Today, 17 July 2026, marks an important milestone under the EU’s Critical Entities Resilience Directive (CER), as Member States are required to identify and designate the entities considered “critical” for the provision of essential services.
Understanding the CER Directive
The CER forms part of the EU’s broader effort to strengthen the resilience of critical infrastructure and essential services. It replaced the earlier European Critical Infrastructure Directive (Directive 2008/114/EC), which had a relatively narrow focus relating to the energy and transport sectors. In contrast, the CER significantly expands both the sectors covered and the range of threats that must be addressed, recognising the significant threats posed by natural hazards, terrorist attacks, insider threats, or sabotage, as well as public health emergencies.
The CER sits alongside the Network and Information Security Directive (NIS2), which entered into force at the same time and shares a similar objective of enhancing the resilience of essential services across the European Union. However, the two regimes address different dimensions of risk. NIS2 focuses principally on cybersecurity and information systems security, whereas the CER adopts an “all-hazards” approach that encompasses physical, operational and organisational resilience. Together, the two frameworks are intended to provide a comprehensive resilience regime for critical services across the EU.
A key milestone in the implementation of the CER is the requirement for Member States to identify critical entities by today, 17 July 2026. Once notified of their designation, most critical entities will have ten months before the CER’s substantive resilience obligations begin to apply to them. As a result, organisations operating in sectors covered by the CER should be assessing now whether they are likely to fall within scope, reviewing existing resilience frameworks and identifying any gaps that may need to be addressed ahead of compliance.
Designation criteria and scope
The CER establishes a framework through which Member States identify critical entities operating in sectors considered essential to societal and economic stability, including: energy; transport; banking; financial market infrastructures; health drinking water; waste water; digital infrastructure; public administration; space; and certain aspects of food production, processing and distribution. With the exception of food production, processing and distribution, these sectors align with those sectors designated as “sectors of High Criticality” under Annex I of NIS2. There are however a few important differences in the way in which those sectors are classified under the CER. For example, the health classification includes entities holding a distribution authorisation under the Medical Products for Human Use Directive – the same classification under NIS2 does not.
An entity may be designated as a critical entity where it provides one or more essential services, operates within a Member State and an incident affecting that entity could have significant disruptive effects on the provision of those services. Unlike NIS2, there is no fixed size threshold – a small water operator, for example, could be designated under CER even if it falls below NIS2’s size threshold. Conversely, a large tech company might be in scope of NIS2 but not designated under CER. Importantly, entities designated as critical under CER automatically qualify as ‘essential entities’ under NIS2, even if they would otherwise have fallen into the ‘important’ tier or been excluded entirely from NIS2 on size grounds. This means that organisations designated as critical under the CER may inadvertently become subject to NIS2 even if they have not assessed themselves as in scope.
After identification, entities will be notified within one month and must comply with resilience requirements within ten months of notification. The CER’s risk assessment and identification process also requires Member States to develop a national strategy that includes comprehensive risk assessments every four years. These risk assessments aim to identify potential threats to essential services provided by critical entities, evaluating natural and man-made hazards, interdependencies between sectors, and the potential cascading effects of disruptions.
Key Compliance Obligations for Critical Entities
Once designated, critical entities become subject to a range of resilience obligations including:
- Risk Assessments
Critical entities must carry out risk assessments to identify threats that could disrupt the provision of essential services. These assessments must consider a broad range of hazards, including natural disasters, malicious acts, insider threats, accidents and supply chain-related risks. The analysis should also take account of dependencies on third parties and other critical sectors. Critical entities must document all of this in a resilience plan that is regularly tested and reviewed.
- Resilience Measures
Following their risk assessments, critical entities must implement appropriate and proportionate technical, organisational and security measures to enhance resilience. Subject to specific conditions set out by each Member State, conduct background checks where required, including on individuals occupying sensitive roles within, or acting on behalf of, the critical entity.
- Incident Notification
The CER also introduces incident reporting obligations. Critical entities must notify the relevant competent authority of incidents that significantly disrupt, or have the potential to significantly disrupt, the delivery of essential services. The initial notification is required within 24 hours of becoming aware of the incident, followed by a detailed report no later than one month after.
- Regulatory Oversight
Competent authorities are granted supervisory powers that include conducting audits and inspections, requesting information and taking enforcement action where necessary. As with NIS2, regulated organisations should expect increased scrutiny of their resilience governance arrangements and associated documentation.
Next Steps for Organisations
Organisations will not be required to comply with the CER’s entity-level obligations unless and until they are formally identified and/or notified as a critical entity by the relevant national authority (noting that in some Member States e.g. Germany and the Czech Republic, secondary legislation is expected to introduce a self-assessment rather than a designation regime). Nevertheless, given the potentially significant work required to complete the risk assessments and implement the necessary resilience and organisational measures within the ten-month compliance period, particularly in light of the uneven pace of implementation across Member States, we recommend that organisations who consider themselves particularly likely to be designated should undertake proportionate preparatory work in advance.
This could include:
- Assessing whether they are likely to fall within scope of the CER based on the essential services they provide and their role within one of the CER’s 11 critical sectors.
- Carrying out a gap analysis against applicable national CER requirements and existing resilience, business continuity and crisis management frameworks.
- Undertaking a preliminary risk assessment including natural hazards, accidents, insider threats, sabotage, supply chain vulnerabilities and cross-sector dependencies.
- Reviewing and strengthen resilience measures, including physical security, operational continuity, incident response, supply chain resilience and recovery arrangements. Develop or update a resilience plan that documents identified risks, mitigation measures, governance arrangements and testing procedures.
- Preparing incident notification procedures to enable compliance with national reporting requirements once designated.
- Considering alignment with related regulatory frameworks, including NIS2.
- Monitoring national implementation measures and designation processes, as Member States continue to finalise and operationalise their CER regimes following today’s designation deadline.
We have dedicated experts working on the CER and other EU Digital Decade laws across DLA Piper. For any further insights on how the CER Directive may apply to your organisation, get in touch with your usual DLA Piper contact.
Recent Comments