NIS2 and CER: Adopted the Same Day for the Same Critical Sectors — Your Dual Compliance Guide
On 27 December 2022, the Official Journal of the European Union published two directives on the same day. Directive (EU) 2022/2555 — NIS2 — establishes cybersecurity requirements for critical infrastructure operators. Directive (EU) 2022/2557 — the Critical Entities Resilience Directive, or CER — establishes physical resilience requirements for those same operators. The simultaneous publication was not a coincidence. The two directives were designed as a regulatory package, and for organisations operating in the ten overlapping Annex I sectors, understanding how they connect is not optional [3].
The legal bridge between them is Article 3(1)(f) of NIS2. It designates as essential entities those “identified as critical entities under Directive (EU) 2022/2557” — regardless of size [2]. That carries direct consequences: not the lighter important-entity supervision regime, but the stricter essential entity tier with proactive on-site inspections, personal management liability, and the full 24-hour incident reporting clock.
This guide explains what each directive requires, which sectors fall under both, and what your organisation must do if it operates at the intersection of cyber and physical resilience. For background on the NIS2 directive text and its key articles, and for how sectors and size thresholds determine applicability, see our NIS2 scope guide.
Does This Apply to Your Organisation?
CER is narrower than NIS2 in one critical respect: it applies only to entities that member states formally designate as “critical entities” following a national risk assessment. Operating in a covered sector is necessary but not sufficient. The scenarios below map the most common applicability outcomes [1][4].
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

| Situation | CER? | NIS2? | Outcome |
|---|---|---|---|
| Annex I sector; formally designated as a CER critical entity | Yes | Yes — essential entity (Art. 3(1)(f)) | Full dual compliance required |
| NIS2 Annex I sector; large entity; not CER-designated | No | Yes — essential entity (size threshold) | NIS2 only |
| NIS2 Annex II sector only (manufacturing, postal, chemicals, etc.) | No | Yes — important entity (typically) | NIS2 Annex II regime only |
| Central government public administration | Likely (confirm CER designation) | Yes — NIS2 Annex I essential entity | Dual compliance likely |
| SME below NIS2 size threshold; not CER-designated | Usually no | Usually no | Confirm with national authority |
What the CER Directive Requires
CER is not a cybersecurity directive. It addresses physical and operational resilience: the capacity of critical infrastructure to prevent, withstand, and recover from natural disasters, terrorist attacks, sabotage, insider threats, and pandemics — disruptions that fall outside the cybersecurity scope of NIS2 [1].

The directive replaces the 2008 European Critical Infrastructure Directive, which covered only energy and transport. CER extends that framework to eleven sectors and introduces an all-hazards approach: designated entities must assess and manage the full spectrum of risks, not only those most common in their sector [5].
Only entities formally designated as “critical entities” by their member state carry CER obligations. Designation follows a national risk assessment — which each member state must complete by January 2026 — and is followed by written notification to the entity. From the date of that notification, critical entities have ten months to achieve full CER compliance [1].
The four core obligations for designated critical entities are [1]:
- Risk assessment every four years — covering all relevant natural and man-made risks, including cross-border and interdependency threats. The assessment must be conducted before resilience measures are put in place and renewed at least every four years or following any significant incident.
- Resilience measures — proportionate technical and organisational measures to prevent incidents, protect physical assets, limit impact, and enable recovery. These must address physical security of facilities, governance processes, supply chain integrity, operational continuity, and redundancy of critical systems.
- Personnel background checks — member state authorities may require screening of persons in sensitive roles at or on behalf of the critical entity, including employees and contractors with access to critical assets or systems.
- Incident notification — incidents with a “significant disruptive effect” on essential services must be notified to the national CER competent authority “without undue delay.” CER does not set a fixed notification window; the specific timing is determined by each member state’s transposition law.
Critical entities must also produce and maintain a resilience plan documenting their protective measures and response procedures. The plan must be submitted to and reviewed by the competent authority.
