Critical Entities Resilience (CER) Directive (EU) 2022/2557

Critical Entities Resilience (CER)

The Critical Entities Resilience (CER) Directive is a new EU law focused on strengthening the physical and operational resilience of vital infrastructure across Europe. Adopted in late 2022 and effective from 2024, CER replaces the older 2008 critical infrastructure rules by expanding the scope to in total 11 key sectors including energy, transport, banking, financial market infrastructure, health care, drinking water, wastewater, digital infrastructure, public administration, space, and food. Its goal is to ensure that organizations providing essential services can withstand and quickly recover from all hazards – whether natural disasters, pandemics, terrorism, sabotage or other threats. Recent crisis situations like COVID-19, geopolitical conflicts, and an increase in sabotage have exposed gaps in resilience, making CER especially timely. Why does it matter? If your company operates in a critical sector, CER likely brings legal obligations (enforced by national authorities with penalties for non-compliance) to systematically manage risks and protect the continuity of services that society relies on. Beyond avoiding penalties, complying with CER builds trust and ensures your organization can continue operations during disruptive events – safeguarding your customers, revenue, and reputation.

Key Requirements for Critical Entities

Under CER, each “critical entity” (an organization officially designated by its country as providing essential services) must meet several important requirements.

  • Identify Essential Services & Critical Assets
    You should start by determining which of your services and infrastructures are “essential” under the directive’s criteria. Member States will formally identify critical entities by mid-2026, however organizations are expected to proactively map their critical services, assets, and dependencies under their own responsibility. This includes understanding what disruptions would count as having a significant impact on society or the economy if your services failed. (Notably, if you are already classified as an essential entity under the NIS2 cybersecurity directive, you are likely within CER’s scope as well.) By knowing your critical services, you can focus resilience efforts where they’re most needed.
  • All-Hazards Risk Assessments
    Critical entities must regularly assess all relevant risks that could disrupt their operations – from natural hazards (fires, floods, storms) to human-made threats (terrorist attacks, insider threats, cyber-attacks, etc.). An initial comprehensive risk assessment is required within a set time after being notified of your critical status (the directive specifies within 9 months of designation), and at least every four years thereafter for updates. This “critical entity risk assessment” should examine worst-case scenarios, cross-sector dependencies (e.g. impacts on energy or digital infrastructure you rely on), and cross-border factors. The outcome should identify your key vulnerabilities and potential impact of various incidents. Being proactive and conducting these assessments now (even before formal designation) is wise, so you can start addressing any gaps in advance.
  • Resilience Measures, Continuity Plans & Physical Protection
    Based on the risk assessment, CER requires entities to implement appropriate and proportionate measures to prevent disruptions and mitigate their impact. In practice, this means developing a robust resilience plan (or updating existing business continuity and emergency plans) covering how you will protect critical facilities and assets, manage different incident scenarios, and maintain or restore essential services during a crisis. Measures typically include strengthening physical security controls at sites (e.g. access control, surveillance, building reinforcements), improving system redundancy and backup arrangements, preparing emergency response procedures, and ensuring backup resources (like auxiliary power or alternative suppliers) are in place. CER also emphasizes organizational measures – for example, establishing clear roles and communication lines for crisis management, and training your personnel so they know how to react if an incident strikes. Regulators will expect that your organization can demonstrate a well-thought-out plan to prevent incidents when possible, protect your infrastructure, and rapidly respond and recover if disruptions occur.
  • Incident Reporting & Response
    Just as with cyber incidents under NIS2, critical entities must notify authorities of major incidents that significantly disrupt (or could disrupt) the essential service. CER mandates prompt reporting – an initial notification within 24 hours of becoming aware of an incident is required, followed by a more detailed report about a month later (with specifics on what happened and the impact). Internally, you need to have an incident response process for all-hazard events: the capability to detect incidents, assess their severity, and escalate quickly. This ties back to having strong monitoring and emergency procedures. Practically, complying with this means ensuring your team knows how to spot incidents early, who to inform, what action to take, and how to collect the necessary information for regulators. It’s important to integrate these processes with your cyber incident response (from NIS2) so that whether it’s a physical attack or a cyberattack, your organization reacts quickly and follows the correct reporting obligations. Being prepared here not only keeps you on the right side of the law, but also helps minimize downtime and damage when something goes wrong.

