CER Guidelines Resilience
The European Commission published Guidelines (C/2026/3712) for resilience, physical and personnel measures for the EU CER directive.
CER requires critical operators to take appropriate and proportionate technical, security and organisational measures to ensure their resilience.
The Guidelines from 2026 contain non-binding resilience and security measures for CER operators.
- C/2026/3712
- General considerations
- Prevention
- Physical protection
- Response, resistance
- Recovery
- Employee security
- Awareness
- Comments
Mappings to the following standards are provided without guarantee of correctness or completeness.
- ISO 27001:2022: Information security management with Annex A security controls
- ISO 22301:2019: Governance for resilience and BCM
- KRITIS-Dachgesetz: Obligations from German CER transposition (2026)
- NIS2 (DE): Obligations from German NIS2 transposition (2025)
C/2026/3712
CER Guidelines
The CER Guidelines (C/2026/3712) were published in July 2026 by the Commission as part of communication C/2026/4730. There are seven domains (A—G) with 94 measures, recommendations and controls for CER topics ranging from general risk considerations to personnel security. The Guidelines were drafted by the Commission with the Critical Entities Resilience Group (CERG) in 2025.
| Group | Requirements | Controls |
|---|---|---|
| A | General considerations Governance and risk management |
A.6—A.17 |
| B | Prevention BCM and risk reduction and measures |
B.18—B.23 |
| C | Physical protection Security of facilities, perimeters, assets |
C.24—C.50 |
| D | Response, resistance and mitigation Incident response and preparation, crises |
D.51—D.65 |
| E | Recovery Redundancy, recovery and BCM planning |
E.66—E.75 |
| F | Employee security management Security of staff, screening, training |
F.76—F.85 |
| G | Awareness Training, awareness, exercises |
G.86—G.94 |
Note the guidelines are a recommendation from the European Commission, mandated by CER to further specify the technical, security and organisational measures that may be taken by critical entities.
However they serve as a useful specification of the various EU CER requirements on resilience to guide and facilitate operators in selecting more concrete controls.
General considerations A
| CER guide |
Requirement | ISO 27001 2022 |
ISO 22301 2019 |
KRITIS DachG |
NIS2 DE |
|---|---|---|---|---|---|
| A.6 | Entities elect resilience measures based on risk analyses:
|
4.1 8.2 8.3 |
4 6 8.2.3 |
DG.3 | NS.1 |
| A.7 | Measures need to be appropriate and proportionate to risks
|
6.1 8.2 8.3 |
6.1 6.2 8.2 |
DG.5 | NS.3 NS.1 |
| A.8 | Guideline measures cover all CER sectors But might not apply to all sectors equally |
- | - | §4 | - |
| A.9 | Measures depend on EU member states risk assessments and critical entities’ risk assessments |
4.1 6.1.2 |
4.1 6.1.2 |
DG.3 §11 |
- |
| A.10 | Resilience measures without prejudice to other legislation NIS2, GDPR, energy law, sector regulation |
A.5.31 | 4.2.2 | - | - |
| A.11 | High-risk AI systems must comply with EU AI legislation EU Artificial Intelligence Act |
- | - | - | - |
| A.12 | Documentation of resilience measures in a resilience plan and use other, existing measures to comply |
partial 6 7.5 |
7.5 4 8 |
DG.18 | NS.2 |
| A.13 | Liaison officer to be designated by critical entity to coordinate measures and interface to authorities |
5.1 5.3 A.5.5 |
5.1 5.3 8.4.2 |
DG.26 | NS.37 |
| A.14 | Identify all assets, cross-border, interdependency aspectsgiven the highly interconnected natureof CER sectors |
4.1 | 4.1 | DG.3 | NS.1 |
| A.15 | Entity and national risk assessments are core mechanism for measures but also for interdependencies |
4.1 | 4.1 | DG.3 §11 |
NS.1 |
| A.16 | International and European standards taken into account for resilience measures |
6 7.1 |
6 7.1 |
DG.5 §11 |
NS.3 |
| A.17 | Critical maritime infrastructure especially protected due to the complex nature of threats |
- | - | DG.3 §12 (2) |
- |
Prevention B
