Critical Entities Resilience Directive

Directive 2022/2557 on the resilience of critical entities and repealing Council Directive 2008/114/EC (CER Directive)

Background and Scope

The CER Directive requires Member States to identify critical entities within key societal sectors and to ensure that these entities actively strengthen their capacity to prevent, manage and recover from disruptions. A 2019 evaluation of the previous directive found that protective measures focused solely on individual assets were insufficient to prevent disruptions, given the increasingly interconnected and cross-border nature of critical infrastructure operations. Increasing hybrid threats, climate-related risks and deepening interdependencies between sectors made a stronger and more harmonised EU framework necessary.

The CER Directive takes an all-hazards approach, covering natural, man-made, accidental and deliberate risks. It applies to the following sectors: energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, certain aspects of public administration, space, and the production, processing and distribution of food. Member States are required to identify critical entities within these sectors and support them in meeting their resilience obligations. The Directive requires these entities to actively work on their resilience, meaning their ability to prevent, manage and recover from incidents, rather than merely protecting individual assets.

Cybersecurity falls outside the scope of the Directive and is governed separately by the NIS2 Directive (EU) 2022/2555, adopted on the same date, though Member States must implement the two Directives in a coordinated manner.

Key Obligations

  • Risk assessment: Member States shall ensure that critical entities carry out a risk assessment within nine months of identification, and thereafter at least every four years, covering all relevant risks that could disrupt the provision of essential services.
  • Resilience measures: Member States shall ensure that critical entities take appropriate technical, security and organisational measures to prevent, manage and recover from incidents, and document these in a resilience plan.
  • Incident notification: Member States shall ensure that critical entities notify the competent authority without undue delay of incidents causing or capable of causing a significant disruption to essential services, with an initial notification within 24 hours of becoming aware of the incident.
2029 June 17, 2029

Deadline for the Commission to submit its first periodic report to the European Parliament and the Council on the functioning of the Directive, including an assessment of its added value and effects.

2026 July 17, 2026

Deadline for Member States to identify critical entities for the sectors and subsectors listed in the Annex.

2026 January 17, 2026

Deadline for Member States to adopt a national strategy for the resilience of critical entities and to carry out their risk assessment.

2024 October 17, 2024

Deadline for Member States to adopt and publish the national implementing measures, with application from 18 October 2024. Directive 2008/114/EC was repealed with effect from the same date.

2022 December 14, 2022

The Directive was adopted by the European Parliament and the Council.