← The Key2XS journal
ASSA Abloy Cliq

Accountability and Legal Liability Under the CER Directive: What Critical Entities Must Prepare For

May 28, 2025 · 4 min read · by the Key2XS team

Accountability and Legal Liability Under the CER Directive: What Critical Entities Must Prepare For

In short: The CER Directive makes critical entities legally accountable for resilience, up to and including management liability. Preparing means demonstrable risk assessments, resilience measures and incident reporting — with physical access control among the obligations auditors will test.

Accountability and Legal Liability Under the CER Directive: What Critical Entities Must Prepare For (Part 3 of our CER Series)

The Critical Entities Resilience (CER) Directive, adopted by the European Union in 2022, introduces a powerful legal and operational framework to safeguard Europe’s essential services. From energy and water to transport and digital infrastructure, operators deemed “critical” now face a heightened level of accountability — not only in operational terms but also in legal exposure.

As the directive is transposed into national legislation across EU member states, organizations must understand the new liabilities it imposes on executives, board members, and operational leaders. Compliance is no longer a technical checkbox; it is a matter of legal responsibility.

 


 

1. A Shift from Voluntary to Enforceable Resilience Obligations

Prior to the CER Directive, many resilience activities — such as risk assessments or continuity planning — were considered best practices rather than enforceable requirements. The CER changes this by introducing mandatory risk management measures tailored to each critical entity’s threat landscape.

Failure to implement these measures, or to report disruptions and incidents as required, may now lead to administrative penalties, civil liability, or even criminal sanctions, depending on national transposition.

 


 

2. Management Accountability: The Personal Risk for Executives

The directive emphasizes that responsibility for compliance lies at the top level of management:

 


 

3. Legal Exposure from Supply Chains and Outsourcing

The CER Directive requires entities to assess and mitigate risks not just internally, but across their entire value chain, including contractors, third-party suppliers, and service providers.

 


 

4. Reporting Requirements and Legal Consequences of Non-Disclosure

Entities must report any incident that significantly disrupts critical operations within strict timelines. These obligations resemble those under GDPR, and failure to report can lead to:

 


 

5. Strengthening Legal Readiness: What Organizations Must Do

To avoid legal pitfalls and demonstrate compliance:

 


 

Conclusion

The CER Directive is a wake-up call for Europe’s critical sectors: resilience is now a legal obligation, not a recommendation. Organizations must act swiftly to close governance gaps, upgrade their legal preparedness, and embed accountability into their core strategy. In the age of hybrid threats and systemic interdependencies, resilience isn’t just operational — it’s a matter of legal survival.

Written by the Key2XS team

Key2XS is founder-run. Questions about this piece land with the people who built the platform. Talk to us.

Govern the keys you already have

See identity, policy and physical keys in one 30-minute demo, scoped to your estate.