CER Guidelines Resilience

Mapping picture

The European Commission published Guidelines (C/2026/3712) for resilience, physical and personnel measures for the EU CER directive. CER requires critical operators to take appropriate and proportionate technical, security and organisational measures to ensure their resilience. The Guidelines from 2026 contain non-binding resilience and security measures for CER operators.

Mappings to the following standards are provided without guarantee of correctness or completeness.

C/2026/3712

CER Guidelines

The CER Guidelines (C/2026/3712) were published in July 2026 by the Commission as part of communication C/2026/4730. There are seven domains (A—G) with 94 measures, recommendations and controls for CER topics ranging from general risk considerations to personnel security. The Guidelines were drafted by the Commission with the Critical Entities Resilience Group (CERG) in 2025.

Group Requirements Controls
A General considerations
Governance and risk management
A.6—A.17
B Prevention
BCM and risk reduction and measures
B.18—B.23
C Physical protection
Security of facilities, perimeters, assets
C.24—C.50
D Response, resistance and mitigation
Incident response and preparation, crises
D.51—D.65
E Recovery
Redundancy, recovery and BCM planning
E.66—E.75
F Employee security management
Security of staff, screening, training
F.76—F.85
G Awareness
Training, awareness, exercises
G.86—G.94

Note the guidelines are a recommendation from the European Commission, mandated by CER to further specify the technical, security and organisational measures that may be taken by critical entities. However they serve as a useful specification of the various EU CER requirements on resilience to guide and facilitate operators in selecting more concrete controls.

up

General considerations A

OpenKRITIS mapping of CER guidelines ∙ version 20260718
CER
guide
Requirement ISO 27001
2022
ISO 22301
2019
KRITIS
DachG
NIS2
DE
A.6
Entities elect resilience measures based on risk analyses:
  • National risk assessments based on EU CER
  • Entity risk assessments according to national transposition
4.1
8.2
8.3
4
6
8.2.3
DG.3 NS.1
A.7
Measures need to be appropriate and proportionate to risks
  • Appropriate: risk/impact-based, effective and suitable to make it fully resilient in the provision of essential service
  • Proportionate: necessary, sufficient, not excessive; tailored
6.1
8.2
8.3
6.1
6.2
8.2
DG.5 NS.3
NS.1
A.8
Guideline measures cover all CER sectors
But might not apply to all sectors equally
- - §4 -
A.9
Measures depend on EU member states risk assessments
and critical entities’ risk assessments
4.1
6.1.2
4.1
6.1.2
DG.3
§11
-
A.10
Resilience measures without prejudice to other legislation
NIS2, GDPR, energy law, sector regulation
A.5.31 4.2.2 - -
A.11
High-risk AI systems must comply with EU AI legislation
EU Artificial Intelligence Act
- - - -
A.12
Documentation of resilience measures in a resilience plan
and use other, existing measures to comply
partial
6
7.5
7.5
4
8
DG.18 NS.2
A.13
Liaison officer to be designated by critical entity
to coordinate measures and interface to authorities
5.1
5.3
A.5.5
5.1
5.3
8.4.2
DG.26 NS.37
A.14
Identify all assets, cross-border, interdependency aspects
given the highly interconnected nature of CER sectors
4.1 4.1 DG.3 NS.1
A.15
Entity and national risk assessments are core mechanism
for measures but also for interdependencies
4.1 4.1 DG.3
§11
NS.1
A.16
International and European standards taken into account
for resilience measures
6
7.1
6
7.1
DG.5
§11
NS.3
A.17
Critical maritime infrastructure especially protected
due to the complex nature of threats
- - DG.3
§12 (2)
-