What NIS2 Requires for Essential Entities
NIS2 draws a firm line between essential entities (Annex I sectors) and important entities (Annex II sectors). For any organisation designated as a CER critical entity, the relevant NIS2 tier is essential entity — and the difference matters in terms of supervision intensity.

Essential entities are subject to proactive ex-ante supervision: competent authorities can initiate on-site security inspections, targeted audits, and compliance reviews at any time, without needing to demonstrate a prior breach. Important entities are supervised reactively — enforcement follows evidence of non-compliance. For the full breakdown of how this distinction works and which organisations fall into each tier, see our essential vs important entities guide [4].
Under NIS2 Article 21, essential entities must implement security measures across ten domains: risk analysis and information security policies; incident handling; business continuity, backup management, and disaster recovery; supply chain security; network and information system acquisition, development, and maintenance; cybersecurity measure effectiveness assessment; basic cyber hygiene practices and training; cryptography and encryption; human resources security and access control; and multi-factor authentication. For how these business continuity obligations interact with CER resilience planning, see our NIS2 business continuity guide.
The NIS2 incident reporting regime for essential entities operates on a fixed timeline [4]:
| Stage | Deadline | Required content |
|---|---|---|
| Early warning | Within 24 hours of becoming aware | Incident occurred; suspected malicious cause; potential cross-border impact |
| Incident notification | Within 72 hours | Updated assessment; initial severity; indicators of compromise |
| Final report | Within 1 month | Full description, impact assessment, root cause, remediation measures |
NIS2 also establishes personal management accountability: governing bodies of essential entities are directly responsible for approving and overseeing cybersecurity measures and can be held personally liable for negligence in the event of a significant incident [4].
The Article 3(1)(f) Bridge: How CER Designation Upgrades Your NIS2 Status
Article 3(1)(f) of NIS2 is the provision that operationally connects the two directives. It designates as essential entities those “identified as critical entities under Directive (EU) 2022/2557, referred to in Article 2(3) of this Directive” [2]. The practical consequence is an automatic NIS2 status upgrade that most organisations in the overlap sectors have not yet fully considered.
The mechanism runs in three stages:
- National risk assessment — by January 2026, each member state must complete a risk assessment across all eleven CER sectors to identify which specific organisations, if disrupted, would cause a “significant disruptive effect” on essential services [1].
- Formal designation and notification — by July 2026, member states must identify and formally notify individual organisations as critical entities. From the notification date, those organisations have ten months to achieve full CER compliance [1].
- Automatic NIS2 essential entity status — the moment your member state issues the CER designation notification, your NIS2 classification becomes essential entity, regardless of your organisation’s size or whether you would otherwise meet the NIS2 size threshold [2].
This automatic upgrade carries a specific consequence for organisations that previously assessed themselves as NIS2 important entities: CER designation reclassifies them as essential entities, bringing proactive supervision, full Article 21 security obligations, the 24-hour/72-hour reporting clock, and direct management liability — without any change to the organisation’s size or operations.
Member states are additionally required, under NIS2 Article 9, to include a “policy framework for enhanced coordination” between NIS2 and CER competent authorities in their national cybersecurity strategies [3]. This was written into both directives from the outset — the two frameworks were intended to operate in parallel, not in isolation.
Which Sectors Fall Under Both Directives
Ten of CER’s eleven Annex I sectors also appear in NIS2 Annex I. These are the ten sectors where CER designation triggers the full dual compliance obligation: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, and space [1][4].

The one CER Annex I sector not in NIS2 Annex I is food (large-scale production, processing, and wholesale distribution). Food operators appear in NIS2 only in Annex II, meaning they would normally be subject to the important entity regime. However, because Art. 3(1)(f) applies to all CER critical entities regardless of sector annex position, a food operator formally designated as a CER critical entity is automatically reclassified as a NIS2 essential entity [2].
The one NIS2 Annex I sector not in CER is ICT service management (B2B) — managed service providers and managed security service providers. These organisations carry NIS2 essential entity obligations but have no corresponding CER dimension; physical resilience requirements do not apply to them under the CER framework.