CER & NIS2 – Coordinated Resilience: It’s important to understand that CER and NIS2 go hand-in-hand. CER focuses on physical and operational resilience of critical services, while NIS2 focuses on cybersecurity resilience. In fact, the law explicitly notes that organizations deemed “essential” under NIS2 are considered to be providing essential services under CER. This means many companies (for example, in energy, transport, health, finance, digital infrastructure) will fall under both directives. Rather than treating them separately, efforts to comply with CER should be aligned with NIS2 compliance. Both require a risk-based approach, incident management, continuity planning, and top-level governance attention. By coordinating CER and NIS2 efforts, you can avoid duplication and ensure that your physical security and cybersecurity programs complement each other. For instance, you might use an integrated risk assessment methodology covering both cyber and physical threats, and a unified incident response plan that triggers the right actions and notifications for any major incident. The aim is to build one cohesive resilience strategy. We spotlight this holistic approach whereas we help map CER requirements alongside NIS2, DORA (for financial sector ICT risks), ISO 27001, and other frameworks so that compliance becomes part of a unified operational resilience program, not an isolated checklist.

Frequently asked questions

What is the CER Directive?

The CER Directive focuses on the resilience of critical entities and essential services. It addresses how organisations prevent, manage and mitigate disruptions that may affect important societal functions.

How does CER differ from NIS2?

NIS2 mainly focuses on cybersecurity and network and information systems. CER has a broader resilience perspective that also covers physical, organisational and operational risks.

Which sectors may be affected by CER?

CER covers critical sectors such as energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space and food.

What should a CER risk assessment include?

A risk assessment should identify essential services, dependencies, threats, vulnerabilities, potential disruptions and consequences. It should also link risks to continuity, protection and recovery measures.

How can CER work be integrated into existing governance?

CER should be integrated with business continuity, crisis management, information security, physical security, supplier governance and management reporting. This makes resilience part of normal governance.

Helping You Comply with CER

At Kristensson, we understand that navigating the new CER Directive can be challenging. Our team offers practical, hands-on support to help your organization achieve compliance while strengthening its overall resilience. We tailor our services to your needs – whether you’re just starting to assess CER’s impact or looking to enhance existing continuity plans. Our support includes.

