continuity and recovery, incident management, personnel security including background checks for sensitive roles, and awareness.
  • A resilience risk assessment within 9 months of being notified as critical, and every 4 years.
  • Incident notification (Art. 15): notify the competent authority of incidents that significantly disrupt essential services — initial notification within 24 hours, detailed report within one month.

Special regime — “critical entities of particular European significance”

Entities providing essential services to 6+ Member States can be designated of particular European significance; the Commission may, at their host state’s request, organise advisory missions to assess their measures.

Enforcement

Member States set supervisory powers (on-site inspections, audits) and penalties, which must be effective, proportionate and dissuasive — but CER does not harmonise fine ceilings the way NIS2 does, so penalty levels vary nationally.

Interplay

  • NIS2: an entity identified as critical under CER is automatically an essential entity under NIS2. Many states designate connected or identical authorities and often transpose both directives together (e.g. France’s Resilience Bill; the Netherlands’ Wwke alongside the Cyberbeveiligingswet).
  • Sector rules: financial-sector operational resilience is largely handled by DORA; CER coordinates rather than duplicates.
  • Digital Omnibus: CER incident notifications are slated to join the Single Entry Point.

Status

Same transposition timeline and delays as NIS2 (deadline 17 Oct 2024; many states late). The 2026 milestone to watch is the 17 July 2026 deadline to identify critical entities, which switches on the entity-level obligations.

Sources