up

Prevention B

OpenKRITIS mapping of CER guidelines ∙ version 20260718
CER
guide
Requirement ISO 27001
2022
ISO 22301
2019
KRITIS
DachG
NIS2
DE
B.18
Integrated system for resilience measures and prevention
Business Continuity Management (BCM)
partial
A.5.29
A.5.30
4—10 DG.4 NS.7
B.19
Risk reduction and and climate adaption measures
Over the lifetime of the critical infrastructure
4.1
AMD1
4.1
AMD1
DG.3
§11 (2)
DG.6
-
B.20
Incident database and systematic incident reporting system
for a history of events and asset recovery
A.5.24
A.5.25
A.5.26
8.4.2
8.4.3
DG.12
DG.23
DG.24
NS.6
B.21
Identification of error-prone tasks and countermeasures
to prevent human errors
- - - -
B.22
Relevant NIS2 measures should be taken into account 8.2
8.3
- - NS.1
B.23
Manual overrides and human-in-the-loop provisions for OT
for human intervention and manual control in response to hazards
A.5.30 8.3
8.4.4
DG.13 -

up

Physical protection and security C

OpenKRITIS mapping of CER guidelines ∙ version 20260718
CER
guide
Requirement ISO 27001
2022
ISO 22301
2019
KRITIS
DachG
NIS2
DE
C.24
Physical measures against natural and man-made threats
procedural controls to detect, deter, delay, deny ...
A.7.5 - DG.7
DG.9
NS.25
C.25
Appropriate and proportionate measures to threats
  • Coordination with authorities and PPPs
  • Consider state actors as hybrid threats
  • Consider other threats such as terrorism, military, activism
8.2
8.3
A.5.5
A.5.6
8.2
8.3
DG.5 NS.3
C.26
Perimeter-hardening measures to deter and delay
security fencing, reinforced walls, gating, vehicle mitigation, light
A.7.1 - DG.7 NS.25
C.27
Controlled checkpoint for access of staff, vehicles, goods
limited routes, barriers, spacing
A.7.2 - DG.10 NS.25
C.28
Robust or reinforced external entry points (gates/doors)
and retrofitted and protected frames and windows
A.7.2
A.7.3
- DG.10 NS.25
C.29
Perimeter monitoring and detection of breaches
real-time, alarms, sensors; with zonal coverage, monitored and tested
A.7.4 - DG.8
DG.9
NS.25
C.30
Video systems for monitoring, real-time and recording
facilities, entry routes; proper technical parameters, testing
A.7.4 - DG.8 NS.25
C.31
Lighting and illumination of entry points, car parks, ways
field of view and avoid glare, shadows; emergency and backup lighting
A.7.5 - DG.7 NS.25
C.32
Signage for security restrictions, privacy and monitoring A.5.31
A.5.33
A.5.34
- DG.8 NS.25
C.33
Layered security zones for access controls
access management, mantraps, locking doors and on-site security staff
A.7.6 - DG.7 NS.25
C.34
Utility and equipment rooms locked and access-controlled
for electricity, water, cooling, heating, AC, telecommunications etc.
A.7.8 - DG.7 NS.25
C.35
Segregated mail rooms and depots away from core assets
safety procedures, equipment and trained staff for threats
A.7.3
A.7.6
- DG.7 NS.25
C.36
External facilities and assets with proportionate protection
routine inspection and maintenance
A.7.9
A.7.13
- DG.7 NS.25
C.37
Access control and restricted or classified information handling procedures should not preclude NIS2 A.5.15
A.5.18
- DG.10 NS.23
C.38
Single register for physical keys and credentials
with issuance, revocation and return dates; procedures for loss
A.5.18 - DG.10 NS.23
NS.25
C.39
Least privilege access rights and regularly reviewed
Zones with access control and logging; visitor procedures
A.5.15
A.5.18
A.7.2
A.7.6
- DG.10 NS.23
NS.25
C.40
Sensitive information assets protected and positioned according to threats, access on need-to-know basis A.5.15
A.7.3
A.7.6
- DG.7
DG.10
NS.23
NS.25
C.41
Inventory of sensitive information assets with classification and handling rules, according to business risk A.5.9
A.5.12
A.5.15
- DG.1 NS.24
C.42
Follow national rules on classification and information
national security, government information
A.5.12
A.5.31
- - NS.24
C.43
Rules and agreements (NDA) for external access to information, contractual mechanisms A.5.20
A.6.6
- - NS.23
NS.20
C.44
Security zones for facilities housing sensitive information (SCIF), stringent access control and monitoring A.5.15
A.7.3
A.7.4
A.7.6
- DG.7
DG.8
DG.10
NS.23
NS.25
C.45
Regular review of access rights and retention periods
measures to reclassify and sanitize assets as needed
A.5.18 - DG.10 NS.23
C.46
Drone (UAV) detection, tracking and identification
radar, radio, light and thermal, acoustic, ISAC technologies
A.5.18 - DG.9
DG.10
NS.23
C.47
Countermeasures against surveillance (ISR) by drones
obscure visibility of sensitive assets and housing in close facilities
A.7.3
A.7.5
- DG.7 NS.25
C.48
Countermeasures against sabotage by drones and UAVs
Counter-UAV netting, canopies, blast-windows, roof strengthening
A.7.1
A.7.5
- DG.7 NS.25
C.49
Establish geographical zones to manage risks of drones
Liaise with national authorities, geofencing, aviation frameworks
A.7.3
A.7.6
A.5.5
- DG.7 NS.25
C.50
Partnerships with counter-drone operations from authorities, law-enforcement and defense A.5.5
A.5.7
- DG.7 NS.25

