The Critical Entities Resilience Directive, CER, has entered a new phase.
The deadline for EU Member States to transpose Directive (EU) 2022/2557 into national legislation expired on 17 October 2024. Member States subsequently had until 17 January 2026 to establish their national resilience strategy and carry out the required risk assessments. The next major deadline passed on 17 July 2026, when Member States were required to identify their critical entities.
That changes the nature of CER. For organisations designated as critical entities, the question is no longer when Europe will implement CER. The question is when their individual compliance obligations become enforceable.
The European CER framework is built around four important milestones:
17 October 2024. National transposition
EU Member States were required to transpose CER into national legislation.
17 January 2026. National strategy and risk assessment
Member States were required to establish a national strategy for the resilience of critical entities and perform the required national risk assessments.
17 July 2026. Identification of critical entities
Member States were required to identify the organisations considered critical under the Directive.
Up to 10 months after notification. Operational compliance
Once an organisation has been formally notified that it is a critical entity, its own implementation clock starts.
This last point is particularly important. There is no single European date on which every company suddenly has to comply with all CER operational requirements. The effective deadline depends on when the competent national authority formally notifies an organisation of its designation.
Under Article 6 of the CER Directive, Member States must notify organisations within one month after identifying them as critical entities. From that notification date:
Within 9 months, the critical entity must perform its own risk assessment.
Within 10 months, the Chapter III resilience obligations become applicable.
For an organisation notified on 17 August 2026, for example, this creates the following timeline:
|
Milestone |
Deadline |
|---|---|
|
Identification as critical entity |
17 July 2026 |
|
Latest notification |
17 August 2026 |
|
Entity risk assessment completed |
17 May 2027 |
|
CER resilience obligations fully applicable |
17 June 2027 |
The actual dates may be earlier if the national authority identifies and notifies an organisation earlier.
This makes 2026 and the first half of 2027 the critical implementation period for European operators of essential infrastructure.
Implementation has not happened at the same speed across Europe.
According to the Key2XS CER Implementation Tracker, most Member States have now communicated national implementation measures. The tracker recorded implementation measures for 19 of the 27 EU Member States in its February 2026 dataset.
Since then, important developments have taken place. Germany and the Netherlands, among others, have completed major parts of their national implementation.
The European picture can therefore broadly be divided into three groups.
The following countries had notified implementation measures according to the CER implementation data available through EUR-Lex and the Key2XS CER Tracker:
Austria
Implementation measures notified. Latest notification recorded on 24 October 2025.
Belgium
Implementation measures notified. Latest notification recorded on 19 January 2026.
Croatia
Implementation measures notified. Latest notification recorded on 17 June 2025.
Cyprus
Implementation measures notified. Latest notification recorded on 22 July 2025.
Czech Republic
Implementation measures notified. Latest notification recorded on 19 August 2025.
Denmark
Implementation measures notified. Latest notification recorded on 10 July 2025.
Estonia
One of the earlier Member States to implement CER. Measures were notified from November 2024.
Finland
CER legislation entered into force on 1 July 2025. Finnish authorities subsequently worked towards identifying critical entities by the statutory deadline of 17 July 2026.
Germany
Germany implemented CER through the KRITIS-Dachgesetz. The Act entered into force on 17 March 2026. Further ordinances and implementation measures are still being developed, including rules determining which installations fall within the scope of the legislation.
Greece
National implementation measures have been notified.
Hungary
A substantial package of national measures has been communicated as part of CER implementation.
Ireland
Ireland implemented CER through the European Union (Resilience of Critical Entities) Regulations 2024 and was one of the countries to complete implementation relatively early.
Italy
Italy was among the earliest Member States to notify CER implementation measures, in September 2024.
Latvia
Implementation measures notified, with the latest notification recorded in January 2026.
Lithuania
Multiple national measures have been adopted and notified.
Luxembourg
Luxembourg adopted its national CER framework through the Law of 5 May 2026 on the resilience of critical entities. It has also adopted a national Strategy for Strengthening the Resilience of Critical Entities.
Malta
Implementation measures were notified in January 2026.
Netherlands
The Netherlands implemented CER through the Wet weerbaarheid kritieke entiteiten, Wwke.
The Dutch Parliament completed the legislative process in July 2026. The Wwke and associated regulations entered into force on 15 August 2026.
Approximately 500 organisations are expected to fall within the Dutch CER framework. They cover sectors including energy, transport, drinking water, wastewater, healthcare, digital infrastructure, government, banking, financial market infrastructure, space, nuclear infrastructure and food.
For Dutch organisations, 15 August 2026 is therefore an important date. The implementation debate is over. The supervisory and compliance phase has started.
Portugal
National implementation measures were notified in March 2025.
Romania
Implementation measures were notified from December 2024.
Slovakia
National implementation measures were notified from January 2025.
Slovenia
Implementation measures were notified in June 2025.
Not every Member State met the original European timetable.
The European Commission initiated infringement procedures against Member States that had failed to fully transpose or notify CER implementation measures.
As recently as April 2026, the Commission decided to refer Bulgaria, France, Luxembourg, the Netherlands, Poland, Spain and Sweden to the Court of Justice of the European Union for failure to transpose the Directive or communicate the required measures.
That list should not be interpreted as the current implementation status of every country. Luxembourg and the Netherlands, for example, subsequently completed important legislative steps. It does demonstrate something else.
CER implementation across Europe has been highly asynchronous.
