CER Directive
Also known as: Critical Entities Resilience Directive, Directive (EU) 2022/2557
The EU law that makes the operators of vital services like power and water able to withstand floods, sabotage and other physical threats.
Draft - this entry has not been reviewed yet.
Formal
Directive (EU) 2022/2557, under which each member state names the critical entities in 11 sectors by 17 July 2026; those entities must assess their risks, take physical and organisational measures and report serious disruptions within 24 hours. Member states had to write it into national law by 17 October 2024; the Danish law applies from 1 July 2025.
In plain English
Protecting a dam is not only about who knows the control-room code - it is also the fence, the spare generator and the plan for the day the river rises.
In practice
A Danish energy company named as a critical entity maps risks such as storms and sabotage, adds fences, cameras and backup power at its key sites, screens staff in sensitive roles and rehearses restoring supply after a site is hit.
Why it matters
Society grinds to a halt when power, water, transport or hospitals fail, and a cut cable or a flooded pumping station does as much damage as a hacker; cyber rules alone leave that side uncovered.
Technical deep dive
Directive (EU) 2022/2557 was adopted on 14 December 2022 alongside NIS2 (Directive (EU) 2022/2555) and repeals Directive 2008/114/EC, the old European Critical Infrastructure directive that covered only energy and transport assets and was widely seen as ineffective because it protected installations rather than the entities operating them. CER shifts the unit of regulation from the asset to the operator: a "critical entity" is an entity in one of the eleven Annex sectors (energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, public administration, space, food production, distribution and processing) that provides an essential service, operates on the member state's territory and for which an incident would have a significant disruptive effect under the Article 7 criteria (number of users, dependency of other sectors, market share, geographic spread, availability of alternatives).
The obligations cascade in a fixed order. Each member state had to adopt a national resilience strategy (Art. 4) and carry out a national risk assessment (Art. 5), and then identify its critical entities by 17 July 2026 (Art. 6) and notify them within one month. From notification, the entity has nine months to perform its own all-hazards risk assessment (Art. 12), repeated when necessary and at least every four years, and ten months to implement resilience measures under Art. 13(1)(a)-(f): prevention including disaster risk reduction and climate adaptation, physical protection of premises (fencing, barriers, perimeter monitoring), response and crisis management, recovery through business continuity and alternative supply chains, personnel security management, and awareness and training. These measures must be documented in a resilience plan. Art. 14 lets member states provide for background checks on staff in sensitive roles, and Art. 15 requires notification of significant incidents within 24 hours of awareness, followed where relevant by a detailed report within one month.
The boundary with NIS2 is explicit and often misread. Under Art. 8, entities identified in the banking, financial market infrastructure and digital infrastructure sectors are exempt from Art. 11 and Chapters III, IV and VI, because DORA and NIS2 already cover their resilience; conversely, every CER critical entity is treated as an essential entity under NIS2, so its cyber measures follow NIS2 Art. 21 while its physical and organisational resilience follows CER. Entities that provide the same or similar essential services to or in six or more member states can be designated as of particular European significance (Art. 17) and may receive Commission advisory missions (Art. 18).
In Denmark the directive is transposed by the CER-loven (lov om kritiske enheders modstandsdygtighed), in force since 1 July 2025, with Styrelsen for Samfundssikkerhed coordinating and sector authorities identifying and supervising entities. A practical failure mode is treating CER as a security-guard exercise: auditors look for a risk assessment that traces from hazard scenarios (flood, sabotage, supply-chain loss, pandemic absenteeism) to specific measures and tested continuity plans, not just fences and cameras.
What to learn first
Everything this builds on, foundations first.
- Asset inventory
- →Availability
- →Critical assets
- →CER Directive
Relationships
- A kind of
- EU directive
- Requires
- Critical assets
- Don't confuse with
- NIS2 Directive
Sources & further reading
Standards & official texts
- Directive (EU) 2022/2557 on the resilience of critical entities · European Union
Official documentation
- Tre nye love styrker Danmarks beredskab og sikkerhed i kritisk infrastruktur · Styrelsen for Samfundssikkerhed
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…