← The Key2XS journal
ASSA Abloy Cliq

Adapting to the CER Directive: Organizational Changes in Facility Management and ICT

May 27, 2025 · 3 min read · by the Key2XS team

Adapting to the CER Directive: Organizational Changes in Facility Management and ICT

In short: The CER Directive forces organizational change, not just paperwork: facility management and ICT can no longer operate in silos. Physical access must be governed with the same rigor as digital access, which reshapes roles, processes and tooling in both departments.

Adapting to the CER Directive: Organizational Changes in Facility Management and ICT
(Part 2 of our CER Series)

With the enforcement of the Critical Entities Resilience (CER) Directive across the European Union, critical infrastructure operators are facing not just a compliance challenge, but a strategic shift in how their organizations are structured and managed — particularly within Facility Management and Information & Communication Technology (ICT) departments.

The CER Directive, which aims to ensure the resilience of critical entities against a broad spectrum of risks, requires far-reaching changes that affect operational protocols, governance models, and internal collaboration frameworks.

 


 

1. Facility Management: From Maintenance to Mission-Critical Security

Historically viewed as operational support, Facility Management (FM) is now elevated to a frontline security role under CER:

 


 

2. ICT: From Support System to Integrated Risk Engine

The CER Directive expands the role of ICT beyond traditional cybersecurity, placing it at the heart of resilience planning and real-time risk management:

 


 

3. Cross-Functional Governance and New Roles

The CER Directive fosters a convergence of responsibilities, requiring organizations to rethink governance structures:

 


 

Conclusion

The CER Directive is more than a compliance requirement — it is a transformation trigger. Facility Management and ICT are no longer peripheral services; they are now central to an organization’s resilience posture. For critical entities, the challenge lies not only in updating systems, but in aligning people, processes, and technology around a shared mission: the protection of Europe’s most vital infrastructure.

Written by the Key2XS team

Key2XS is founder-run. Questions about this piece land with the people who built the platform. Talk to us.

Govern the keys you already have

See identity, policy and physical keys in one 30-minute demo, scoped to your estate.