Entity risk assessment
Within nine months of notification, an all-hazards assessment of the risks that could disrupt your essential services, refreshed at least every four years.
Europe's physical resilience law for the organisations it cannot afford to lose. Member states identified their critical entities by 17 July 2026; if a designation letter has reached you, your compliance clock is already running.
CER runs on a fixed cascade: member states transpose, identify their critical entities, and each notified entity then has nine months to assess its risks and ten before the resilience obligations of Chapter III apply.
Entity deadlines assume notification by 17 August 2026. A later designation letter shifts your dates accordingly: nine months to the risk assessment, ten to the obligations.
CER is all-hazards: sabotage, terrorism, insider threats and natural hazards, not just cyber. The obligations centre on demonstrable control of your physical operation.
Within nine months of notification, an all-hazards assessment of the risks that could disrupt your essential services, refreshed at least every four years.
Prevent, protect, respond, mitigate and recover. Explicitly includes adequate physical protection of premises and infrastructure: perimeter, detection and access controls.
Manage who holds sensitive roles and access, with background checks: identity verification and criminal records for defined categories of personnel.
Notify significant incidents without undue delay and within 24 hours of awareness, including cross-border and cross-sector effects.
Competent authorities can inspect sites, audit your measures and issue binding orders; national law attaches penalties.
CER covers the physical half of resilience; NIS2 covers the cyber half. Most designated critical entities must satisfy both regimes at once.
Member states designate critical entities per sector on the basis of their national risk assessments. Designation is individual: you are in scope when the letter says so.
In the Netherlands roughly 500 organisations are expected to be designated under the Wwke.
Fences and cameras protect sites; they do not govern who can open what. Identity-governed physical access turns CER's paper obligations into an operating model with evidence built in.
Adequate physical protection of premises and critical infrastructure, including access controls.
Every key and access point is bound to an identity and a policy: who may open what, where, in which time window.
Employee security management and background checks for sensitive roles.
Sensitive-area access follows verified identity and role, and is revoked the day the role ends, for employees and contractors alike.
An all-hazards risk assessment of what could disrupt essential services.
A complete, current inventory of physical access: which key opens which door, who holds it, and where the exposure concentrates.
Incident notification within 24 hours of awareness.
Reconstruct who accessed what, when and on whose approval from one audit trail, within the notification window.
On-site inspections and audits by the competent authority.
Inspection-ready reporting: certification runs, exception lists and full access history on demand.
The Netherlands transposed CER through the Wet weerbaarheid kritieke entiteiten, approved by the Senate on 7 July 2026 and in force since 15 August 2026, together with the implementing decree Besluit weerbaarheid kritieke entiteiten. Sector ministries now designate critical entities; each notified organisation gets nine months for its risk assessment and ten before the resilience obligations apply.
Nine months to a risk assessment, ten to demonstrable resilience. See how identity-governed physical access gets a critical entity inspection-ready, and what it saves along the way.