CER directive: Resilience for “everything but cyber”
…and why it still matters for cybersecurity
Everybody talks about NIS-2, nobody talks about CER. Time to change that — and learn why CER as a directive for “everything but cyber” has quite a lot to do with cybersecurity…
CER is the abbreviation for the Critical Entities Resilience Directive (EU 2022/2557). It came into force on January 16, 2023 and should have been transposed into national law in all EU member states by October 17, 2024 — but many states, including Germany, haven’t been able to meet that deadline.
The CER Directive is often overlooked in comparison to NIS-2. Perhaps because it is often over-simplified as “it’s only about physical security”.
Who is affected?
The CER directive affects “critical entities”. These include the energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, public administration, space as well as food production, processing and distribution sectors — a somewhat expanded version of the familiar critical infrastructure sectors regulated in the EU.
These are very much the same critical facilities that the critical infrastructure cybersecurity directive NIS-2 regulates. The NIS-2 scope covers the CER critical facilities in full and goes beyond them.
Also in other aspects, CER has many parallels with NIS-2. Affected facilities must carry out a risk analysis, take measures and report incidents.
What is the difference to NIS-2?
CER excludes cybersecurity, because it is already covered by NIS-2. This is stated directly in the first article (Art. 1 (2)). Thus, CER is about the resilience of the critical services — against everything except cyber attacks.
Obligations for EU member states
The directive contains quite a few tasks not directly for critical entities, but for the EU member states: they must
- adopt a resilience strategy,
- identify critical entities on their territory, and
- carry out a risk assessment for all critical services every four years.
Again, for “everything but cyber” — for accidents, natural disasters, pandemics and also — and here it becomes clear why “everything but cyber” is so difficult: hybrid threats. But more on that later.
Obligations for critical entities
This risk assessment is then sent to the EU Commission and the critical entities — which in turn have to carry out risk assessments (again: for everything except cyber) for themselves every four years on this basis.
Then, the critical entities must take resilience measures on the basis of all these risk assessments. For everything except cyber:
- Disaster preparedness and crisis management
- Business continuity management including restart plans
- Physical protection and
- Reliability checks and training for staff.
In addition, security incidents must be reported to the relevant authorities in the member states.
What does CER have to do with cybersecurity?
Very valid question. Because if CER covers “everything but cyber” — can’t we be completely indifferent to it from a cyber perspective?
I could offer two reasons why not.
Reason one: The CER results are the foundation for NIS-2.
The core requirement of the CER directive is resilience, i.e. getting back on your feet quickly in the event of a security incident.
In business continuity management (BCM), the primary method in addition to the risk analysis is a business impact analysis (BIA): you analyze which business processes need to run to keep the critical service running and consider how bad it would be for each process if it ceased to work. If it ceases to work for cyber or non-cyber reasons ? The BIA (in contrast to risk analysis!) doesn’t care at all.
Therefore, in business impact analysis, a reduction to “everything but cyber” is impossible.
And even if the process models that are created as part of a BIA tend to be far away from “cyber” at first glance, a BIA is a goldmine for a cybersecurity risk assessment as required for NIS-2. It provides what so many cyber risk assessments lack: that you don’t take off into cyberspace, but keep your feet firmly on the ground, where the critical service is actually provided. That’s the basis for all consequence-based risk assessments.
Those who have modeled their critical processes before the cyber risk analysis know the worst possible consequences of a cyber incident — and can focus on them.
Those who have modeled their critical processes before the cyber risk analysis can prioritize the importance of cyber systems.
In conclusion: The business impact analysis that CER asks for should be required reading for anyone implementing NIS-2.
Reason two: Attackers do not separate “cyber” and “non-cyber” either.
Let’s get back to the hybrid threats: These have long been a reality. The great fears of a cyber war in which cyber attacks are used instead of bombs have not materialized so far, but this is not an “all-clear” signal: hybrid threats mean that cyber attacks are used in addition to physical attacks, not instead. A bomb destroys more effectively, but if communication is disrupted and disinformation is spread at the same time, this increases the effect of the bomb on the country under attack. Hybrid means doing one thing while not leaving the other undone.
So it’s not just that attackers don’t distinguish between “cyber” and “non-cyber”: the mixing of both is deliberate and strategic. This needs to be taken into account, especially in risk assessments.
It would therefore be desirable for the member states’ implementation of CER and NIS-2 to happen together, or at least in coordination with each other.
That’s what Article 1 (2) of the CER Directive obliges the member states to do: “coordinate the implementation” of NIS-2 and CER.
But at least in the latest German drafts for NIS-2 implementation, which I follow most closely, the implementation of the CER Directive is no longer mentioned. While the German NIS-2 implementation is picking up speed, there has so far been a deafening silence on CER implementation.
In short: if NIS-2 is to become a racing car, then CER is the filling station; the place where the car gets the fuel it urgently needs.
The working title that the past German government was using for the German CER directive implementation was “critical infrastructure umbrella law”. At least the title wasn’t that bad…
This article was first published in the montly “Security-Briefing for Hard Hats” [in German]. You can subscribe here.