up

Response, resistance and mitigation D

OpenKRITIS mapping of CER guidelines ∙ version 20260718
CER
guide
Requirement ISO 27001
2022
ISO 22301
2019
KRITIS
DachG
NIS2
DE
D.51
Governance & method to mitigate incident consequences
  • Crisis and disaster management off-site
  • Off-site assistance and integration into on-site response
  • Fail-safe infrastructure for impact mitigation; safe-to-fail
partial
A.5.30
- DG.11 NS.10
D.52
Consider capabilities and capacities required for fail-safe
storage, backup, thermal safety, hazardous materials, cooling
partial
A.5.30
A.7.11
A.8.6
A.8.14
8.2
8.3
8.4.4
7.5
DG.13 NS.7
D.53
Maintenance and repair capacities with supply needs
Diversify supply routes, infrastructure reinforcement, backup systems
A.7.13 8.3.4 DG.14 NS.11
D.54
Integrity in IT systems, networks and software in equipment
e.g. high-risk suppliers, interference from radio frequencies and cyber
A.7.8
A.8.27
A.5.20
- - NS.15
NS.12
D.55
Alternative power systems like UPS and generators
regularly tested, fuel for at least 72 hours, vendor emergency contracts
A.7.13
A.8.14
6
8.3
8.4
8.5
DG.6 NS.8
D.56
Limit water use during disruptions with alternative sources
backup wells, storage tanks, treatment units; ensure human quality
- 6
8.3
8.4
8.5
DG.6 -
D.57
Just-in-case inventory of utilities (water, boilers, chemicals)
Contingency planning in supply chains, back-up resource and supplies
- 8.3.4
(8.3.2)
DG.14 NS.11
D.58
Maintenance programs based on reqs, risk and experience
Predictive maintenance, forecast of failures, protocols for monitoring
A.7.13 - DG.7 NS.25
D.59
Governance structure for resilience – top-to-bottom
resilience objectives, strategy, policy, planning and communication
6.1.3
6.2
8.3
4
5
6.3
9
10
DG.4
DG.26
NS.7
D.60
Clear decision making hierachies, resilience officer
roles, responsibilities and competences at board-level, risk
5
A.5.4
5.1
5.3
7.2
DG.26 NS.37
D.61
Formal cooperation and sharing with national authorities
law-enforcement, emergency, defense, policy makers
4
A.5.5
4
8.4.2
DG.1
DG.2
DG.19
DG.20
DG.21
DG.22
DG.23
DG.26
NS.37
D.62
Cooperation with other private-sector actors
own and other sectors, other member states
A.5.6 4.2 - -
D.63
Crisis communication protocols for incidents
information flow; templates, redundant channels and systems
- 8.4.2 DG.11
DG.23
DG.25
NS.10
NS.28
D.64
Services with multi-scale redundancy design
to ensure cross-border, national, regional and local services
A.8.14
A.8.6
8.3
8.4
DG.13 NS.7
D.65
Emergency response procedures with alert systems
geo-targeting capabilities, communications, SOPs
partial
A.5.26
partial
8.4
DG.12 NS.6

