CER Directive · Physical Resilience · EU

CER pentest:
Do for physical security what you do for cyber

The CER Directive is the physical counterpart to NIS2: it requires operators of critical entities to systematically test and demonstrate their physical resilience, just as NIS2 requires for cybersecurity. In Germany, the national transposition (the KRITIS-Dachgesetz) has been in force since 17 March 2026; operators designated as critical entities must register with BBK and BSI by 17 July 2026. Those who ignore this face personal liability.

Test evidence for your CER records Focus on physical resilience Free initial consultation
The dip and the restartSchematic
Resilience curve: capacity to operate before, during and after a disruption, tested against untested Disruption tested untested Time Capacity to operate
Tested: the dip stays shallow and operations restart quickly.
Untested: a deeper outage, a longer restart, rarely back to the previous level.
What you get
  1. 01
    Physical resilience evidence

    Documented proof that your physical security measures have been tested and assessed, usable for CER audits and regulatory submissions.

  2. 02
    Real attack simulation

    Instead of a theoretical risk model, we actually test whether unauthorised access to your critical areas is possible.

  3. 03
    Physical & social engineering combined

    Most physical security gaps arise through the human factor. We test both together for a realistic overall picture.

  4. 04
    Clear remediation recommendations

    Every finding with a concrete measure: what needs immediate attention, what can be addressed mid-term?

Our report documents physical vulnerabilities in line with CER Directive requirements and is suitable for internal and external audits as well as regulatory submissions.

NIS2 meets CER

What is the CER Directive?

Many organisations have introduced and regularly tested extensive cybersecurity measures. The CER Directive requires exactly the same for physical security. The concept is identical; only the attack vectors differ.

What you do for cyber, now also for physical security

Cybersecurity (NIS2)
  • Penetration test on IT systems
  • Firewall & access control review
  • Vulnerability scans & risk analysis
  • Documented audit report for regulators
One operation, two layers CER requires the same
Physical security (CER)
  • Physical pentest on buildings & facilities
  • Access control & lock systems tested
  • Social engineering & tailgating simulated
  • Documented resilience evidence for regulators

Organisations that already take NIS2 seriously have learned that systematic testing beats blindly trusting security measures. CER transfers this principle to the physical world, with the same legal consequences for non-compliance.

One legislative package, two obligations

CER vs. NIS2: same package, different focus

CER and NIS2 come from the same 2022 EU legislative package and often apply to the same operators, yet they are two separate compliance obligations that are frequently confused.

NIS2: Directive (EU) 2022/2555

NIS2

Governs cybersecurity: protecting networks, IT systems, and data of essential and important entities. Transposed in Germany via the NIS2UmsuCG.

CER: Directive (EU) 2022/2557

CER

Governs the physical and organisational resilience of the same category of operators: protection against sabotage, natural disasters, technical failure, and terrorism. Transposed in Germany via the KRITIS-Dachgesetz.

CER evidence does not replace NIS2 evidence, or vice versa. Operators subject to both directives need documented compliance on both levels.

Affected entities

Who does the CER Directive apply to?

CER applies to operators of critical entities in the eleven sectors of the Directive's annex; the transport sector covers air, rail, road, water and public transit. The overlap with NIS2 is significant: many operators fall under both directives at once and must demonstrate cyber as well as physical resilience.

  1. 01Energy
  2. 02Transport: air & rail
  3. 03Transport: road, water & public transit
  4. 04Banking
  5. 05Financial market infrastructure
  6. 06Health
  7. 07Drinking water
  8. 08Waste water
  9. 09Digital infrastructure
  10. 10Public administration
  11. 11Space
  12. 12Food: production, processing & distribution

What are the consequences of non-compliance?

CER is not a recommendation catalogue: it is binding EU law with real consequences.

  1. 01Fines of up to €1 million under section 24 of the German KRITIS umbrella act, graded by breach – there are no turnover-based fines here as there are under NIS2
  2. 02Orders for immediate remediation from competent authorities, including possible temporary operational restrictions
  3. 03Public disclosure of violations, with significant reputational damage towards customers, partners, and investors
  4. 04Civil liability towards third parties in the event of incidents where security obligations were demonstrably neglected

Management responsibility: non-delegable

Section 20 of the German KRITIS umbrella act puts management on the hook: it must implement the resilience measures and make sure they are actually in place. Where it fails to, it is liable to its own entity for the damage, under the rules that apply to its legal form anyway. The duty cannot be handed down.

Status in Germany: the KRITIS-Dachgesetz

Germany missed the EU transposition deadline of 17 October 2024. The KRITIS-Dachgesetz was approved by the Federal Cabinet on 10 September 2025, passed by the Bundestag on 29 January 2026, approved by the Bundesrat on 6 March 2026, and has been in force since 17 March 2026. Operators designated as critical entities must register with the Federal Office of Civil Protection and Disaster Assistance (BBK) and the BSI by 17 July 2026.

CER requirements

What does Art. 13 CER require of operators?

Article 13 CER requires operators to take 'appropriate and proportionate technical, security and organisational measures' across four goals: preventing incidents, ensuring physical protection, responding to incidents, and recovering from them. A physical penetration test is the audit instrument for the most important of these and delivers the evidence that regulators expect.

  1. Prevent Art. 13 (1) a
  2. Protect Art. 13 (1) b
  3. Respond Art. 13 (1) c
  4. Recover Art. 13 (1) d
  1. 01

    Physical access controls

    Operators must ensure that only authorised persons have access to critical areas. A pentest shows whether these controls hold up in practice or only exist on paper.

