Home > CER Directive
EU Directive (EU) 2022/2557 · In force since 16 January 2023

EU Critical Entities Resilience Directive (CER)

Europe's physical resilience law for the organisations it cannot afford to lose. Member states identified their critical entities by 17 July 2026; if a designation letter has reached you, your compliance clock is already running.

Transposition deadline 17 Oct 2024 Entity designation 17 Jul 2026 NL: Wwke in force 15 Aug 2026 EU transposition: live tracker below
The CER clock

Designated in 2026, accountable in 2027

CER runs on a fixed cascade: member states transpose, identify their critical entities, and each notified entity then has nine months to assess its risks and ten before the resilience obligations of Chapter III apply.

Today
  1. 16 Jan 2023Directive in force across the EU
  2. 17 Oct 2024National transposition deadline
  3. 17 Jan 2026National resilience strategies and state risk assessments due
  4. 17 Jul 2026Member states identify critical entities; designation letters are landing now
  5. May / Jun 2027Notified entities: risk assessment due 17 May, resilience obligations apply from 17 Jun

Entity deadlines assume notification by 17 August 2026. A later designation letter shifts your dates accordingly: nine months to the risk assessment, ten to the obligations.

What it requires

What a critical entity must be able to prove

CER is all-hazards: sabotage, terrorism, insider threats and natural hazards, not just cyber. The obligations centre on demonstrable control of your physical operation.

ART. 12

Entity risk assessment

Within nine months of notification, an all-hazards assessment of the risks that could disrupt your essential services, refreshed at least every four years.

ART. 13

Resilience measures

Prevent, protect, respond, mitigate and recover. Explicitly includes adequate physical protection of premises and infrastructure: perimeter, detection and access controls.

ART. 13 & 14

Employee security

Manage who holds sensitive roles and access, with background checks: identity verification and criminal records for defined categories of personnel.

ART. 15

Incident notification

Notify significant incidents without undue delay and within 24 hours of awareness, including cross-border and cross-sector effects.

ART. 21

Supervision and enforcement

Competent authorities can inspect sites, audit your measures and issue binding orders; national law attaches penalties.

ALL-HAZARDS

The complement to NIS2

CER covers the physical half of resilience; NIS2 covers the cyber half. Most designated critical entities must satisfy both regimes at once.

Who is in scope

Eleven sectors Europe cannot afford to lose

Member states designate critical entities per sector on the basis of their national risk assessments. Designation is individual: you are in scope when the letter says so.

In the Netherlands roughly 500 organisations are expected to be designated under the Wwke.

EnergyTransportHealthPublic administrationBankingFinancial market infrastructureDrinking waterWaste waterDigital infrastructureSpaceFood production & distribution
Where the directive meets physical access

Resilience you can prove, not just claim

Fences and cameras protect sites; they do not govern who can open what. Identity-governed physical access turns CER's paper obligations into an operating model with evidence built in.

ART. 13

Adequate physical protection of premises and critical infrastructure, including access controls.

Every key and access point is bound to an identity and a policy: who may open what, where, in which time window.

ART. 13 & 14

Employee security management and background checks for sensitive roles.

Sensitive-area access follows verified identity and role, and is revoked the day the role ends, for employees and contractors alike.

ART. 12

An all-hazards risk assessment of what could disrupt essential services.

A complete, current inventory of physical access: which key opens which door, who holds it, and where the exposure concentrates.

ART. 15

Incident notification within 24 hours of awareness.

Reconstruct who accessed what, when and on whose approval from one audit trail, within the notification window.

ART. 21

On-site inspections and audits by the competent authority.

Inspection-ready reporting: certification runs, exception lists and full access history on demand.

See how the platform works →

Live from EUR-Lex

Live: CER transposition across the EU

The Critical Entities Resilience Directive (EU 2022/2557) requires every member state to transpose it into national law. We track the implementing measures notified to EUR-Lex in real time, so you always know where each country stands.

Loading implementation data...
In the Netherlands

Wet weerbaarheid kritieke entiteiten (Wwke)

The Netherlands transposed CER through the Wet weerbaarheid kritieke entiteiten, approved by the Senate on 7 July 2026 and in force since 15 August 2026, together with the implementing decree Besluit weerbaarheid kritieke entiteiten. Sector ministries now designate critical entities; each notified organisation gets nine months for its risk assessment and ten before the resilience obligations apply.

In force
15 August 2026
Expected designations
± 500 organisations
Implementing decree
Stb. 2026, 190
Coordination
NCTV and sector ministries
Keep reading

Latest on CER

All coverage →

Designated? Start the clock with evidence in hand

Nine months to a risk assessment, ten to demonstrable resilience. See how identity-governed physical access gets a critical entity inspection-ready, and what it saves along the way.

Book a demo Build your business case