Skip to main content

      The Critical Entities Resilience Directive (CER) is the physical counterpart to the cyber-focused NIS2 directive. The overall aim of CER is to strengthen collective resilience by addressing physical threats to critical infrastructure meaning that CER shifts the focus from digital resilience to physical threats, personnel security, and operational durability. 

      Ensuring that public and private organizations possess intrinsic robustness and operational resilience is necessary for national stability and security, and the CER underscores this exact necessity. This makes it vital for organizations providing essential services to proactively address these specific requirements. 

      In this article, we share our breakdown of CER, highlight key requirements and scope criteria, and provide insights based on our ongoing client engagements.


      1. Understanding the Directive

      Recent global crises - including geopolitical conflicts, supply chain vulnerabilities, and climate-driven disasters - have highlighted the urgent need for enhanced physical readiness across Europe.

      At the same time, increasing systemic interconnectedness, complex supply chains, fragmented sector-specific regulations, and inconsistent definitions of "critical" infrastructure have made effective resilience measures highly challenging.

      CER establishes a harmonized framework to protect critical infrastructure from non-cyber risks. It utilizes an "all-hazards" approach, encompassing everything from natural disasters and technical failures to intentional acts of sabotage or terrorism. It covers physical security, personnel security, supply chain vulnerability, and the operational resilience of essential services across 11 critical sectors, incl. energy, banking, healthcare, and food production/distribution. 

      2. Regulatory timeline and Danish supervision 

      CER entered into force at the EU level in January 2023. Organizations classified as "critical entities" under the CER must be formally designated no later than July 17, 2026. 

      Once an organization receives its official designation, it has a strict 10-month window to comply with the directive’s requirements. This establishes a final compliance deadline for May 2027.

      In Denmark, CER is primarily implemented in “Lov om kritiske enheders modstandsdygtighed” (The CER Act) which is governed by the sector responsibility principle (sektoransvarsprincippet), meaning individual sector ministries (ressortministerier) oversee compliance within their specific fields. Overarching coordination and general implementation processes are driven by the Ministry of Resilience and Preparedness (Ministeriet for Samfundssikkerhed og Beredskab) and the Danish Resilience Agency (Styrelsen for Samfundssikkerhed).

      Our explicit recommendation is that any organization operating within a critical sector should begin aligning its resilience frameworks now to prepare for deadlines.  

      3. Designation criteria and scope

      Sectors in scope:

      • Energy
      • Transport
      • Healthcare
      • Drinking Water
      • Wastewater
      • Financial Market Infrastructure
      • Banking
      • Digital Infrastructure
      • Public Administration
      • Large-scale Food Production, Processing, and Distribution
      • Space

      An entity is classified as critical under CER if:

      1. It provides an essential service.
      2. Its core infrastructure is physically located within Denmark.
      3. An operational incident would cause significant disruptive effects on society or the economy.

      4. Key requirements for designated entities


      Critical entities are legally required to collaborate actively with competent authorities and industry peers. This includes sharing incident insights, participating in joint resilience exercises, and establishing specialized training protocols. 

      Within 9 months of designation, entities must execute an internal risk assessment. This assessment must be updated at least every four years and must cover: 

      • All relevant natural and man-made physical threats.
      • Direct dependencies and systemic supply chain vulnerabilities. 

      The risk assessment requirements under CER are significantly more comprehensive than traditional security reviews. We also recommend that all organizations incorporate this broader framework to achieve a holistic approach to resilience.

      Designated entities must implement proportionate technical and organizational measures to compile a formal Resilience Plan (modstandsdygtighedsplan). This framework covers: 

      • Physical security of premises, critical facilities, and infrastructure. 
      • Structured incident prevention, handling, mitigation, and recovery protocols. 
      • Specialized personnel security management, including mandatory background checks for sensitive roles. 
      • Appointing a dedicated point of contact to interface with the authorities. 
      • The formal compilation of a resilience plan.

      The framework relies on core functional pillars to achieve security and operational durability: Prevent, Protect, Respond, Resist, Mitigate, and Recover. Additionally, entities must designate a dedicated point of contact to interface with the authorities.

      The CER Directive emphasizes the critical importance of personnel security, explicitly mandating background checks for sensitive roles. Covered organizations must also account for third-party vendor personnel when mitigating insider risk.

      Implementing these personnel security measures highlights the importance of surrounding legislation; it is crucial that organizations balance background checks with local privacy regulations, employment laws, and anti-discrimination mandates.

      Critical entities are legally required to notify authorities of any incident that significantly disrupts, or has the potential to disrupt, the delivery of essential services. The following notification windows apply:

      • Within 24 hours: Submission of an initial, preliminary incident alert. 
      • Within 1 month: Submission of a detailed, comprehensive final report. 

      5. Sanctions and enforcement

      The enforcement and penalty regimes under the Danish CER Act are dictated to be effective, proportionate, and highly dissuasive. Supervisory sector authorities hold the power to issue binding administrative orders and enforce strict compliance penalties to ensure national resilience. 


      Frederik Thufason

      Partner, Advisory

      KPMG in Denmark


      How KPMG can help

      We offer end-to-end operational support to ensure your organization is ready for the Danish CER Act: 

      • Clarifying organizational scope and group considerations. 
      • Conducting gap, maturity, and deep physical risk assessments. 
      • Deep technical insight into physical, personnel, and information security.
      • Development of compliance roadmaps.
      • Implementation of measures covering the entire spectrum of resilience, from preventive security to emergency preparedness and business continuity.
      • Coordinated compliance with CER, NIS2 etc.

      We have a proprietary maturity measurement tool for physical, personnel, and information security that enables leadership to make informed choices on where risk-reducing measures should be applied.




      Contact us

      Please reach out if you would like to hear more about how we can help your organization.

      Frederik Thufason

      Partner, Advisory

      KPMG in Denmark

      Theodosios Kokotas
      Theodosios Kokotas

      Senior Manager, Advisory

      KPMG in Denmark



      Subscribe to our KPMG insights newsletter

      Turn insight into opportunity with perspectives and actionable insights on the issues shaping the future of business - from technology and transformation to transactions and financial services.