| CER guide |
Requirement | ISO 27001 2022 |
ISO 22301 2019 |
KRITIS DachG |
NIS2 DE |
|---|---|---|---|---|---|
| B.18 | Integrated system for resilience measures and prevention Business Continuity Management (BCM) |
partial A.5.29 A.5.30 |
4—10 | DG.4 | NS.7 |
| B.19 | Risk reduction and and climate adaption measures Over the lifetime of the critical infrastructure |
4.1 AMD1 |
4.1 AMD1 |
DG.3 §11 (2) DG.6 |
- |
| B.20 | Incident database and systematic incident reporting system for a history of events and asset recovery |
A.5.24 A.5.25 A.5.26 |
8.4.2 8.4.3 |
DG.12 DG.23 DG.24 |
NS.6 |
| B.21 | Identification of error-prone tasks and countermeasures to prevent human errors |
- | - | - | - |
| B.22 | Relevant NIS2 measures should be taken into account | 8.2 8.3 |
- | - | NS.1 |
| B.23 | Manual overrides and human-in-the-loop provisions for OT for human intervention and manual control in response to hazards |
A.5.30 | 8.3 8.4.4 |
DG.13 | - |
Physical protection and security C
| CER guide |
Requirement | ISO 27001 2022 |
ISO 22301 2019 |
KRITIS DachG |
NIS2 DE |
|---|---|---|---|---|---|
| C.24 | Physical measures against natural and man-made threats procedural controls to detect, deter, delay, deny ... |
A.7.5 | - | DG.7 DG.9 |
NS.25 |
| C.25 | Appropriate and proportionate measures to threats
|
8.2 8.3 A.5.5 A.5.6 |
8.2 8.3 |
DG.5 | NS.3 |
| C.26 | Perimeter-hardening measures to deter and delay security fencing, reinforced walls, gating, vehicle mitigation, light |
A.7.1 | - | DG.7 | NS.25 |
| C.27 | Controlled checkpoint for access of staff, vehicles, goods limited routes, barriers, spacing |
A.7.2 | - | DG.10 | NS.25 |
| C.28 | Robust or reinforced external entry points (gates/doors) and retrofitted and protected frames and windows |
A.7.2 A.7.3 |
- | DG.10 | NS.25 |
| C.29 | Perimeter monitoring and detection of breaches real-time, alarms, sensors; with zonal coverage, monitored and tested |
A.7.4 | - | DG.8 DG.9 |
NS.25 |
| C.30 | Video systems for monitoring, real-time and recording facilities, entry routes; proper technical parameters, testing |
A.7.4 | - | DG.8 | NS.25 |
| C.31 | Lighting and illumination of entry points, car parks, ways field of view and avoid glare, shadows; emergency and backup lighting |
A.7.5 | - | DG.7 | NS.25 |
| C.32 | Signage for security restrictions, privacy and monitoring | A.5.31 A.5.33 A.5.34 |
- | DG.8 | NS.25 |
| C.33 | Layered security zones for access controls access management, mantraps, locking doors and on-site security staff |
A.7.6 | - | DG.7 | NS.25 |
| C.34 | Utility and equipment rooms locked and access-controlled for electricity, water, cooling, heating, AC, telecommunications etc. |
A.7.8 | - | DG.7 | NS.25 |
| C.35 | Segregated mail rooms and depots away from core assets safety procedures, equipment and trained staff for threats |
A.7.3 A.7.6 |
- | DG.7 | NS.25 |
| C.36 | External facilities and assets with proportionate protection routine inspection and maintenance |
A.7.9 A.7.13 |
- | DG.7 | NS.25 |
| C.37 | Access control and restricted or classified information handling procedures should not preclude NIS2 | A.5.15 A.5.18 |
- | DG.10 | NS.23 |
| C.38 | Single register for physical keys and credentials with issuance, revocation and return dates; procedures for loss |
A.5.18 | - | DG.10 | NS.23 NS.25 |
| C.39 | Least privilege access rights and regularly reviewed Zones with access control and logging; visitor procedures |
A.5.15 A.5.18 A.7.2 A.7.6 |
- | DG.10 | NS.23 NS.25 |
| C.40 | Sensitive information assets protected and positioned according to threats, access on need-to-know basis | A.5.15 A.7.3 A.7.6 |
- | DG.7 DG.10 |
NS.23 NS.25 |
| C.41 | Inventory of sensitive information assets with classification and handling rules, according to business risk | A.5.9 A.5.12 A.5.15 |
- | DG.1 | NS.24 |
| C.42 | Follow national rules on classification and information national security, government information |
A.5.12 A.5.31 |
- | - | NS.24 |
| C.43 | Rules and agreements (NDA) for external access to information, contractual mechanisms | A.5.20 A.6.6 |
