Manage cookies
This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. Visit our cookie policy to learn more.
Manage cookies
Cookie Settings
Cookies necessary for the correct operation of the site are always enabled.
Other cookies are configurable.
Essential cookies
Always On. These cookies are essential so that you can use the website and use its functions. They cannot be turned off. They're set in response to requests made by you, such as setting your privacy preferences, logging in or filling in forms.
Analytics cookies
Disabled
These cookies collect information to help us understand how our Websites are being used or how effective our marketing campaigns are, or to help us customise our Websites for you. See a list of the analytics cookies we use here.
Advertising cookies
Disabled
These cookies provide advertising companies with information about your online activity to help them deliver more relevant online advertising to you or to limit how many times you see an ad. This information may be shared with other advertising companies. See a list of the advertising cookies we use here.
KRITIS and the CER Directive Explained: Critical Entity Resilience | Resilience Guard
Critical infrastructure regulation

KRITIS and CER: resilience as a supervised legal duty.

Europe now regulates the physical and organisational resilience of its critical entities, not just their cybersecurity. The CER Directive pairs with NIS2 at EU level, and Germany's KRITIS regime shows what national implementation looks like. Here is the architecture, the dates and the duties.

The architecture

What are CER and KRITIS?

The Critical Entities Resilience Directive, Directive (EU) 2022/2557, is the EU's regime for the physical and organisational resilience of critical entities. In force since 16 January 2023 and applying from 18 October 2024, it requires Member States to adopt national resilience strategies, due by 17 January 2026, and to identify their critical entities by 17 July 2026, across eleven sectors including energy, transport, banking, health, water and digital infrastructure. Identified entities must assess their risks, take technical and organisational resilience measures, report significant incidents and, where relevant, conduct background checks.

CER is deliberately the twin of NIS2: one addresses the physical and organisational dimension of a critical entity, the other the cyber dimension, and the two are designed to operate in a coordinated way on the same organisations. The practical consequence for leadership is that resilience is now framed as a governance obligation with supervision behind it, not an operational courtesy.

KRITIS is Germany's long established national expression of the same idea. Under the BSI Act, operators of critical infrastructure above the thresholds of the KRITIS regulation must implement technical and organisational measures to the state of the art, prove their effectiveness to the federal office every two years and report significant incidents; Germany is extending this regime from cyber to all hazards physical resilience through the planned KRITIS umbrella act transposing CER. Together with the Swiss ISG and Austria's network and information security law, this forms the DACH landscape our clients most often navigate.

CER
Directive (EU) 2022/2557
Applies from
18 October 2024
Identification
Critical entities by 17 Jul 2026
Germany
BSI Act and KRITIS regime
ONE CRITICAL ENTITY, TWO EUROPEAN DIRECTIVES, ONE NATIONAL REGIMEThe critical entity: one organisation, one resilience postureCER Directive 2022/2557Physical and organisational resilienceRisk assessment and measuresIncident reportingBackground checksIdentification by 17 July 2026NIS2 Directive 2022/2555Cybersecurity risk managementArticle 21 measures24h, 72h, one month reportingManagement accountabilitySupervision and finesNational transpositionGermany: BSI Act, KRITIS regulation and the planned KRITIS umbrella act. Switzerland: ISG. Austria: NISG.The directives are designed to operate as a pair: one entity, one risk picture, two supervised dimensions.
One critical entity under the twin directives: CER for physical and organisational resilience, NIS2 for cyber, both landing through national transposition in Germany, Switzerland and Austria.
The duties

What an identified critical entity must do

Assess the risks. An all hazards risk assessment spanning natural hazards, accidents, sabotage, terrorism and hybrid threats, revisited on a defined cadence and after significant change.
Take resilience measures. Technical and organisational measures proportionate to the risk: physical protection, redundancy, continuity arrangements, and the crisis and recovery capability to withstand and recover from incidents.
Report significant incidents. Notification of incidents that significantly disrupt or could disrupt the essential service, feeding national and European situational awareness.
Verify the people. Background checks for specified categories of personnel where the risk warrants it, a duty that surprises many operators and needs early legal and HR groundwork.
Evidence all of it. Supervision means the capability must be demonstrable: documented, exercised and auditable, which is where our organisational resilience practice and exercise programmes do their work.
Questions

Frequently asked questions

What is the difference between CER and NIS2?+

They are twin directives on the same critical organisations: CER governs physical and organisational resilience, all hazards, while NIS2 governs cybersecurity and incident reporting. An identified critical entity should expect to answer to both, through one coherent capability rather than two programmes.

Which sectors does CER cover?+

Eleven: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, public administration, space, and food production and distribution.

When will we know if we are a critical entity?+

Member States must identify their critical entities by 17 July 2026, on the basis of national strategies due by 17 January 2026. Organisations in the eleven sectors should not wait for the letter: the duties are foreseeable and the capability takes longer to build than the deadline leaves.

What is KRITIS in Germany?+

The established German critical infrastructure regime under the BSI Act: operators above the KRITIS regulation thresholds must implement state of the art measures, prove them to the BSI every two years and report incidents. Germany is extending the regime from cyber to physical resilience through the planned KRITIS umbrella act that transposes CER.

We operate in Switzerland; does CER apply to us?+

Not directly, as Switzerland is not an EU Member State, but Swiss critical infrastructure operators carry the parallel ISG duties, and Swiss groups with EU operations are frequently pulled into CER and NIS2 through their subsidiaries. See our Swiss ISG briefing.

Explore further

Related services

Continuity and resilience

Organisational Resilience

The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.

Explore the service ›
Regulation and crisis

NIS2 Compliance

From scope determination to Article 21 measures and 24 hour reporting readiness under Directive (EU) 2022/2555.

Explore the service ›
Regulation and crisis

Crisis Management

Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.

Explore the service ›
Continuity and resilience

Business Continuity Management

BIA, ISO 22301 aligned strategy, plans and validation: a continuity programme built to survive contact with a real disruption.

Explore the service ›
Continuity and resilience

Business Continuity Exercises

Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.

Explore the service ›
Cyber and security

Cyber Resilience

Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.

Explore the service ›
Cyber and security

Supply Chain Security

The risk you inherit from suppliers and shared platforms: mapped, assured, contracted and exercised, per ISO 28000, NIS2 and DORA.

Explore the service ›
Sector framework

DAEDALUS Airport Resilience Framework

The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.

Explore the service ›
Risk and governance

Risk Management

From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.

Explore the service ›
Regulation and crisis

DORA Compliance

The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.

Explore the service ›
Cyber and security

Information Security

Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.

Explore the service ›
Risk and governance

7A Risk Management Framework

Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.

Explore the service ›
Risk and governance

AI Governance and Resilience

Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.

Explore the service ›
Next step

Be ready before the identification letter arrives.

Ask us for a CER readiness assessment: your likely designation, your gaps against the duties, and the sequence to close them by the dates that matter.

Book a consultation
All consultations are treated with strict confidentiality.