For international operators, this matters. A company operating energy infrastructure, transport assets, telecom sites, water facilities or data centres in multiple European countries may face different national legislation, authorities, designation processes and effective compliance dates.
The underlying European obligation, however, is the same.
|
Country |
CER implementation position |
Operational timeline |
|---|---|---|
|
Austria |
Implemented |
Entity-specific after notification |
|
Belgium |
Implemented |
Entity-specific after notification |
|
Bulgaria |
Delayed / EU enforcement proceedings |
National process still relevant |
|
Croatia |
Implemented |
Entity-specific after notification |
|
Cyprus |
Implemented |
Entity-specific after notification |
|
Czech Republic |
Implemented |
Entity-specific after notification |
|
Denmark |
Implemented |
Entity-specific after notification |
|
Estonia |
Implemented |
Entity-specific after notification |
|
Finland |
Implemented |
Entity designation underway/completed |
|
France |
Delayed implementation |
National implementation determines activation |
|
Germany |
KRITIS-Dachgesetz in force since 17 March 2026 |
Further implementing rules being introduced |
|
Greece |
Implemented |
Entity-specific after notification |
|
Hungary |
Implemented |
Entity-specific after notification |
|
Ireland |
Implemented |
Entity-specific after notification |
|
Italy |
Implemented |
Entity-specific after notification |
|
Latvia |
Implemented |
Entity-specific after notification |
|
Lithuania |
Implemented |
Entity-specific after notification |
|
Luxembourg |
Law adopted 5 May 2026 |
Entity-specific after notification |
|
Malta |
Implemented |
Entity-specific after notification |
|
Netherlands |
Wwke in force 15 August 2026 |
Designation triggers entity obligations |
|
Poland |
Delayed implementation |
National process still relevant |
|
Portugal |
Implemented |
Entity-specific after notification |
|
Romania |
Implemented |
Entity-specific after notification |
|
Slovakia |
Implemented |
Entity-specific after notification |
|
Slovenia |
Implemented |
Entity-specific after notification |
|
Spain |
Delayed implementation |
National process still relevant |
|
Sweden |
Delayed implementation |
National process still relevant |
Because national implementation continues to develop, organisations should always verify their current national status and competent authority.
This is one of the most important misunderstandings around CER. 17 July 2026 was primarily a deadline for Member States. For companies, the more important event is formal designation and notification.
Imagine an infrastructure operator receives formal notification on 1 September 2026. Its indicative timeline becomes:
1 September 2026. Formal notification.
1 June 2027. Nine-month deadline for its entity risk assessment.
1 July 2027. Ten-month point at which the Chapter III resilience obligations apply.
Waiting until notification before starting the implementation programme would therefore be a risky strategy. Nine or ten months may sound like a substantial period. For a large critical infrastructure operator with thousands of sites, employees, contractors, physical assets and access points, it is not.
CER goes considerably further than traditional business continuity planning. Critical entities must understand the risks that can disrupt their essential services and implement appropriate and proportionate technical, security and organisational measures.
The European Commission published additional Article 13(5) guidance in July 2026 on the measures organisations can take to improve their resilience. The underlying principle is an all-hazards approach. That includes natural events, accidents and technical failures, but also intentional threats such as sabotage, terrorism, unauthorised physical access and other actions capable of disrupting essential services.
This means that physical security can no longer be treated as an isolated facilities-management function.
For critical infrastructure operators, one of the consequences of CER is that access to physical infrastructure increasingly needs the same level of governance as access to information systems.
A transformer station, water installation, telecom site, railway control facility, data centre or other critical asset may be protected by a highly secure lock. But the lock alone does not answer the governance questions CER creates.
Who is authorised to enter?
Why does that person have access?
Who approved it?
Is that person still employed or contracted?
Does the access correspond with their current role?
When does the authorisation expire?
Can access be revoked immediately?
Can the organisation demonstrate this to an auditor or regulator?
And can the organisation reconstruct who had access to a critical asset when an incident occurs?
These are not lock-management questions. They are identity, policy and governance questions.
This is where the convergence between CER, Identity Governance and physical access becomes strategically relevant. Many critical infrastructure organisations already manage digital identities through platforms such as SailPoint, Microsoft Entra ID, Okta or other IAM and IGA systems.
Physical keys and electronic locking systems, however, are often managed through completely separate processes. That creates a governance gap.
An employee may be removed from the corporate identity system while retaining a physical key. A contractor may finish an assignment while access to remote infrastructure remains active. Different electronic locking systems may have different user databases, authorisation models and revocation processes.
CER puts increasing pressure on organisations to close that gap.
Key2XS connects identity governance with electronic key and locking infrastructure, allowing physical access rights to follow the same identity lifecycle, policies and approval structures used for logical access.
The objective is straightforward:
One identity. One policy framework.
Governed access to both digital and physical infrastructure.
2027 will be the year in which critical entities have to demonstrate that CER actually works operationally.
For organisations operating critical infrastructure, that changes the conversation.
The question is no longer:
When will CER become law?
The questions are now:
Have we been designated? When were we notified? When does our nine-month risk assessment deadline expire? When do our ten-month resilience obligations become enforceable? And can we demonstrate control over everyone who has physical access to our critical infrastructure?
Those dates will differ between countries and between organisations. The direction does not. CER is moving European critical infrastructure from policy-based physical security towards demonstrable, auditable and identity-driven physical access governance.
Track the latest national implementation status in the Key2XS CER Directive Implementation Tracker.