CER Directive: strengthening the resilience of critical entities across the EU
The Critical Entities Resilience (CER) Directive is a European directive aimed at strengthening the resilience of critical infrastructure across the European Union (EU).
Unlike the Network and Information Security (NIS) Directive and its successor NIS2 — which focus on cybersecurity and the protection of digital systems and networks — the CER Directive is primarily concerned with the physical resilience of critical infrastructure. It addresses risks arising from natural hazards, terrorist attacks, sabotage, public health emergencies and other non-cyber threats that could disrupt essential services. This complementary approach ensures that both digital and physical dimensions of critical infrastructure protection are addressed within the EU’s broader resilience framework.
It forms a key pillar of the EU’s broader resilience framework by requiring Member States and in-scope entities to identify, assess and mitigate risks that could disrupt the provision of essential services. EU Member States are required to transpose the CER Directive into national law - introducing enhanced obligations for critical entities, including risk assessments, resilience measures, and incident reporting frameworks, as well as increased regulatory oversight at national level. In this guide, we provide an overview of the current implementation status across EU Member States, based on our comprehensive mapping exercise, and highlight key national developments to watch.
Timeline for compliance
The CER Directive entered into force on 16 January 2023 and Member States were required to transpose it into national law by 17 October 2024. The next key milestone was 17 July 2026, by which Member States had to identify the entities considered critical for the provision of essential services. Once an entity is notified of its designation, the Directive’s substantive resilience obligations generally apply ten months after that notification. As national transposition and designation processes continue to develop across Member States, organizations should monitor local implementation closely and assess whether they may fall within scope.
Resilience measures and governance
But how will this directive strengthen the resilience of critical entities? The CER Directive takes a comprehensive, all-hazards approach to resilience. Critical entities must carry out risk assessments, implement appropriate technical, security, and organizational measures to ensure their resilience, document those measures in a resilience plan and notify competent authorities of disruptive incidents. The directive also introduces governance requirements, background checks for personnel with sensitive roles, and supervisory and enforcement mechanisms. It seeks to establish a consistent level of resilience across all EU member states. Cooperation between member states and alignment with sector-specific legislation, including the NIS2 Directive, is central to the framework.
Your resilience partners
We can help you assess whether your organization qualifies as a critical entity under the CER Directive, interpret the resilience obligations that apply to your operations, and implement pragmatic strategies for compliance. We find innovative ways to simplify complexity, bring greater administrative ease, and future-proof your business against disruption.