STOP PRESS: This Practice Note reflects the current legislative position, however please note that certain elements will be impacted by the Digital Omnibus proposals published on 19 November 2025 pursuant to the Commission’s ‘simplification’ agenda. For more information, see Practice Note: EU Digital Omnibus—tracker. This Practice Note provides an overview of the key aspects of Directive (EU) 2022/2557 on the resilience of critical entities, the EU Critical Entities Resilience Directive (CER Directive), including its scope, key obligations for critical entities, its sanctions regime and what the new requirements mean for organisations in practice. The CER Directive is part of the EU’s broader effort to strengthen the resilience of critical infrastructure across sectors. It is not primarily a cybersecurity law, but it does intersect with cybersecurity as cyber incidents can threaten the resilience of critical entities, alongside other threats such as natural hazards, terrorism, insider threats, pandemics and sabotage. Background In an evaluation report published in July 2019, the European Commission determined that the technological, economic, social, political and environmental context