Compliance & Regulations/European Union/EU CER
Critical Infrastructure · European Union — critical entities

EU CER Directive

The EU directive on resilience of critical entities — physical and operational resilience baseline for 11 sectors including energy, transport, banking, and digital infrastructure.

Regulator
European Commission + national competent authorities
Jurisdiction
European Union — critical entities
Status
Transposition deadline 17 October 2024.
In force since
Active
Regulator's source
Who it applies to

Critical entities identified by Member States across 11 sectors.

Audit / certification status

Continuous evidence pipeline available; audit support included for all customers.

What it requires

What EU CER actually requires.

These are the obligations a regulated entity owes — the things an assessor or supervisor will ask about.

01

Risk assessment of physical and operational threats.

02

Resilience measures including business continuity and supply chain.

03

Incident notification to the competent authority.

04

Background checks for personnel in sensitive roles.

How Safeguard maps to it

Pre-mapped controls. Continuous evidence.

Each requirement above is bound to live telemetry — not screenshots. The mapping below is what your auditor or regulator sees.

Physical and cyber risk overlay — joint posture report.

Incident-notification timer mirroring NIS2 cadence where overlap exists.

Evidence we produce

Artifacts your auditor accepts.

Each evidence artifact is signed and timestamped. Auditors can verify integrity without trusting Safeguard.

Resilience plan with measures linked to risk assessment.

Personnel background-check register.

Ready for EU CER?

Bring the framework. We'll walk the controls with you — section by section, evidence packet by evidence packet, with the regulators you actually have to answer to.

Safeguard | Software Supply Chain Security Platform | Zero CVE + Self-Healing