Europe now regulates the physical and organisational resilience of its critical entities, not just their cybersecurity. The CER Directive pairs with NIS2 at EU level, and Germany's KRITIS regime shows what national implementation looks like. Here is the architecture, the dates and the duties.
The Critical Entities Resilience Directive, Directive (EU) 2022/2557, is the EU's regime for the physical and organisational resilience of critical entities. In force since 16 January 2023 and applying from 18 October 2024, it requires Member States to adopt national resilience strategies, due by 17 January 2026, and to identify their critical entities by 17 July 2026, across eleven sectors including energy, transport, banking, health, water and digital infrastructure. Identified entities must assess their risks, take technical and organisational resilience measures, report significant incidents and, where relevant, conduct background checks.
CER is deliberately the twin of NIS2: one addresses the physical and organisational dimension of a critical entity, the other the cyber dimension, and the two are designed to operate in a coordinated way on the same organisations. The practical consequence for leadership is that resilience is now framed as a governance obligation with supervision behind it, not an operational courtesy.
KRITIS is Germany's long established national expression of the same idea. Under the BSI Act, operators of critical infrastructure above the thresholds of the KRITIS regulation must implement technical and organisational measures to the state of the art, prove their effectiveness to the federal office every two years and report significant incidents; Germany is extending this regime from cyber to all hazards physical resilience through the planned KRITIS umbrella act transposing CER. Together with the Swiss ISG and Austria's network and information security law, this forms the DACH landscape our clients most often navigate.
They are twin directives on the same critical organisations: CER governs physical and organisational resilience, all hazards, while NIS2 governs cybersecurity and incident reporting. An identified critical entity should expect to answer to both, through one coherent capability rather than two programmes.
Eleven: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, public administration, space, and food production and distribution.
Member States must identify their critical entities by 17 July 2026, on the basis of national strategies due by 17 January 2026. Organisations in the eleven sectors should not wait for the letter: the duties are foreseeable and the capability takes longer to build than the deadline leaves.
The established German critical infrastructure regime under the BSI Act: operators above the KRITIS regulation thresholds must implement state of the art measures, prove them to the BSI every two years and report incidents. Germany is extending the regime from cyber to physical resilience through the planned KRITIS umbrella act that transposes CER.
Not directly, as Switzerland is not an EU Member State, but Swiss critical infrastructure operators carry the parallel ISG duties, and Swiss groups with EU operations are frequently pulled into CER and NIS2 through their subsidiaries. See our Swiss ISG briefing.
The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.
From scope determination to Article 21 measures and 24 hour reporting readiness under Directive (EU) 2022/2555.
Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.
BIA, ISO 22301 aligned strategy, plans and validation: a continuity programme built to survive contact with a real disruption.
Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.
Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.
The risk you inherit from suppliers and shared platforms: mapped, assured, contracted and exercised, per ISO 28000, NIS2 and DORA.
The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.
From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.
The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.
Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.
Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.
Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.
Ask us for a CER readiness assessment: your likely designation, your gaps against the duties, and the sequence to close them by the dates that matter.
Book a consultation