- | - | NS.23 NS.20 |
| C.44 | Security zones for facilities housing sensitive information (SCIF), stringent access control and monitoring | A.5.15 A.7.3 A.7.4 A.7.6 |
- | DG.7 DG.8 DG.10 |
NS.23 NS.25 |
| C.45 | Regular review of access rights and retention periods measures to reclassify and sanitize assets as needed |
A.5.18 | - | DG.10 | NS.23 |
| C.46 | Drone (UAV) detection, tracking and identification radar, radio, light and thermal, acoustic, ISAC technologies |
A.5.18 | - | DG.9 DG.10 |
NS.23 |
| C.47 | Countermeasures against surveillance (ISR) by drones obscure visibility of sensitive assets and housing in close facilities |
A.7.3 A.7.5 |
- | DG.7 | NS.25 |
| C.48 | Countermeasures against sabotage by drones and UAVs Counter-UAV netting, canopies, blast-windows, roof strengthening |
A.7.1 A.7.5 |
- | DG.7 | NS.25 |
| C.49 | Establish geographical zones to manage risks of drones Liaise with national authorities, geofencing, aviation frameworks |
A.7.3 A.7.6 A.5.5 |
- | DG.7 | NS.25 |
| C.50 | Partnerships with counter-drone operations from authorities, law-enforcement and defense | A.5.5 A.5.7 |
- | DG.7 | NS.25 |
Response, resistance and mitigation D
| CER guide |
Requirement | ISO 27001 2022 |
ISO 22301 2019 |
KRITIS DachG |
NIS2 DE |
|---|---|---|---|---|---|
| D.51 | Governance & method to mitigate incident consequences
|
partial A.5.30 |
- | DG.11 | NS.10 |
| D.52 | Consider capabilities and capacities required for fail-safe storage, backup, thermal safety, hazardous materials, cooling |
partial A.5.30 A.7.11 A.8.6 A.8.14 |
8.2 8.3 8.4.4 7.5 |
DG.13 | NS.7 |
| D.53 | Maintenance and repair capacities with supply needs Diversify supply routes, infrastructure reinforcement, backup systems |
A.7.13 | 8.3.4 | DG.14 | NS.11 |
| D.54 | Integrity in IT systems, networks and software in equipment e.g. high-risk suppliers, interference from radio frequencies and cyber |
A.7.8 A.8.27 A.5.20 |
- | - | NS.15 NS.12 |
| D.55 | Alternative power systems like UPS and generators regularly tested, fuel for at least 72 hours, vendor emergency contracts |
A.7.13 A.8.14 |
6 8.3 8.4 8.5 |
DG.6 | NS.8 |
| D.56 | Limit water use during disruptions with alternative sources backup wells, storage tanks, treatment units; ensure human quality |
- | 6 8.3 8.4 8.5 |
DG.6 | - |
| D.57 | Just-in-case inventory of utilities (water, boilers, chemicals) Contingency planning in supply chains, back-up resource and supplies |
- | 8.3.4 (8.3.2) |
DG.14 | NS.11 |
| D.58 | Maintenance programs based on reqs, risk and experience Predictive maintenance, forecast of failures, protocols for monitoring |
A.7.13 | - | DG.7 | NS.25 |
| D.59 | Governance structure for resilience – top-to-bottom resilience objectives, strategy, policy, planning and communication |
6.1.3 6.2 8.3 |
4 5 6.3 9 10 |
DG.4 DG.26 |
NS.7 |
| D.60 | Clear decision making hierachies, resilience officer roles, responsibilities and competences at board-level, risk |
5 A.5.4 |
5.1 5.3 7.2 |
DG.26 | NS.37 |
| D.61 | Formal cooperation and sharing with national authorities law-enforcement, emergency, defense, policy makers |
4 A.5.5 |
4 8.4.2 |
DG.1 DG.2 DG.19 DG.20 DG.21 DG.22 DG.23 DG.26 |
NS.37 |
| D.62 | Cooperation with other private-sector actors own and other sectors, other member states |
A.5.6 | 4.2 | - | - |
| D.63 | Crisis communication protocols for incidents information flow; templates, redundant channels and systems |
- | 8.4.2 | DG.11 DG.23 DG.25 |
NS.10 NS.28 |
| D.64 | Services with multi-scale redundancy design to ensure cross-border, national, regional and local services |
A.8.14 A.8.6 |
8.3 8.4 |
DG.13 | NS.7 |
| D.65 | Emergency response procedures with alert systems geo-targeting capabilities, communications, SOPs |
partial A.5.26 |
partial 8.4 |
DG.12 | NS.6 |
Recovery E
| CER guide |
Requirement | ISO 27001 2022 |
ISO 22301 2019 |
KRITIS DachG |
NIS2 DE |
|---|---|---|---|---|---|
| E.66 | Redundancy measures for primary systems failure service prioritisation, manual operation, workforce recovery |