up

Recovery E

OpenKRITIS mapping of CER guidelines ∙ version 20260718
CER
guide
Requirement ISO 27001
2022
ISO 22301
2019
KRITIS
DachG
NIS2
DE
E.66
Redundancy measures for primary systems failure
service prioritisation, manual operation, workforce recovery
A.5.3
A.8.14
8.2
8.3
8.4
DG.13 NS.7
E.67
Alternative disastery recovery sites: hot or warm sites
distant from primary facilities; possible mobile facilities; off-site backup
A.5.3
A.6.7
A.8.14
8.2
8.3
8.4
DG.13 NS.7
E.68
Business continuity plans (BCPs) and business impact analyses (BIAs) of critical functions (BCM)
identify objectives (RTO, RPO), SLAs; tested and reviewed
A.5.30 6
8.2
8.3
8.4
DG.6
DG.13
NS.7
E.69
Crisis management procedures with command structures
decision making authority, action plans, crisis teams
- 8.4.2 DG.11 NS.10
NS.28
E.70
Planning for surge workforce requirements during incidents
surge roster, training and mutual-aid agreements
7.1
A.5.30
6
7.1
8.4
DG.6 NS.9
E.71
Phased restart protocols for recovery with priorities on BIA
validation, testing of data & functions, QS, transition to normal
A.5.30
A.5.29
8.2
8.3
8.4.4
7.5
DG.12 NS.6
E.72
After-action reviews (AARs) with structured methods
after all incidents and exercises for lessons learned; with findings
9.1
A.5.27
8.6
9.3
DG.4 NS.7
E.73
Long-term supply chain resilience strategies for services
contigency plans, mapping of suppliers, alternative supply chains
A.5.21
A.5.23
8.3.4
(8.3.2)
DG.14 NS.11
E.74
Strategic stockpiling of stocks and resupply mechanisms
so essential services are not affected if supply chain is disrupted
A.5.21 8.3.4 DG.14 NS.11
E.75
Contracts with other sector entities to share resources
staff, equipment during large-scale recovery
A.5.30 8.3.4 DG.4 NS.7

up

Employee security management F

OpenKRITIS mapping of CER guidelines ∙ version 20260718
CER
guide
Requirement ISO 27001
2022
ISO 22301
2019
KRITIS
DachG
NIS2
DE
F.76
Staff-related threats and lists of staff with critical functions
risk of error, sabotage, insider threats, absences
- - DG.15 NS.22
F.77
Consider essential services and link to staff lists and groups
lear, comprehensive and up-to-date documentation of staff categories
- - DG.15 NS.22
F.78
Rules for access to premises, infrastructure and information
processes for granting and revocal
A.5.15
A.5.18
- DG.10 NS.23
F.79
Permissions only on a need-to-know/need-to-access basis
role-based access control (RBAC), IAM, SoD, JiT
A.5.15
A.5.18
- DG.10 NS.23
F.80
Background checks with robust internal procedures
request background checks and designate staff categories
A.6.1 - DG.15 NS.22
F.81
Background check policy with roles, types of checks
identity verification, criminal and employment records and education
A.6.1 - DG.15 NS.22
F.82
Coherent to CIR (EU) 2024/2690 and Article 21 (2) (i) NIS2
personnel security of the NIS2 Implementing Act
A.6.* - - NS.22
CIR10
F.83
Qualifications and training of staff, awareness for resilience
risk-based measures for type and scope of training needed for staff
7.2
7.3
A.6.3
7.2
7.3
DG.16 NS.20
F.84
Training and qualification requirements based on risk, BCM
based on different categories and incident roles of staff
7.2
7.3
A.6.3
7.2
7.3
DG.16 NS.20
F.85
Qualification requirements for staff based on services
ensure staff can execute resilience plan, response, BCM, crises
7.2
7.3
7.2
7.3
DG.16 NS.20