    Physical pentest
  2. 02

    Perimeter security

    Fences, cameras, lighting, and barriers must be effective. We test whether they actually stop a determined attacker or merely serve as a deterrent.

    Physical pentest
  3. 03

    Protection against insider threats

    Not all threats come from outside. Social engineering and insider scenarios show how resilient your organisation truly is against internal risks.

    Social engineering
  4. 04

    Employee security awareness

    Employees are the first and last line of defence. We test whether they recognise tailgating, pretexts, and manipulation attempts, or willingly hold the door open.

    Social engineering
  5. 05

    Incident detection & response

    How quickly is a physical intruder detected and reported? We test the detection and response capability of your organisation under realistic conditions.

    Physical pentest
  6. 06

    Protection of critical resources

    Servers, control systems, operations centres: the most sensitive areas need the highest protection. We test their security specifically and show where the gaps are.

    Physical pentest
  7. 07

    Personnel & supply chain due diligence

    Art. 13 also requires background checks for security-relevant personnel and contractually pushing resilience obligations down to suppliers and service providers. We test whether these obligations actually hold up in practice, or only exist on paper.

    Social engineering
Our approach

How does a CER physical pentest work?

Systematic, documented, and CER-compliant: our approach delivers the evidence the directive requires and regulators expect.

  1. 01

    Scoping & target definition

    Which areas, buildings, and scenarios should be tested? We jointly define the scope, taking your operational requirements and CER obligations into account.

  2. 02

    Reconnaissance & preparation

    Information gathering about your site, publicly visible security measures, employee movements, and potential entry points.

  3. 03

    Physical penetration test

    Simulated break-in attempt under realistic conditions: tailgating, lock picking, perimeter tests, social engineering, within the agreed scope.

  4. 04

    Documentation & analysis

    Complete logging of all test actions, findings, and timestamps. Assessment by severity, exploitability, and regulatory relevance.

  5. 05

    CER-compliant final report

    Complete report with all findings, recommendations, and CER mapping per Art. 13. Suitable as audit evidence for regulatory authorities and management.

11
Sectors affected by CER
Art. 13
CER core article for physical measures
24 hrs
Initial incident notification deadline (Art. 15 CER)
3 months
registration deadline, counted from the day an installation qualifies as critical
Relevant pentest modules

What building blocks does your CER evidence need?

CER focuses on physical resilience. These three modules cover the central requirements of the directive and deliver the evidence regulators expect.

Physical penetration test

Simulated break-in attempt at your facilities: tailgating, lock picking, perimeter tests. The core module for CER evidence: we test whether unauthorised access is possible.

Learn more

Social engineering assessment

Phishing, vishing, personal manipulation: most physical security gaps arise through the human factor. We show how far targeted deception goes.

Learn more

Resilience documentation

For CER, the test alone is not enough: the evidence must also be documented and suitable for regulators. We deliver a structured final report as a complete audit document.

Learn more

What our CER report contains

  1. Complete documentation of all test actions performed with timestamps
  2. Assessment of every finding by severity and exploitability
  3. Mapping to Art. 13 CER requirements catalogue
  4. Prioritised remediation plan with concrete recommendations
  5. Management summary for board, supervisory board, and regulators
Frequently asked questions

CER & physical security testing: your questions

NIS2 regulates the cybersecurity of critical entities: protecting IT systems, networks, and data. CER is the physical counterpart: it requires the same operators to systematically test and ensure their physical resilience. In short, NIS2 covers the digital side, CER covers the physical. Both are binding EU law, and both carry real sanctions for non-compliance.
CER does not prescribe a specific testing method, but requires operators to test, assess, and document their physical security measures. A physical penetration test is the recognised and practical instrument for this: it delivers real insights rather than theoretical risk models and provides the audit evidence regulators expect. Organisations that rely solely on paper documentation without ever actually testing their measures will find themselves without evidence when it matters.
No, and this is one of the most important aspects of the CER Directive. The duty to ensure physical resilience lies explicitly at board level. Managing directors and board members face personal liability for the fulfilment of these obligations. The topic can be coordinated internally, but the responsibility remains with management. In the event of damage, regulators and courts will examine whether senior management fulfilled their supervisory duty.
CER provides for fines of up to 2% of global annual turnover, comparable to GDPR sanctions. On top of that come orders for immediate remediation, possible operational restrictions, and public disclosure of violations. Proven negligence also exposes organisations to civil liability towards third parties. The combination of fines, reputational damage, and personal liability makes inaction the most expensive option.
Yes, and we recommend this for all operators subject to both directives. A combined assessment tests both physical and digital attack vectors in one engagement and delivers an integrated report that serves as evidence for both directives. This saves effort and provides the complete security picture. Talk to us about a tailored combination package.
There is no one-size-fits-all answer: scope, number of sites, desired scenarios, and reporting depth all significantly affect the effort involved. What we can say is that an outage nobody ever rehearsed usually costs a multiple of what the test would have cost. After a free initial consultation you will receive a transparent fixed-price offer.
Designation runs through the member states: the basis is a national strategy to strengthen the resilience of critical entities plus a national risk assessment. An operator is considered critical if it provides an essential service in one of the eleven CER sectors, is located in the relevant member state, and an incident would significantly disrupt the provision of that service. In Germany, formal designation is carried out by the BBK under the KRITIS-Dachgesetz; affected operators are notified by the competent authorities and must then register.
Article 15 CER requires an initial notification to the competent authority without undue delay, no later than 24 hours after the incident becomes known, where operationally feasible. A detailed report covering root cause, affected users, duration, and geographic extent follows no later than one month later. Whether your organisation even detects a physical incident in time is exactly what we test in the Incident Detection & Response module.