NIS2 Annex II sectors — postal and courier services, waste management, chemicals, manufacturing, digital providers, and research — fall entirely outside CER. Entities in these sectors face NIS2 important entity obligations but not CER’s physical resilience framework, except where CER designation applies (which would also upgrade them to NIS2 essential under Art. 3(1)(f)).
Two Regulators, One Entity: Navigating Dual Competent Authority Coordination
The structural challenge for dual-covered entities is that most member states have designated separate competent authorities for NIS2 and CER. Your cybersecurity authority — typically a national CSIRT, cybersecurity agency, or sector regulator under NIS2 — is a different body from the resilience authority that handles CER supervision, which is typically a civil contingency, critical infrastructure protection, or interior ministry function [1].
When a national authority formally designates your organisation as a CER critical entity, it is required to inform the relevant NIS2 competent authority [1]. From that point, two supervisory relationships run in parallel:
- NIS2 competent authority — proactively supervises your Article 21 cybersecurity measures; receives your 24-hour early warnings and 72-hour incident notifications; may conduct on-site inspections and security audits without prior notice.
- CER competent authority — reviews and approves your resilience plan; receives incident notifications for physically disruptive events with a significant effect on essential services; may conduct advisory resilience assessments.
When a single incident combines physical disruption and cyber impact — a physical intrusion that enables a network breach, or a flood that takes down a data centre — both notification regimes are likely triggered simultaneously. Filing notifications under both frameworks from the moment of awareness, rather than waiting to determine which authority has primary jurisdiction, is the approach most consistent with both directives’ reporting timelines [1][6].
Some member states have taken steps to unify their NIS2 and CER competent authorities or establish formal coordination protocols. Confirm with your national competent authority whether a single notification route is available for hybrid incidents, and whether joint supervisory processes apply in your jurisdiction.
What Dual Compliance Requires in Practice
The two frameworks share enough common ground that a coordinated compliance programme can serve both — with specific additions that remain unique to each. The gap analysis below maps the key obligations [1][4][6].
| Obligation | NIS2 (Art. 21) | CER | Coordination approach |
|---|---|---|---|
| Risk assessment | Yes — cyber-focused | Yes — all-hazards, every 4 years | Two separate assessments, or one expanded all-hazards assessment with a dedicated cyber annex |
| Business continuity and resilience plan | Yes — Art. 21(2)(c) | Yes — resilience plan required | Plans can be unified where they address both cyber and physical disruption; approval pathways differ (internal governance for NIS2; competent authority review for CER) |
| Incident notification | Yes — 24h/72h/1-month to NIS2 authority | Yes — “without undue delay” to CER authority | Separate notifications to separate authorities; for hybrid incidents, file under both simultaneously |
| Supply chain security | Yes — Art. 21(2)(d) | Yes — resilience plan covers supply chain dependency mapping | Unified vendor register; NIS2 requires explicit security clauses in supplier contracts; CER requires interdependency mapping |
| Physical security measures | Not explicitly required | Yes — core obligation | CER-only workstream: physical access control, facility hardening, personnel screening |
| Cybersecurity technical measures (10 domains) | Yes — Art. 21 all 10 domains | Not explicitly required | NIS2-only workstream: network security, access management, cryptography, MFA, vulnerability management |
| Management accountability and governance | Yes — personal liability for governing body | Yes — governance requirement | Single board-level governance framework can serve both; separate approval of NIS2 security policy and CER resilience plan |
In practice, the CISO or head of IT security leads the NIS2 cybersecurity workstream, while a head of physical security, resilience manager, or critical infrastructure protection officer leads the CER workstream. Both report to the same board-level governance function, as management accountability under both directives ultimately runs to the governing body [4].
