This is an info Alert.
SnapKey Logo
  • Solutions
      • Solutions
      • SnapKey Residential
      • SnapKey Utility
      • SnapKey Public
      • SnapKey Logistics
      • SnapKey Sensors
      • Guest Check-in
      • Reactivatable Keys
      • Self-service Rentals
  • Industries
      • Industries
      • Utility companies
      • Residential buildings
      • Office buildings & Coworking spaces
      • Logistics
      • Holiday homes
      • Public restrooms
      • Construction sites
      • Unmanned stores
      • Temporary lockers
      • Virtual Keybox
  • Resources
      • Resources
      • Knowledge
      • Videos
      • API documentation
      • Trust & Security
      • System status
  • Partners
  • Company
      • Company
      • About us
      • Why SnapKey
      • Contact
auth.sign_inBook a demo

The CER Directive after 17 July 2026 – designated as a critical entity? The clock is running

The deadline for designating critical entities expired on 17 July 2026. If your organisation has been notified, you have 9 months for the risk assessment and 10 months to comply. Here is what CER requires of your physical security.
18. September 2026
6 min

On 17 July 2026, the deadline expired for competent authorities to identify critical entities within their sectors. With that, the Critical Entities Resilience Directive moved from being law on paper to being a task with a deadline.

If your organisation has received notification that it has been designated a critical entity, two clocks are already counting down.


The two deadlines that matter

Deadline What must be in place
9 months after notification Risk assessment completed – covering both natural and human-made risks
10 months after notification Full compliance with the resilience requirements

The starting gun is your notification – not 17 July. If you were notified in July 2026, your risk assessment is due around April 2027 and full compliance around May 2027.


What CER actually requires

CER is about resilience, not cybersecurity. That is the single most important difference between CER and NIS2. Where NIS2 looks at your network and information systems, CER looks at your ability to keep delivering an essential service — whether the threat is a storm, a power cut, sabotage, or a person walking through a door she should not be able to open.

Designated entities must, among other things:

Risk assessment

Systematic assessment of natural and human-made risks to your critical functions

Preventive measures

Concrete measures that prevent incidents – including physical protection of sites

Resilience planning

Plans for responding to and recovering from incidents

Training and exercises

Staff must be trained – and the training must be documented

Notification duty

Significant disruptions must be reported to the competent authority

Point of contact

A designated contact towards the competent authority

In Denmark, supervision is split: the Agency for Societal Security (SAMSIK) is the coordinating authority, while individual sector authorities act as competent authorities within their own domains. Other member states have equivalent arrangements.


The notification deadline: 24 hours

For an incident that significantly disrupts – or has the potential to significantly disrupt – the provision of your essential service:

Incident detected
   │
   ├─ 24 hours ──────► Initial notification to the competent authority
   │
   └─ 1 month ───────► Detailed report (where relevant)

Note how this differs from NIS2, which has three stages (24 hours / 72 hours / 1 month). If you carry both NIS2 and CER obligations, you must be able to run two different reporting tracks for the same incident.

When determining whether a disruption is significant, the directive points to the number and proportion of users affected, the duration of the disruption, and the geographical area affected.


The problem: physical security is rarely documented

This is where most organisations hit the same wall. The preventive measures exist physically – fences, locks, keys, procedures – but they cannot be evidenced.

A typical water utility or substation is secured today with a mechanical key. And a mechanical key cannot answer the questions a competent authority asks:

  • Who has access to this site right now?
  • Who was physically present on 14 March between 02:00 and 04:00?
  • What happened to the key when that employee left the company?
  • Can you prove the contractor only had access during the agreed period?

With a key cabinet, the honest answer to all four is "we don't know". That is not only a security problem — it is a documentation problem, and documentation is what supervision asks for.


How digital access control closes the gap

CER requirement What must actually be demonstrable
Preventive measures Access limited to named people within defined time windows – not to everyone holding a key
Risk assessment Real access data: who holds keys, which keys are dormant, where the critical access points are
Notification duty Incidents recorded automatically with a timestamp, so the 24-hour clock runs from a documented moment
Resilience planning Access can be withdrawn instantly – no site visit, no rekeying
Evidence for supervision Signed reports for a chosen period, produced in minutes rather than weeks

In SnapKey, the same underlying data satisfies all five: every unlock is tied to a person, a key, a time and a result. If your sites already run on iLOQ, this sits on top of the system you own — see SnapKey for iLOQ. Events such as forced open, door left open and access denied are recorded automatically, and an incident can be escalated into a regulatory case with a built-in countdown to the 24-hour and one-month deadlines.


If you have just been designated

  1. Find the notification date. Everything is measured from it. Put the 9- and 10-month deadlines in the calendar today.
  2. Map the physical access points to your critical functions – not just the office, but pumping stations, plant rooms, cabinets and remote sites.
  3. Count the keys. Most organisations discover at this point that the number of issued keys is unknown. That number belongs in the risk assessment.
  4. Decide how you will evidence access going forward. Without a system for it, the risk assessment rests on guesswork.
  5. Settle your reporting path, including who the point of contact is and who can realistically file a notification within 24 hours – including on a Friday evening.

FAQ

What if we have not been notified?

Then you are most likely not designated as a critical entity in this round. Designations can be revised, and many organisations fall under NIS2 without being designated under CER. Check both regimes – they overlap but are not the same.

Are CER and NIS2 the same thing?

No. NIS2 concerns cybersecurity in network and information systems. CER concerns physical and organisational resilience against all types of threat. Many organisations fall under both and must therefore meet two sets of requirements with different reporting deadlines.

Does the 10-month clock start on 17 July 2026?

No. It starts on the date your organisation received notification of its designation. 17 July 2026 was the authorities' deadline for carrying out the identification.

Do we have to replace every lock to comply with CER?

No. The requirement is that you can evidence preventive measures and control access to critical functions. In many cases that is achieved by digitising access to the most critical points first and letting the rest follow.


Contact us

Does your physical access control need to be demonstrable before the deadline? Let's talk about where you stand.

Contact us
Related articles
CER Directive – Complete Guide to Critical Infrastructure Compliance

Understand the CER Directive (EU 2022/2557) and learn how SnapKey helps secure your critical infrastructure with advanced access control and compliance.

Energy Legislation and Access Control – Requirements for Critical Infrastructure

Understand energy legislation requirements for physical security and access control. Learn how SnapKey helps energy companies achieve compliance.

NIS2 Directive – Access Control and Cybersecurity Requirements 2025

The NIS2 law introduces enhanced requirements for cybersecurity and access control for businesses in critical infrastructure. Learn about the new requirements and how to achieve compliance.


SnapKey Logo

SnapKey is your digital key for all types of locks. Easily open doors and locks directly from your smartphone, and enjoy fast, secure and flexible access without physical keys or extra apps. Perfect for private homes, businesses and shared spaces.

Solutions
SnapKey ResidentialSnapKey UtilitySnapKey PublicSnapKey LogisticsGuest Check-in
Developers
API documentationAPI referenceWebhooksChangelogSystem status
Company
About usWhy SnapKeyBecome a partnerKnowledgeVideosContact us
Legal
Terms & ConditionsPrivacy PolicyTrust & Security
Contact
SnapKey ApS+45 3242 9050info@snapkey.dk

© All rights reserved.