A.5.3 A.8.14 |
8.2 8.3 8.4 |
DG.13 | NS.7 |
| E.67 | Alternative disastery recovery sites: hot or warm sites distant from primary facilities; possible mobile facilities; off-site backup |
A.5.3 A.6.7 A.8.14 |
8.2 8.3 8.4 |
DG.13 | NS.7 |
| E.68 | Business continuity plans (BCPs) and business impact analyses (BIAs) of critical functions (BCM) identify objectives (RTO, RPO), SLAs; tested and reviewed |
A.5.30 | 6 8.2 8.3 8.4 |
DG.6 DG.13 |
NS.7 |
| E.69 | Crisis management procedures with command structures decision making authority, action plans, crisis teams |
- | 8.4.2 | DG.11 | NS.10 NS.28 |
| E.70 | Planning for surge workforce requirements during incidents surge roster, training and mutual-aid agreements |
7.1 A.5.30 |
6 7.1 8.4 |
DG.6 | NS.9 |
| E.71 | Phased restart protocols for recovery with priorities on BIA validation, testing of data & functions, QS, transition to normal |
A.5.30 A.5.29 |
8.2 8.3 8.4.4 7.5 |
DG.12 | NS.6 |
| E.72 | After-action reviews (AARs) with structured methods after all incidents and exercises for lessons learned; with findings |
9.1 A.5.27 |
8.6 9.3 |
DG.4 | NS.7 |
| E.73 | Long-term supply chain resilience strategies for services contigency plans, mapping of suppliers, alternative supply chains |
A.5.21 A.5.23 |
8.3.4 (8.3.2) |
DG.14 | NS.11 |
| E.74 | Strategic stockpiling of stocks and resupply mechanisms so essential services are not affected if supply chain is disrupted |
A.5.21 | 8.3.4 | DG.14 | NS.11 |
| E.75 | Contracts with other sector entities to share resources staff, equipment during large-scale recovery |
A.5.30 | 8.3.4 | DG.4 | NS.7 |
Employee security management F
| CER guide |
Requirement | ISO 27001 2022 |
ISO 22301 2019 |
KRITIS DachG |
NIS2 DE |
|---|---|---|---|---|---|
| F.76 | Staff-related threats and lists of staff with critical functions risk of error, sabotage, insider threats, absences |
- | - | DG.15 | NS.22 |
| F.77 | Consider essential services and link to staff lists and groupslear, comprehensive and up-to-date documentationof staff categories |
- | - | DG.15 | NS.22 |
| F.78 | Rules for access to premises, infrastructure and information processes for granting and revocal |
A.5.15 A.5.18 |
- | DG.10 | NS.23 |
| F.79 | Permissions only on a need-to-know/need-to-access basis role-based access control (RBAC), IAM, SoD, JiT |
A.5.15 A.5.18 |
- | DG.10 | NS.23 |
| F.80 | Background checks with robust internal procedures request background checks and designate staff categories |
A.6.1 | - | DG.15 | NS.22 |
| F.81 | Background check policy with roles, types of checks identity verification, criminal and employment records and education |
A.6.1 | - | DG.15 | NS.22 |
| F.82 | Coherent to CIR (EU) 2024/2690 and Article 21 (2) (i) NIS2 personnel security of the NIS2 Implementing Act |
A.6.* | - | - | NS.22 CIR10 |
| F.83 | Qualifications and training of staff, awareness for resilience risk-based measures for type and scope of training needed for staff |
7.2 7.3 A.6.3 |
7.2 7.3 |
DG.16 | NS.20 |
| F.84 | Training and qualification requirements based on risk, BCM based on different categories and incident roles of staff |
7.2 7.3 A.6.3 |
7.2 7.3 |
DG.16 | NS.20 |
| F.85 | Qualification requirements for staff based on services ensure staff can execute resilience plan, response, BCM, crises |
7.2 7.3 |
7.2 7.3 |
DG.16 | NS.20 |
Awareness G
| CER guide |
Requirement | ISO 27001 2022 |
ISO 22301 2019 |
KRITIS DachG |
NIS2 DE |
|---|---|---|---|---|---|
| G.86 | Awareness program for staff on resilience measures instilling security culture; staff are a vital element at every stage |
A.6.3 | 7.3 7.4 8 |
DG.16 | NS.19 |
| G.87 | Resilience culture based on awareness raising measures subject to sensitive information and need-to-know basis |
A.6.3 | 7.3 7.4 8 |
DG.16 | NS.19 |
| G.88 | Awareness measures together with NIS2 cyberhygiene and cybersecurity training |
A.6.3 | 7.3 7.4 8 |
DG.16 | NS.19 |
