What is the CER Directive?
The CER Directive (Critical Entities Resilience Directive) is an EU directive designed to strengthen the resilience of organizations that provide services critical to society and the economy. Its formal designation is Directive (EU) 2022/2557.
CER covers eleven sectors, including energy, transport, banking and financial services, health, drinking water, wastewater, digital infrastructure, public administration, space, and food. Member States must identify critical entities in these sectors and establish requirements for their resilience.
The directive takes a broad approach to risk. Critical entities must be able to prevent, protect against, respond to, resist, and recover from incidents. This includes natural hazards as well as human-made threats such as sabotage, terrorism, and hybrid threats.
CER is closely connected to NIS2. While NIS2 primarily addresses cybersecurity in network and information systems, CER has a broader focus on organizational resilience and continuity.
The CER Directive has been assessed as EEA-relevant. As of 2026, it has not yet been implemented in Norwegian law, and Norwegian authorities are preparing its implementation alongside NIS2.
Sicra and the CER Directive
Organizations affected by CER need to understand which critical services and dependencies they have, which incidents could affect them, and which measures can improve their resilience.
Sicra helps organizations assess security maturity, risk, security strategy, and existing security controls. This can support efforts to identify risks and prioritize measures as organizations prepare for greater resilience requirements. Sicra's security analysis includes security mapping, risk assessment, and prioritized recommendations based on NSM principles.
Services
Security maturity assessment
Security strategy
Security analysis – NSM principles
NIS2 and ISO27001
Related terms: NIS2 (Network and Information Systems Directive 2), DORA (Digital Operational Resilience Act), Compliance, Governance, ISO 27001 (International Organization of Standardization), NSM (Norwegian National Security Authority), Security management, Security audits, Supply chain, Cybersecurity