The CER Directive is the physical counterpart to NIS2: it requires operators of critical entities to systematically test and demonstrate their physical resilience, just as NIS2 requires for cybersecurity. In Germany, the national transposition (the KRITIS-Dachgesetz) has been in force since 17 March 2026; operators designated as critical entities must register with BBK and BSI by 17 July 2026. Those who ignore this face personal liability.
Documented proof that your physical security measures have been tested and assessed, usable for CER audits and regulatory submissions.
Instead of a theoretical risk model, we actually test whether unauthorised access to your critical areas is possible.
Most physical security gaps arise through the human factor. We test both together for a realistic overall picture.
Every finding with a concrete measure: what needs immediate attention, what can be addressed mid-term?
Our report documents physical vulnerabilities in line with CER Directive requirements and is suitable for internal and external audits as well as regulatory submissions.
Many organisations have introduced and regularly tested extensive cybersecurity measures. The CER Directive requires exactly the same for physical security. The concept is identical; only the attack vectors differ.
Organisations that already take NIS2 seriously have learned that systematic testing beats blindly trusting security measures. CER transfers this principle to the physical world, with the same legal consequences for non-compliance.
CER and NIS2 come from the same 2022 EU legislative package and often apply to the same operators, yet they are two separate compliance obligations that are frequently confused.
Governs cybersecurity: protecting networks, IT systems, and data of essential and important entities. Transposed in Germany via the NIS2UmsuCG.
Governs the physical and organisational resilience of the same category of operators: protection against sabotage, natural disasters, technical failure, and terrorism. Transposed in Germany via the KRITIS-Dachgesetz.
CER evidence does not replace NIS2 evidence, or vice versa. Operators subject to both directives need documented compliance on both levels.
CER applies to operators of critical entities in the eleven sectors of the Directive's annex; the transport sector covers air, rail, road, water and public transit. The overlap with NIS2 is significant: many operators fall under both directives at once and must demonstrate cyber as well as physical resilience.
CER is not a recommendation catalogue: it is binding EU law with real consequences.
Section 20 of the German KRITIS umbrella act puts management on the hook: it must implement the resilience measures and make sure they are actually in place. Where it fails to, it is liable to its own entity for the damage, under the rules that apply to its legal form anyway. The duty cannot be handed down.
Germany missed the EU transposition deadline of 17 October 2024. The KRITIS-Dachgesetz was approved by the Federal Cabinet on 10 September 2025, passed by the Bundestag on 29 January 2026, approved by the Bundesrat on 6 March 2026, and has been in force since 17 March 2026. Operators designated as critical entities must register with the Federal Office of Civil Protection and Disaster Assistance (BBK) and the BSI by 17 July 2026.
Article 13 CER requires operators to take 'appropriate and proportionate technical, security and organisational measures' across four goals: preventing incidents, ensuring physical protection, responding to incidents, and recovering from them. A physical penetration test is the audit instrument for the most important of these and delivers the evidence that regulators expect.
Operators must ensure that only authorised persons have access to critical areas. A pentest shows whether these controls hold up in practice or only exist on paper.
Physical pentestFences, cameras, lighting, and barriers must be effective. We test whether they actually stop a determined attacker or merely serve as a deterrent.
Physical pentestNot all threats come from outside. Social engineering and insider scenarios show how resilient your organisation truly is against internal risks.
Social engineeringEmployees are the first and last line of defence. We test whether they recognise tailgating, pretexts, and manipulation attempts, or willingly hold the door open.
Social engineeringHow quickly is a physical intruder detected and reported? We test the detection and response capability of your organisation under realistic conditions.
Physical pentestServers, control systems, operations centres: the most sensitive areas need the highest protection. We test their security specifically and show where the gaps are.
Physical pentestArt. 13 also requires background checks for security-relevant personnel and contractually pushing resilience obligations down to suppliers and service providers. We test whether these obligations actually hold up in practice, or only exist on paper.
Social engineeringSystematic, documented, and CER-compliant: our approach delivers the evidence the directive requires and regulators expect.
Which areas, buildings, and scenarios should be tested? We jointly define the scope, taking your operational requirements and CER obligations into account.
Information gathering about your site, publicly visible security measures, employee movements, and potential entry points.
Simulated break-in attempt under realistic conditions: tailgating, lock picking, perimeter tests, social engineering, within the agreed scope.
Complete logging of all test actions, findings, and timestamps. Assessment by severity, exploitability, and regulatory relevance.
Complete report with all findings, recommendations, and CER mapping per Art. 13. Suitable as audit evidence for regulatory authorities and management.
CER focuses on physical resilience. These three modules cover the central requirements of the directive and deliver the evidence regulators expect.
Simulated break-in attempt at your facilities: tailgating, lock picking, perimeter tests. The core module for CER evidence: we test whether unauthorised access is possible.
Learn morePhishing, vishing, personal manipulation: most physical security gaps arise through the human factor. We show how far targeted deception goes.
Learn moreFor CER, the test alone is not enough: the evidence must also be documented and suitable for regulators. We deliver a structured final report as a complete audit document.
Learn more