Regulations
CER Directive: Resilience of Critical Entities Beyond NIS2
NIS2 protects the digital, the CER directive protects the physical. They are two sides of the same European design for critical infrastructure, and NIS2 entities often fall under the CER too.
Two directives, one design
When European legislation on critical infrastructure comes up, NIS2 takes almost all the attention. But it travels in pairs with a less cited and equally relevant directive: the CER, Critical Entities Resilience, on the resilience of critical entities.
The distinction is clear and worth keeping in mind. NIS2 protects the digital world: information systems, networks, cybersecurity. The CER protects the physical and operational world: the ability of a critical entity to keep delivering essential services in the face of any threat, not just cyber. Physical sabotage, natural disasters, hybrid attacks, catastrophic failures. Together they cover the two dimensions of the same risk.
For anyone running OT environments, this convergence is natural: a plant that delivers an essential service is vulnerable both to a cyber attack and to a physical act against its infrastructure, and the two often combine.
What the CER protects
The CER directive shifts the centre of gravity from data protection to service continuity. The underlying question is not "are my systems safe from hackers?", but "is my organisation able to keep delivering the essential service whatever happens?".
This broadens the spectrum of threats considered well beyond cyber:
- Physical attacks and sabotage against facilities.
- Natural events and emergencies (floods, earthquakes, heatwaves affecting energy grids).
- Hybrid threats that combine physical and digital actions.
- Insider threats and critical dependencies on third parties.
The sectors covered largely mirror the essential ones under NIS2: energy, transport, water, healthcare, digital infrastructure, public administration, space, food production and distribution.
The obligations in practice
The entities identified as critical by member states must adopt a set of measures that, in substance, build a resilience programme:
- Risk assessment: analyse the threats relevant to the entity and its own physical and operational vulnerabilities, with periodic updates.
- Resilience measures: technical and organisational controls to prevent incidents, protect sites, manage emergencies, ensure continuity and recovery.
- Incident notification: report to the authorities those events that interrupt or risk significantly interrupting the delivery of essential services.
- Personnel security: screening of people who access sensitive functions and sites, and management of physical access.
The recurring emphasis is continuity: prevent the interruption, and when that is not possible, recover quickly.
The relationship with NIS2
The European legislator designed the two directives in coordination, and this is the practical key for companies. There is a broad, intended overlap: many entities that are critical under the CER are also essential entities under NIS2. The stated goal is to prevent the same organisation from running two separate and disconnected programmes.
For those subject to both, the sensible approach is a single risk management programme covering the cyber dimension (NIS2) and the physical and operational one (CER), with integrated risk assessments and coordinated incident notification. Treating them as two distinct compliance exercises is wasteful and a source of inconsistencies.
Transposition and what to do now
Like NIS2, the CER is a directive and lives through the national transposition of each member state, which identifies the critical entities and defines the application details. The timing and the formal identification of entities are the reference to monitor at national level.
In the meantime, here are the actions that do not require waiting for the regulatory detail:
- Map your exposure: does the organisation deliver essential services in the covered sectors? Is it plausible that it will be identified as a critical entity?
- Integrate the programmes: anyone building NIS2 compliance should design it from the start to accommodate the physical and continuity dimension of the CER, instead of having to bolt it on later.
- Assess risk across the full spectrum: extend the risk analysis beyond cyber, including physical, hybrid and service continuity threats.
The CER is a reminder of a truth that OT knows well: the security of a critical infrastructure is not decided only in the bits. It is also decided at the gates, in the emergency generators and in the ability to keep operating when something, of whatever nature, goes wrong.
The MON5 angle
The service continuity that the CER directive puts at the centre also runs through the control systems that deliver it: without knowing which OT assets sustain the essential service, the required risk assessment remains incomplete. MON5 starts here: assessment and passive asset discovery build the map of plants and dependencies without stopping production.
Continuous monitoring and the correlation of vulnerabilities with real exposure then feed a single risk management programme, useful both for NIS2 and for the operational dimension of the CER. To understand where your organisation stands today, request an OT assessment.
Related articles
Regulations
NIS2 Is Here: Now What? An Operational Guide to Your Next Steps
The NIS2 directive has been transposed: what matters now is what to do in practice. From entity classification to OT asset visibility, an operational checklist.

Regulations
Cyber Resilience Act: What Changes for OT and IoT Device Manufacturers
The Cyber Resilience Act introduces security obligations for manufacturers of products with digital elements. For OT and IoT device makers, the compliance scope is broad and the deadlines are approaching.

Cybersecurity
The Iberian Blackout: Lessons for Critical Energy Infrastructure
The blackout that brought Spain and Portugal to a standstill shows how fragile energy grids are and why visibility into OT assets is decisive.
Do you have visibility into your OT network?
MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.
Learn more about the regulation: NIS2