EU Regulatory Center
CER — physical resilience for critical entities
Physical and operational resilience obligations for critical entities across eleven sectors, designed to work alongside NIS2’s cyber obligations.
Status
Law in force
Directive (EU) 2022/2557
The Critical Entities Resilience (CER) Directive required transposition into national law by 17 October 2024 — the same deadline as NIS2 — and is designed to be read together with it: CER addresses physical and operational resilience, while NIS2 addresses cybersecurity risk management.
Scope at a glance
| Question | Answer |
|---|---|
| Who | Entities identified by Member States as critical across eleven sectors, including energy, transport, health, water and digital infrastructure. |
| What | Resilience assessments, risk-mitigation measures, and incident-notification obligations for physical and operational disruptions. |
| Relationship to NIS2 | CER and NIS2 share sectoral overlap and are intended to be assessed together, not in isolation. |
| Screening | Entities may also face investment-screening considerations where foreign ownership could affect critical-entity resilience. |
Core obligations
- Conduct a resilience assessment covering physical and operational risks.
- Implement measures to prevent, resist and recover from disruptive incidents.
- Notify the competent authority of incidents that significantly disrupt critical services.
- Coordinate physical-resilience measures with NIS2 cybersecurity obligations where sectors overlap.
General guidance, not legal advice
This page summarizes publicly available regulatory status for general guidance only. Confirm applicability, scope and deadlines with qualified legal counsel before making compliance decisions.
How CYRKIL helps
The Critical Infrastructure industry view reads CER and NIS2 obligations together against the same asset and dependency graph.
See Critical InfrastructureHow CYRKIL tracks this
Every regulatory page here runs through the Regulatory Truth Pipeline — official source, human and legal review, then publish, with the source, version and review date always shown.
See the pipeline