Standards
Directive (UE) 2022/2557 — CERUnion européenne

Resilience of critical entities

The physical counterpart to NIS 2. Where NIS 2 covers cyber, CER covers the overall resilience of critical entities against natural hazards, malicious acts, health emergencies and sabotage. It mandates a risk assessment, a resilience plan and notification of disruptive incidents.

Official text

Who it applies to

  • Critical infrastructure operators
  • Security and continuity functions
  • Sector authorities

Structuring points

  • The resilience plan covers prevention, protection, response, mitigation and recovery
  • Background checks for sensitive staff are explicitly contemplated
  • Complementary to NIS 2: an entity can fall under both texts

Designated critical entities across eleven sectors, including energy, transport, banking, health and drinking water.