EU Critical Entities Resilience Directive
EU directive requiring critical infrastructure operators to implement resilience measures. Covers water, waste management, energy, and digital infrastructure sectors.
What CER Directive draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
- Sensitive Data DiscoveryFinds and classifies the regulated data, so everything downstream knows what is in scope.
- Policy & ComplianceTurns the captured activity into the report shape the framework asks for.
- Compliance Advisory ServicesOrganises the gap register, the remediation roadmap, and the auditor-ready pack.
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Risk Assessment
Critical entities MUST carry out risk assessments including cyber threats to operational systems.
An assessment is only defensible if the findings in it are observed rather than asserted. Discovery supplies what regulated data exists and where, scanning supplies the configuration and exposure posture, and the audit trail supplies who has actually been reaching it — so the assessment describes the estate as measured. Our advisory engagements then map each finding to the specific mandate it touches and sequence the remediation.
Resilience Measures
Entities MUST implement measures to ensure resilience including access control and logging.
A continuity requirement asks two different things, and only one of them is a database control. The recovery plan, the failover drill, and the tested restore are yours. What is produced here is the evidence layer under them: backups and exports are hashed and baselined alongside the datafiles, so a backup that was silently truncated, moved, or never written is evident rather than discovered at the restore. Audit events land in columnar storage on immutable object storage with a verification hash per record, so the history survives the incident that made you need it and is still queryable in seconds afterwards. Collection failure is itself an alerting condition, which is what evidences that the record was continuous rather than merely intended to be.
Incident Notification
Significant incidents MUST be notified to competent authorities within 24 hours.
Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.
Background Checks
Critical roles MUST be subject to background verification with access logging.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
What CER Directive covers
This instrument defines no data category of its own. Regulates the physical and organisational resilience of critical ENTITIES. It is the non-cyber sibling of NIS2 and defines no data category at all.
How CER Directive is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The national competent authority designated by each Member State.
Article 22 requires Member States to lay down penalties that are effective, proportionate and dissuasive, and leaves the figures to them. The obligations themselves — resilience measures, incident notification, background checks on sensitive roles — are harmonised even though the sanction is not.
Because CER and NIS2 were adopted together and often transposed together, the national penalty regime for the two is frequently the same instrument.
Uncapped exposure that sits outside this instrument
These come from company law rather than from CER Directive, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for CER Directive,
not configured for it afterwards
Critical Entity Monitoring
Audit access to SCADA and chemical treatment databases
CER Resilience Report
Risk-based forensic-ready log documentation
Utility System Data
Identify SCADA, water treatment, and waste management data
Critical System Access Alert
24-hour incident notification capability
Other Critical Infrastructure frameworks
Walk into the CER Directive audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.