Critical Entities Resilience (CER) Directive

Explore jurisdictions
Discover key contacts

The Critical Entities Resilience (CER) Directive is a European directive aimed at strengthening the resilience of critical infrastructure across the European Union (EU). It forms a key pillar of the EU’s broader resilience framework by requiring Member States and in-scope entities to identify, assess and mitigate risks that could disrupt the provision of essential services. EU Member States are required to transpose the CER Directive into national law - introducing enhanced obligations for critical entities, including risk assessments, resilience measures, and incident reporting frameworks, as well as increased regulatory oversight at national level. In this guide, we provide an overview of the current implementation status across EU Member States, based on our comprehensive mapping exercise, and highlight key national developments to watch.

Jurisdictions covered in our Critical Entities Resilience (CER) Directive implementation tracker

Click on the jurisdictions below and discover the implementation status for each region.

Key:

Not implemented

Partially implemented

Implemented

Austria
Belgium
Bulgaria
Croatia
Cyprus
Czech Republic
Denmark
Estonia
Finland
France
Germany
Greece
Hungary
Ireland
Italy
Latvia
Lithuania
Luxembourg
Malta
Poland
Portugal
Romania
Slovakia
Slovenia
Spain
Sweden
The Netherlands

Key contacts

Nils Müller Partner Data Privacy, Cybersecurity & Technology

T: +49 89 54565 194 E: nilsmueller@ eversheds-sutherland.com

View full profile

Olaf Van Haperen Partner Data Privacy, Cybersecurity & Technology

T: +31 10 2488 000 E: olafvanhaperen@ eversheds-sutherland.com

View full profile

Robbert Santifort Partner

T: +31 10 2488 000 E: robbertsantifort@ eversheds-sutherland.com

View full profile

Caroline Lyannaz Partner

T: +33 1 55 73 41 61 E: carolinelyannaz@ eversheds-sutherland.com

View full profile

Maarten Stassen Partner

T: +32 471 482 177 E: maartenstassen@ eversheds-Sutherland.com

View full profile

Additional resources

Achieving compliance with the EU CER Directive

Overview of how to achieve compliance with the EU CER Directive, covering key requirements and resilience measures.

Explore now

Data Centres: European Cybersecurity and Technology Law

How EU cybersecurity and technology laws affect data centres and their compliance requirements.

Learn more

Navigating cybersecurity compliance - NIS2 Directive

A guide to the EU NIS2 Directive, outlining cybersecurity requirements and implementation across member states.

View our guide

© Eversheds Sutherland. All rights reserved. Eversheds Sutherland is a global provider of legal and other services operating through various separate and distinct legal entities. Eversheds Sutherland is the name and brand under which the members of Eversheds Sutherland Limited (Eversheds Sutherland (International) LLP and Eversheds Sutherland (US) LLP) and their respective controlled, managed and affiliated firms and the members of Eversheds Sutherland (Europe) Limited (each an "Eversheds Sutherland Entity" and together the "Eversheds Sutherland Entities") provide legal or other services to clients around the world. Eversheds Sutherland Entities are constituted and regulated in accordance with relevant local regulatory and legal requirements and operate in accordance with their locally registered names. The use of the name Eversheds Sutherland, is for description purposes only and does not imply that the Eversheds Sutherland Entities are in a partnership or are part of a global LLP. The responsibility for the provision of services to the client is defined in the terms of engagement between the instructed firm and the client.

Connect with us

linkedin logo
facebook icon
youtube icon