CER Directive
Also known as: Critical Entities Resilience Directive, Directive (EU) 2022/2557
The EU law that makes the operators of vital services like power and water able to withstand floods, sabotage and other physical threats.
Draft - this entry has not been reviewed yet.
Formal
Directive (EU) 2022/2557, under which each member state names the critical entities in 11 sectors by 17 July 2026; those entities must assess their risks, take physical and organisational measures and report serious disruptions within 24 hours. Member states had to write it into national law by 17 October 2024; the Danish law applies from 1 July 2025.
In plain English
Protecting a dam is not only about who knows the control-room code - it is also the fence, the spare generator and the plan for the day the river rises.
In practice
A Danish energy company named as a critical entity maps risks such as storms and sabotage, adds fences, cameras and backup power at its key sites, screens staff in sensitive roles and rehearses restoring supply after a site is hit.
Why it matters
Society grinds to a halt when power, water, transport or hospitals fail, and a cut cable or a flooded pumping station does as much damage as a hacker; cyber rules alone leave that side uncovered.
How to put it into practice
The usual steps, in order. Adapt them to your organisation.
- Check whether your sector and type of entity are listed in the annex to the Danish CER Act (lov nr. 433 of 6 May 2025); banking, financial market infrastructure and digital infrastructure are exempt from most duties (§ 1(6)), and IT systems covered by the NIS2 Act stay under NIS2 (§ 1(2)).
- Provide the information the sector minister asks for when deciding whether you are critical (§ 3(4)); entities are identified by 17 July 2026, and each one is told its duties and start date within one month (§ 3(5)).
- Name a contact person, send the contact details to the competent authority, and report any changes (§ 7).
- Within nine months of the notice, carry out a risk assessment of all natural and human-made risks that can disrupt your essential services, including dependencies on other sectors, based on the national risk assessment (§ 5); update it when needed and at least every four years.
- Within ten months of the notice, put the § 6 measures in place, from prevention and climate adaptation, physical protection such as fences, detection and access control, and crisis management to business continuity with alternative supply chains, personnel security and staff awareness.
- Describe the measures in a resilience plan (§ 6(2)), and decide which roles need a background check under the rules issued under § 9.
- Write an incident procedure that notifies the competent authority without undue delay and at the latest 24 hours after you become aware of a significant disruption, and sends a detailed report within one month if the authority asks for it (§ 8).
- Keep documentation ready for supervision, since the authority can inspect sites without a court order and demand an audit (§ 14), issue orders (§ 15), and violations are punished by fines (§ 17).
- Test continuity and crisis plans in exercises, and review the risk assessment, plan and measures after incidents and major changes, reporting the results to management.
Common pitfalls
- Treating CER as a guarding job of fences and cameras, without a risk assessment that traces each scenario to specific measures and tested continuity plans.
- Mixing up the two laws, although the IT systems are protected under the NIS2 Act, while CER covers the physical and organisational ability to keep the service running.
- Assessing only your own sites and forgetting your dependence on power, telecom, transport and key suppliers, which § 5 requires you to consider.
- Waiting until the ten-month deadline is close, when a risk assessment, a resilience plan and background-check procedures take many months to get right.
Good guides
- Critical infrastructure resilience at EU-level(opens in a new tab) · European Commission
- Lov nr. 433 af 6. maj 2025 om kritiske enheders modstandsdygtighed (CER-loven)(opens in a new tab) · Retsinformation (in Danish)
- CER-loven - krav til modstandsdygtighed hos kritiske enheder(opens in a new tab) · Styrelsen for Samfundssikkerhed (in Danish)
- Hvornår træder CER-loven i kraft? - Tidsplan for implementering(opens in a new tab) · Styrelsen for Samfundssikkerhed (in Danish)
Technical deep dive
Directive (EU) 2022/2557 was adopted on 14 December 2022 alongside NIS2 (Directive (EU) 2022/2555) and repeals Directive 2008/114/EC, the old European Critical Infrastructure directive that covered only energy and transport assets and was widely seen as ineffective because it protected installations rather than the entities operating them. CER shifts the unit of regulation from the asset to the operator: a "critical entity" is an entity in one of the eleven Annex sectors (energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, public administration, space, food production, distribution and processing) that provides an essential service, operates on the member state's territory and for which an incident would have a significant disruptive effect under the Article 7 criteria (number of users, dependency of other sectors, market share, geographic spread, availability of alternatives).
The obligations cascade in a fixed order. Each member state had to adopt a national resilience strategy (Art. 4) and carry out a national risk assessment (Art. 5), and then identify its critical entities by 17 July 2026 (Art. 6) and notify them within one month. From notification, the entity has nine months to perform its own all-hazards risk assessment (Art. 12), repeated when necessary and at least every four years, and ten months to implement resilience measures under Art. 13(1)(a)-(f): prevention including disaster risk reduction and climate adaptation, physical protection of premises (fencing, barriers, perimeter monitoring), response and crisis management, recovery through business continuity and alternative supply chains, personnel security management, and awareness and training. These measures must be documented in a resilience plan. Art. 14 lets member states provide for background checks on staff in sensitive roles, and Art. 15 requires notification of significant incidents within 24 hours of awareness, followed where relevant by a detailed report within one month.
The boundary with NIS2 is explicit and often misread. Under Art. 8, entities identified in the banking, financial market infrastructure and digital infrastructure sectors are exempt from Art. 11 and Chapters III, IV and VI, because DORA and NIS2 already cover their resilience; conversely, every CER critical entity is treated as an essential entity under NIS2, so its cyber measures follow NIS2 Art. 21 while its physical and organisational resilience follows CER. Entities that provide the same or similar essential services to or in six or more member states can be designated as of particular European significance (Art. 17) and may receive Commission advisory missions (Art. 18).
In Denmark the directive is transposed by the CER-loven (lov om kritiske enheders modstandsdygtighed), in force since 1 July 2025, with Styrelsen for Samfundssikkerhed coordinating and sector authorities identifying and supervising entities. A practical failure mode is treating CER as a security-guard exercise: auditors look for a risk assessment that traces from hazard scenarios (flood, sabotage, supply-chain loss, pandemic absenteeism) to specific measures and tested continuity plans, not just fences and cameras.
What to learn first
Everything this builds on, foundations first.
- Asset inventory
- →Availability
- →Critical assets
- →CER Directive
Relationships
- A kind of
- EU directive
- Requires
- Critical assets
- Don't confuse with
- NIS2 Directive
Sources & further reading
Standards & official texts
- Directive (EU) 2022/2557 on the resilience of critical entities · European Union
Official documentation
- Tre nye love styrker Danmarks beredskab og sikkerhed i kritisk infrastruktur · Styrelsen for Samfundssikkerhed
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…