up

Awareness G

OpenKRITIS mapping of CER guidelines ∙ version 20260718
CER
guide
Requirement ISO 27001
2022
ISO 22301
2019
KRITIS
DachG
NIS2
DE
G.86
Awareness program for staff on resilience measures
instilling security culture; staff are a vital element at every stage
A.6.3 7.3
7.4
8
DG.16 NS.19
G.87
Resilience culture based on awareness raising measures
subject to sensitive information and need-to-know basis
A.6.3 7.3
7.4
8
DG.16 NS.19
G.88
Awareness measures together with NIS2 cyberhygiene
and cybersecurity training
A.6.3 7.3
7.4
8
DG.16 NS.19
G.89
Trainings based on training requirements in F.82 and F.83
cover resilience measures and resilience lifecycle
7.2
7.3
A.6.3
7.2
7.3
DG.16 NS.20
G.90
Consider gender-sensitive approaches on training - - DG.16 NS.20
G.91
Information materials based on risk and resilience
clear and easy to digest, role of critical entity and disruptions
A.6.3 7.3
7.4
DG.16 NS.19
G.92
Visual information materials with flowcharts
for security breaches, business continuity, threats
A.6.3
A.5.26
7.3
7.4
8.4.2
DG.16 NS.19
G.93
Exercises for staff and roles to validate resilience plan
all-hazards approach, discussion-based exercises, tabletops, ops
A.5.30 8.5 DG.16 NS.19
G.94
Exercise and test full cycle of resilience based on risk
cross-sectoral coordination and dependencies
A.5.30 8.5 DG.16 NS.19

up

Comments and note

The CER Guidelines C/2026/3712 contain an rather exhausting set of resilience and security requirements, or recommendations, for critical operators regulated by EU CER.

Sometimes, as the domains were possibly written by different authors, there is overlap between topics and also domains. BCM and crisis management as well as preparation and response are clustered over several domains, as is access control and access rights.

There are some noteworthy topics only covered on the sidelines by the original EU CER directive

NIS2 and Implementing Act

When mapping CER Guideline requirements to EU NIS2, helped by the EU Implementing Act, there is good but very high-level coverage for most topics. Many CER requirements for resilience and security are also applicable to NIS2 and covered in the Implementing Act – CER and C/2026/3712 just contain more detailed topics with much more depth and details.

German CER in KRITIS-Dachgesetz

An update to the German KRITIS-Dachgesetz mapping for CER Guidelines is forthcoming. There is obviously good coverage by CER Guidelines in KRITIS-Dachgesetz (CER) requirements, however the latter is missing many details and some specific topics from the guidelines. Access control is much lighter in KRITIS-Dachgesetz as are many maintenance, equipment and stock/supply chain requirements.

And some of the topics above (drones, water) have not been covered in KRITIS-Dachgesetz.

ISO 27001 and 22301

There is a mixed picture mapping the CER Guidelines against international security and resilience standards. For many security requirements, there is good coverage in ISO 27001, the standard on information security. Personnel and physical security as well as risk management is covered well in ISO 27001 with notable gaps on overarching BCM and crisis management and strategic resilience.

Still, there is a surprising amount of ISO 27001 controls that cover or touch CER Guideline control.

For ISO 22301, the standard on resilience, there is very good coverage of everything related to preparation, resilience, response and planning. There remain very notable gaps between CER Guidelines and ISO 22301 in physical and personnel security, which are mostly absent from ISO 22301. An ISO 22301-compliant BCMS will go a long way to cover robust resilience management for CER though.

up

Further Information

Sources

  1. Guidelines on the application of Article 13(5) of Directive (EU) 2022/2557 on the resilience of critical entities, Communication from the Commission, C/2026/4730, July 2026
  2. Leitlinien für die Anwendung von Artikel 13 Absatz 5 der Richtlinie (EU) 2022/2557 über die Resilienz kritischer Einrichtungen, Mitteilung der Kommission, C/2026/4730, 13.7.2026
  3. Dachgesetz zur Stärkung der physischen Resilienz kritischer Anlagen, KRITIS-Dachgesetz vom 11. März 2026 (BGBl. 2026 I Nr. 66)
  4. ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements
  5. ISO 22301:2019 Security and resilience — Business continuity management systems — Requirements