The CER Directive after 17 July 2026 – designated as a critical entity? The clock is running
The deadline for designating critical entities expired on 17 July 2026. If your organisation has been notified, you have 9 months for the risk assessment and 10 months to comply. Here is what CER requires of your physical security.
On 17 July 2026, the deadline expired for competent authorities to identify critical entities within their sectors. With that, the Critical Entities Resilience Directive moved from being law on paper to being a task with a deadline.
If your organisation has received notification that it has been designated a critical entity, two clocks are already counting down.
The two deadlines that matter
| Deadline | What must be in place |
|---|---|
| 9 months after notification | Risk assessment completed – covering both natural and human-made risks |
| 10 months after notification | Full compliance with the resilience requirements |
The starting gun is your notification – not 17 July. If you were notified in July 2026, your risk assessment is due around April 2027 and full compliance around May 2027.
What CER actually requires
CER is about resilience, not cybersecurity. That is the single most important difference between CER and NIS2. Where NIS2 looks at your network and information systems, CER looks at your ability to keep delivering an essential service — whether the threat is a storm, a power cut, sabotage, or a person walking through a door she should not be able to open.
Designated entities must, among other things:
Risk assessment
Systematic assessment of natural and human-made risks to your critical functions
Preventive measures
Concrete measures that prevent incidents – including physical protection of sites
Resilience planning
Plans for responding to and recovering from incidents
Training and exercises
Staff must be trained – and the training must be documented
Notification duty
Significant disruptions must be reported to the competent authority
Point of contact
A designated contact towards the competent authority
In Denmark, supervision is split: the Agency for Societal Security (SAMSIK) is the coordinating authority, while individual sector authorities act as competent authorities within their own domains. Other member states have equivalent arrangements.
The notification deadline: 24 hours
For an incident that significantly disrupts – or has the potential to significantly disrupt – the provision of your essential service:
Incident detected
│
├─ 24 hours ──────► Initial notification to the competent authority
│
└─ 1 month ───────► Detailed report (where relevant)
Note how this differs from NIS2, which has three stages (24 hours / 72 hours / 1 month). If you carry both NIS2 and CER obligations, you must be able to run two different reporting tracks for the same incident.
When determining whether a disruption is significant, the directive points to the number and proportion of users affected, the duration of the disruption, and the geographical area affected.
The problem: physical security is rarely documented
This is where most organisations hit the same wall. The preventive measures exist physically – fences, locks, keys, procedures – but they cannot be evidenced.
A typical water utility or substation is secured today with a mechanical key. And a mechanical key cannot answer the questions a competent authority asks:
- Who has access to this site right now?
- Who was physically present on 14 March between 02:00 and 04:00?
- What happened to the key when that employee left the company?
- Can you prove the contractor only had access during the agreed period?
With a key cabinet, the honest answer to all four is "we don't know". That is not only a security problem — it is a documentation problem, and documentation is what supervision asks for.
How digital access control closes the gap
| CER requirement | What must actually be demonstrable |
|---|---|
| Preventive measures | Access limited to named people within defined time windows – not to everyone holding a key |
| Risk assessment | Real access data: who holds keys, which keys are dormant, where the critical access points are |
| Notification duty | Incidents recorded automatically with a timestamp, so the 24-hour clock runs from a documented moment |
| Resilience planning | Access can be withdrawn instantly – no site visit, no rekeying |
| Evidence for supervision | Signed reports for a chosen period, produced in minutes rather than weeks |
In SnapKey, the same underlying data satisfies all five: every unlock is tied to a person, a key, a time and a result. If your sites already run on iLOQ, this sits on top of the system you own — see SnapKey for iLOQ. Events such as forced open, door left open and access denied are recorded automatically, and an incident can be escalated into a regulatory case with a built-in countdown to the 24-hour and one-month deadlines.
If you have just been designated
- Find the notification date. Everything is measured from it. Put the 9- and 10-month deadlines in the calendar today.
- Map the physical access points to your critical functions – not just the office, but pumping stations, plant rooms, cabinets and remote sites.
- Count the keys. Most organisations discover at this point that the number of issued keys is unknown. That number belongs in the risk assessment.
- Decide how you will evidence access going forward. Without a system for it, the risk assessment rests on guesswork.
- Settle your reporting path, including who the point of contact is and who can realistically file a notification within 24 hours – including on a Friday evening.
FAQ
What if we have not been notified?
Then you are most likely not designated as a critical entity in this round. Designations can be revised, and many organisations fall under NIS2 without being designated under CER. Check both regimes – they overlap but are not the same.
Are CER and NIS2 the same thing?
No. NIS2 concerns cybersecurity in network and information systems. CER concerns physical and organisational resilience against all types of threat. Many organisations fall under both and must therefore meet two sets of requirements with different reporting deadlines.
Does the 10-month clock start on 17 July 2026?
No. It starts on the date your organisation received notification of its designation. 17 July 2026 was the authorities' deadline for carrying out the identification.
Do we have to replace every lock to comply with CER?
No. The requirement is that you can evidence preventive measures and control access to critical functions. In many cases that is achieved by digitising access to the most critical points first and letting the rest follow.
Contact us
Does your physical access control need to be demonstrable before the deadline? Let's talk about where you stand.
Related articles
CER Directive – Complete Guide to Critical Infrastructure Compliance
Understand the CER Directive (EU 2022/2557) and learn how SnapKey helps secure your critical infrastructure with advanced access control and compliance.
Energy Legislation and Access Control – Requirements for Critical Infrastructure
Understand energy legislation requirements for physical security and access control. Learn how SnapKey helps energy companies achieve compliance.
NIS2 Directive – Access Control and Cybersecurity Requirements 2025
The NIS2 law introduces enhanced requirements for cybersecurity and access control for businesses in critical infrastructure. Learn about the new requirements and how to achieve compliance.