The CER Directive (Directive (EU) 2022/2557) (CER Directive) is the European Union’s legislative response to the growing need for physical resilience of critical infrastructure and essential services. It complements the NIS2 Directive, which focuses on cybersecurity, by addressing non-cyber threats such as natural disasters, terrorism, sabotage, insider threats, and public health emergencies

 

Who is in scope of the CER Directive?

The CER Directive covers many of the same high-criticality sectors in scope of the NIS2 Directive (essential services – see below for more details). However, unlike NIS2, the requirements of the CER Directive will only apply to those entities who have been designated as “critical” by the relevant EU Member State. Member States have until 17 July 2026 to designate critical entities within their jurisdiction, which will be determined on the basis of a national strategy to strengthen the resilience of critical entities (which should be completed by 17 January 2026) and a national risk assessment to identify critical entities. The determination of who is critical will depend on:

  1. The entity providing one of the essential services;
  2. The entity being located on the territory of the Member State;
  3. An incident would have a significant disruptive effect on the provision by that entity of the essential service or other essential services.

On 11 September 2025, the EU Commission published guidelines supporting (amongst other things) Member States in the identification of critical entities. We note that like NIS2, the CER is a Directive and needs to be transposed into local Member State law to have full legal effect.

What happens when an entity is designated as “critical”?

Within 9 months of receiving a notification that it has been designated as critical, an in-scope entity must conduct a risk assessment. This should include all relevant risks that could disrupt the provision of their essential services – taking into account risks of a cross-sectoral and cross border nature – and include natural disasters, public health emergencies, hybrid threats and other antagonistic threats such as terrorist offences. The risk assessment should also consider key dependencies on their services by other critical entities, and be repeated every 4 years or sooner as required.

Within 10 months of being designated as critical, CER requirements will apply to the critical entity. These include:

  • Putting in place appropriate and proportionate technical, security and organisational measures to ensure resilience to the risks identified in the critical entity risk assessment. These measures should be captured in a resilience plan or equivalent and include measures which:
    • Prevent incidents from occurring
    • Ensure adequate physical protection of premises and critical infrastructure
    • Respond to, resist and mitigate the consequences of incidents
    • Recover from incidents
    • Ensure adequate employee security management e.g. background checks and training
    • Raise awareness re measures among relevant personnel.
  • Notification without undue delay, of incidents that significantly disrupt or have the potential to significantly disrupt the provision of essential services – the timeline is likely to require an initial notification no later than 24 hours after becoming aware of the incident with a follow up report no later than one month after “unless operationally unable to do so”. “Significant disruption” will be assessed taking into account:
    • the number and proportion of users affected by the disruption;
    • the duration of the disruption;
    • the geographical area affected by the disruption (taking into account whether the area is geographically isolated).

 

How do CER and NIS2 work together?

While the CER and NIS2 Directives deal with different risks (non-cyber and cyber respectively) they work together to identify and remedy end-to-end operational resilience risks for entities providing critical services in the EU. However, practically speaking, even if an entity is in scope of NIS2 and not designated as critical under the CER, their operational resilience plans are likely to be impacted by the wider cybersecurity risk management requirements under NIS2, particularly given the focus of NIS2 on significant operational impacts to the critical services of in-scope entities.

It is also worth noting that many entities who are in scope of NIS2 will also be designated as critical under the CER because of the nature of the services they provide. Conversely, entities who do not currently fall under NIS2 (for example because they do not meet the size criterion) will, if deemed critical under the CER (which is not size dependent), automatically fall within the scope of NIS2. This means that some entities who consider themselves to have escaped NIS2's reach will find themselves in scope of both directives at the point of being designated as critical under the CER before 17 July 2026.

For any advice on the potential impacts of CER on your business, and how the Directive is being implemented into local Member State law, please get in touch with your usual DLA Piper contact.

Loading...