Compliance
CER

CER Directive — Critical Infrastructure Resilience in the EU

Complete guide to the Critical Entities Resilience Directive — protecting essential services from physical and natural threats.

What is CER?

The Critical Entities Resilience Directive (EU) 2022/2557 replaces the 2008 European Critical Infrastructure Directive. It establishes a comprehensive framework to strengthen the resilience of critical entities that provide essential services in the EU against non-cyber threats including natural hazards, terrorist attacks, insider threats, and sabotage. It covers 11 sectors and complements the NIS2 Directive, which addresses cybersecurity. Member States had to transpose it into national law by 17 October 2024.

Who It Applies To

Critical entities identified by Member States across 11 sectors: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, and food.

Key Articles & Obligations

Article 1

Article 2

Article 4

Article 5

Article 6

Article 8

Article 12

Article 13

Article 15

Article 21

Key Deadlines

Transposition deadline

17 Oct 2024

Member States had to transpose the CER Directive into national law.

National risk assessment

17 Jan 2026

Member States must complete their national risk assessment.

Entity identification

17 Jul 2026

Member States must identify critical entities under the new framework.

Fines & Enforcement

Determined by Member States as part of transposition. Must be effective, proportionate, and dissuasive.

Critical Entity Obligations

Identified critical entities must take specific measures to ensure the resilience of their essential services.

  • Carry out risk assessments within nine months of notification
  • Take appropriate technical, security, and organisational measures to ensure resilience
  • Notify incidents that significantly disrupt essential services within 24 hours
  • Cooperate with competent authorities and participate in advisory missions
  • Entities of particular European significance (serving 6+ Member States) face additional obligations

How Law4Devs Helps with CER Compliance

Law4Devs provides the full CER Directive as structured JSON. Query by sector, obligation type, or entity classification. Cross-reference with NIS2 for combined cyber and physical resilience.

Related Regulations

Query CER via API

GET /v1/frameworks/cer/articles
200 OK · structured JSON · official EUR-Lex source

Frequently Asked Questions

What is the CER Directive?

The Critical Entities Resilience Directive (EU) 2022/2557 replaces the 2008 European Critical Infrastructure Directive (ECI). It establishes a comprehensive framework to strengthen the resilience of critical entities that provide essential services in the EU against non-cyber threats including natural hazards, terrorist attacks, insider threats, and sabotage. It covers 11 sectors and complements the NIS2 Directive, which addresses cybersecurity. Member States had to transpose it into national law by 17 October 2024.

Who does the CER Directive apply to?

The CER Directive applies to critical entities identified by Member States across 11 sectors: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, and food. Member States identify critical entities based on national risk assessments. Entities of particular European significance — those providing essential services to six or more Member States — face additional obligations and coordinated advisory missions.

What are the key obligations and deadlines?

Critical entities must carry out risk assessments within nine months of notification, take appropriate technical, security, and organisational measures to ensure resilience, and notify incidents that significantly disrupt essential services within 24 hours. Member States must adopt a national strategy, conduct a national risk assessment by 17 January 2026, and identify critical entities by 17 July 2026. The Commission will adopt a list of essential services and conduct peer reviews of national strategies.

How does Law4Devs help with the CER Directive?

Law4Devs provides the full CER Directive text as structured JSON via API. Query by sector, obligation type, or entity classification. Access provisions on risk assessment requirements, resilience measures, incident notification rules, and supervisory powers. Cross-reference with the NIS2 Directive for a combined cyber and physical resilience compliance picture across your critical infrastructure obligations.

Access CER as Structured JSON

All articles, recitals, and amendments — queryable, filterable, and always up to date.