EU Regulatory Center

CER — physical resilience for critical entities

Physical and operational resilience obligations for critical entities across eleven sectors, designed to work alongside NIS2’s cyber obligations.

Status

Law in force
Directive (EU) 2022/2557
The Critical Entities Resilience (CER) Directive required transposition into national law by 17 October 2024 — the same deadline as NIS2 — and is designed to be read together with it: CER addresses physical and operational resilience, while NIS2 addresses cybersecurity risk management.
Reviewed 2026-06 · Source: Official Journal of the European Union

Scope at a glance

QuestionAnswer
WhoEntities identified by Member States as critical across eleven sectors, including energy, transport, health, water and digital infrastructure.
WhatResilience assessments, risk-mitigation measures, and incident-notification obligations for physical and operational disruptions.
Relationship to NIS2CER and NIS2 share sectoral overlap and are intended to be assessed together, not in isolation.
ScreeningEntities may also face investment-screening considerations where foreign ownership could affect critical-entity resilience.

Core obligations

General guidance, not legal advice
This page summarizes publicly available regulatory status for general guidance only. Confirm applicability, scope and deadlines with qualified legal counsel before making compliance decisions.
How CYRKIL helps

The Critical Infrastructure industry view reads CER and NIS2 obligations together against the same asset and dependency graph.

See Critical Infrastructure
How CYRKIL tracks this

Every regulatory page here runs through the Regulatory Truth Pipeline — official source, human and legal review, then publish, with the source, version and review date always shown.

See the pipeline

Get a readiness review against this regulation.