| G.89 | Trainings based on training requirements in F.82 and F.83 cover resilience measures and resilience lifecycle |
7.2 7.3 A.6.3 |
7.2 7.3 |
DG.16 | NS.20 |
| G.90 | Consider gender-sensitive approaches on training | - | - | DG.16 | NS.20 |
| G.91 | Information materials based on risk and resilience clear and easy to digest, role of critical entity and disruptions |
A.6.3 | 7.3 7.4 |
DG.16 | NS.19 |
| G.92 | Visual information materials with flowcharts for security breaches, business continuity, threats |
A.6.3 A.5.26 |
7.3 7.4 8.4.2 |
DG.16 | NS.19 |
| G.93 | Exercises for staff and roles to validate resilience plan all-hazards approach, discussion-based exercises, tabletops, ops |
A.5.30 | 8.5 | DG.16 | NS.19 |
| G.94 | Exercise and test full cycle of resilience based on risk cross-sectoral coordination and dependencies |
A.5.30 | 8.5 | DG.16 | NS.19 |
Comments and note
The CER Guidelines C/2026/3712 contain an rather exhausting set of resilience and security requirements, or recommendations, for critical operators regulated by EU CER.
Sometimes, as the domains were possibly written by different authors, there is overlap between topics and also domains. BCM and crisis management as well as preparation and response are clustered over several domains, as is access control and access rights.
There are some noteworthy topics only covered on the sidelines by the original EU CER directive
- Drone and UAV detection and countermeasures
- Water requirements
- Sensitive and classified information handling
- Inventory of utilities, stocks and suppliers
- Access control and management
NIS2 and Implementing Act
When mapping CER Guideline requirements to EU NIS2, helped by the EU Implementing Act, there is good but very high-level coverage for most topics. Many CER requirements for resilience and security are also applicable to NIS2 and covered in the Implementing Act – CER and C/2026/3712 just contain more detailed topics with much more depth and details.
German CER in KRITIS-Dachgesetz
An update to the German KRITIS-Dachgesetz mapping for CER Guidelines is forthcoming. There is obviously good coverage by CER Guidelines in KRITIS-Dachgesetz (CER) requirements, however the latter is missing many details and some specific topics from the guidelines. Access control is much lighter in KRITIS-Dachgesetz as are many maintenance, equipment and stock/supply chain requirements.
And some of the topics above (drones, water) have not been covered in KRITIS-Dachgesetz.
ISO 27001 and 22301
There is a mixed picture mapping the CER Guidelines against international security and resilience standards. For many security requirements, there is good coverage in ISO 27001, the standard on information security. Personnel and physical security as well as risk management is covered well in ISO 27001 with notable gaps on overarching BCM and crisis management and strategic resilience.
Still, there is a surprising amount of ISO 27001 controls that cover or touch CER Guideline control.
For ISO 22301, the standard on resilience, there is very good coverage of everything related to preparation, resilience, response and planning. There remain very notable gaps between CER Guidelines and ISO 22301 in physical and personnel security, which are mostly absent from ISO 22301. An ISO 22301-compliant BCMS will go a long way to cover robust resilience management for CER though.
Further Information
Sources
- Guidelines on the application of Article 13(5) of Directive (EU) 2022/2557 on the resilience of critical entities, Communication from the Commission, C/2026/4730, July 2026
- Leitlinien für die Anwendung von Artikel 13 Absatz 5 der Richtlinie (EU) 2022/2557 über die Resilienz kritischer Einrichtungen, Mitteilung der Kommission, C/2026/4730, 13.7.2026
- Dachgesetz zur Stärkung der physischen Resilienz kritischer Anlagen, KRITIS-Dachgesetz vom 11. März 2026 (BGBl. 2026 I Nr. 66)
- ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements
- ISO 22301:2019 Security and resilience — Business continuity management systems — Requirements