Defined at Article 2(4) of the Critical Entities Resilience (CER) Directive, Directive (EU) 2022/2557, as an asset, facility, equipment, network or system, or part of one, which is necessary for the provision of an essential service. CER is the physical-resilience counterpart to the NIS2 Directive: NIS2 imposes cybersecurity obligations on “essential and important entities” across 18 sectors, while CER designates the infrastructure itself and requires the entities operating it to run risk assessments and resilience plans against physical threats.
The two regimes share sectors and often the same operators, so a business continuity obligation under Business continuity (DORA) or an incident-reporting duty under Breach notification can sit alongside a parallel CER resilience plan for the same organisation.
