Critical Entities Resilience Directive

European UnionCritical Infrastructure2023
ByDecipherU Editorial

The CER Directive addresses the physical and cybersecurity resilience of critical entities across the EU. While NIS2 focuses on cybersecurity, CER covers physical threats (natural disasters, terrorism, sabotage) and requires critical entities to conduct risk assessments and implement resilience measures. Member states must transpose it alongside NIS2.

Quick Reference

EnactedAdopted November 28, 2022; transposition deadline October 17, 2024
Enforcement BodyNational competent authorities designated by member states
PenaltiesDetermined by member states; must be effective, proportionate, and dissuasive
Applicable ToCritical entities in 11 sectors including energy, transport, health, digital infrastructure, and public administration

Key Requirements

Article 12 (Risk assessment by critical entities)

Critical entities must conduct a risk assessment within 9 months of notification, covering all relevant risks including cyber-physical threats

Article 13 (Resilience measures)

Critical entities must take appropriate measures to ensure resilience, including physical protection, incident management, and personnel security

Article 15 (Incident notification)

Critical entities must notify competent authorities of incidents that significantly disrupt or have the potential to significantly disrupt essential services

How Does CER Directive Affect Cybersecurity Careers?

Cybersecurity professionals working in critical infrastructure must understand how CER complements NIS2. Physical security and cybersecurity convergence roles (e.g., in OT/ICS environments) directly address CER requirements. GRC analysts at critical entities must manage both CER and NIS2 compliance simultaneously.

Cybersecurity Roles That Work With CER Directive

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of CER Directive at the official source: https://eur-lex.europa.eu/eli/dir/2022/2557/oj

Frequently Asked Questions

The CER Directive addresses the physical and cybersecurity resilience of critical entities across the EU. While NIS2 focuses on cybersecurity, CER covers physical threats (natural disasters, terrorism, sabotage) and requires critical entities to conduct risk assessments and implement resilience measures. Member states must transpose it alongside NIS2.

Cybersecurity professionals working in critical infrastructure must understand how CER complements NIS2. Physical security and cybersecurity convergence roles (e.g., in OT/ICS environments) directly address CER requirements. GRC analysts at critical entities must manage both CER and NIS2 compliance simultaneously.

Determined by member states; must be effective, proportionate, and dissuasive

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?