Glossary · Cross-regulation
CER Directive
Directive (EU) 2022/2557 on the resilience of critical entities — NIS2's sister directive covering physical resilience.
Explained in depth: NIS2 overview
The CER Directive (Critical Entities Resilience) was adopted the same day as NIS2 and covers the non-cyber side of the same problem: the resilience of critical infrastructure against physical threats such as sabotage, terrorism, natural disasters, and pandemics. Member states identify critical entities in sectors largely mirroring NIS2 Annex I, and those entities must perform risk assessments, take physical resilience measures, manage personnel security, and report significant disruptive incidents. The two directives are designed to interlock: an entity identified as critical under CER is automatically an essential entity under NIS2, and authorities on both sides are required to cooperate. In Sweden, CER is implemented alongside Cybersäkerhetslagen through its own national legislation.
Why it matters
Organisations identified under CER face two parallel regimes: NIS2 for their network and information systems, CER for their physical operations. Risk assessments, continuity plans, and incident processes should be built once to serve both.