  • CER Readiness Assessments & Gap Analysis
    We begin by evaluating your current state against CER obligations. This readiness assessment reviews how well your existing risk management, security measures, and continuity plans stack up to the directive’s requirements. Which essential services do you provide? Have you identified all critical assets and relevant risks? Do you have the necessary plans and protections in place? Our consultants conduct interviews and document reviews to map these elements and pinpoint any gaps. You’ll receive a clear gap analysis report outlining where you already meet CER standards and where improvements are needed. This gives you a focused action list and helps prioritize the next steps – usually by risk severity and regulatory urgency. Early gap analysis is invaluable in planning your compliance journey.
  • All-Hazard Risk Assessment & Continuity Planning
    Performing a thorough risk assessment and developing a resilience plan can be complex. Kristensson provides expert facilitation to carry out the required all-hazards risk assessments and translate the findings into robust continuity strategies. We will help your team identify probable threat scenarios (from natural catastrophes to malicious acts), evaluate impacts, and assess existing controls. With that foundation, we assist in formulating or updating your business continuity and crisis management plans to address those risks. This includes designing incident response procedures, emergency contact routes, backup resource arrangements, and site-specific protection measures. Our experts bring best practices from international standards (e.g. ISO 22301 for business continuity) and tailor them to your organization’s context. The result is a practical resilience plan and set of technical/organizational measures that not only satisfy CER’s requirements but truly enhance your ability to keep running through adversity.
  • Governance, Roles & Process Support
    Building resilience is not just about documents, it requires the right governance and culture. We work with you to establish a governance framework for CER compliance and resilience management. This often means defining clear roles and responsibilities (for example, assigning a resilience or continuity manager if you don’t have one), setting up overview structures (like steering committees or management reporting for resilience topics), and integrating CER oversight into your existing corporate governance. Kristensson can help draft or refine policies and procedures so that risk assessment, continuity planning, physical security, and incident handling processes are formalized and repeatable. We also assist in training leadership and staff on these processes – ensuring everyone knows their role in maintaining resilience. By embedding CER responsibilities into your organization (from management down to operational teams), you create a sustainable compliance culture where resilience isn’t an afterthought but a core part of how you operate.
  • Integration with NIS2, ISO 27001 & Operational Resilience
    Many CER requirements overlap with other regulations and standards your organization might already follow. Our consultants help you leverage existing frameworks to meet CER obligations efficiently. For example, if you have a ISO 27001 Information Security Management System or are working on NIS2 cybersecurity compliance, we map CER’s expectations to those controls and vice versa. This integration avoids reinventing the wheel – we align policies (like incident management, supplier risk management, crisis communication) so they fulfill both CER and NIS2 needs. We also ensure that any operational resilience or risk management initiatives you have (from financial sector guidelines, DORA in banking, or internal audit recommendations) are harmonized with CER compliance. The outcome is a unified resilience program where improvements count for multiple mandates. This saves effort and creates consistency. Kristensson’s cross-domain expertise (cybersecurity, physical security, governance) means we can bridge the gaps between different compliance efforts and give you a single coherent roadmap instead of separate silos.
  • Compliance Documentation & Review Preparation
    Regulatory scrutiny on critical entities will be high – authorities may conduct audits or request evidence of compliance. Kristensson supports you in preparing all necessary documentation and records to demonstrate CER compliance. We help document your risk assessment results, resilience plans, security measures, training activities, and incident logs in line with best practices. If you need to formally write a “resilience plan” or similar document mandated by the law, we can co-develop that with you. Additionally, we conduct mock audits and readiness reviews to ensure you’re prepared for any official inspections. Our team will walk through the likely questions or checks a regulator might have – for example, verifying physical security at sites, reviewing policies, or testing incident notification processes – so that you can address any weaknesses before the real audit. We aim to give you confidence that when the authorities come knocking to evaluate your preparedness, you will have well-organized evidence and a solid story to tell.
  • Ongoing Support & Continuous Improvement
    Achieving compliance is not a one-off task; maintaining resilience is an ongoing effort. Kristensson offers flexible ongoing support arrangements to ensure you continue to meet CER (and related) requirements over time. We can operate as an extension of your team – scheduling periodic check-ins, annual risk assessment updates, refresher trainings, and plan drills/exercises to test your preparedness. As regulations evolve or new threat intel emerges, we keep you updated and adjust your resilience program accordingly. Whether you need quarterly advisory sessions, continuous monitoring of compliance controls, or help preparing annual compliance reports, we are available to assist. Our services can be provided as time-bound projects or as part of a longer-term partnership, depending on your needs. This means you have the peace of mind that experts are on hand to guide you not just to the compliance deadline, but beyond – ensuring resilience becomes a sustained business-as-usual practice.

Navigating the CER Directive may seem daunting, but with the right guidance it becomes an opportunity to fortify your organization’s foundations. Kristensson is here to be your trusted partner in this journey. We take a clear, hands-on approach, from initial gap analysis to full implementation and ongoing improvement – to help you comply with confidence. With our support, you can turn CER compliance into a chance to enhance your operations, protect what matters, and reassure customers and regulators that your essential services are resilient.

Ready to strengthen your critical infrastructure resilience?

Selected official sources: European Commission JRC: Critical Entities Resilience; EUR-Lex: Directive (EU) 2022/2557.