Key Deadlines for Entities Under Both Directives
| Date | Obligation | Framework |
|---|---|---|
| 17 October 2024 | Transposition deadline — both directives into national law | NIS2 + CER |
| 17 April 2025 | Member states establish NIS2 essential and important entity lists | NIS2 |
| 17 January 2026 | Member states adopt national critical entity resilience strategies | CER |
| 17 July 2026 | Member states formally identify and notify critical entities | CER |
| ~17 May 2027 | Critical entities must achieve full CER compliance (10 months post-notification) | CER |
Several member states missed the October 2024 transposition deadline for both directives; most have since adopted national measures or are finalising their legislative frameworks [1][4]. Enforcement activity is already underway in countries that transposed on time, including supervisory reviews of NIS2 essential entities and early-stage CER designation processes. In January 2026, the European Commission also proposed targeted amendments to NIS2 to increase legal clarity for around 28,700 affected companies [4].

Frequently Asked Questions
Does every NIS2 entity also have to comply with CER?
No. CER applies only to entities formally designated as “critical entities” by their member state following a national risk assessment. The vast majority of NIS2-covered organisations — including medium and large companies in Annex I sectors — will not receive CER designation. CER is reserved for organisations whose disruption would have a demonstrably significant effect on essential services, as assessed at the national level.
My sector is in CER Annex I. Am I automatically a critical entity?
No. Operating in a CER Annex I sector is a necessary but not sufficient condition. Your member state must complete its national risk assessment, determine that your organisation meets the “significant disruptive effect” threshold, and issue a formal written notification. Until that notification arrives, you are not a CER critical entity — though you may still be a NIS2 essential or important entity based on your sector and size.
We are already NIS2 compliant. What additional work does CER require?
NIS2 compliance addresses only cyber resilience. CER adds a separate all-hazards risk assessment covering physical and natural threats, a resilience plan addressing physical security and operational continuity for non-cyber disruptions, background-check procedures for persons in sensitive roles, and incident notification to a separate CER competent authority. The business continuity and supply chain elements of your NIS2 programme can often be extended to serve CER requirements, but physical security measures and resilience plan approval are distinct obligations with no NIS2 equivalent.
What penalties apply for CER non-compliance?
Unlike NIS2, which sets EU-wide penalty caps (up to EUR 10 million or 2% of global annual turnover for essential entities), CER delegates penalty structures to member state transposition law. Member states must set penalties that are “effective, proportionate, and dissuasive,” but the specific amounts vary by jurisdiction. Confirm the applicable sanction regime with your national CER competent authority.
Key Takeaways
- NIS2 (Directive 2022/2555) and CER (Directive 2022/2557) were published in the Official Journal on 27 December 2022 as a deliberate regulatory package — NIS2 addresses cyber resilience, CER addresses physical resilience, for largely the same critical sectors [3].
- NIS2 Article 3(1)(f) creates an automatic status upgrade: any entity formally designated as a CER critical entity becomes a NIS2 essential entity regardless of size, triggering proactive supervision, the 24-hour/72-hour incident reporting regime, and personal management liability [2].
- Ten sectors appear in both Annex I lists: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, and space. Food appears only in CER Annex I; ICT service management (B2B) appears only in NIS2 Annex I [1][4].
- Dual compliance is achievable through a coordinated programme: risk assessments, business continuity plans, supply chain security, and board governance can serve both frameworks, while cybersecurity technical measures (NIS2 Art. 21) and physical security measures (CER) remain distinct workstreams with separate competent authority relationships.
- The CER identification process peaks in July 2026. Organisations in Annex I sectors should assess their likely designation exposure now — not wait for formal notification — to avoid being caught unprepared for the automatic NIS2 essential entity upgrade that follows [1].
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Critical Entities Resilience Directive: Sectors, Obligations, and Timelines. UpGuard.
- NIS2 Directive Article 3: Essential and Important Entities. NIS-2-Directive.com.
- CER and NIS-2 Directives Enter into Force to Strengthen EU’s Resilience. European Commission, 2023.
- NIS2 Directive: Securing Network and Information Systems. European Commission Digital Strategy, 2024.
- EU CER Directive: Compliance, Scope and Impact. Ramboll.
- Comparative Review of NIS2, DORA, GDPR and CER. NeboSystems.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
