The CER Directive (EU) 2022/2557, which replaced the Critical Infrastructure Directive 2008/114/EC, redefines what the European Union expects from operators of essential services across eleven sectors: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, public administration, space and food. Where its predecessor focused narrowly on identifying European Critical Infrastructures, CER introduces binding resilience obligations covering physical security, personnel vetting, risk assessment, incident reporting and business continuity. For organisations that also hold sensitive data, the practical question is whether a single infrastructure architecture can satisfy CER’s physical demands together with the digital requirements of NIS-2 Directive (EU) 2022/2555 and DORA Regulation (EU) 2022/2554, without creating the foreign-jurisdiction exposure that public cloud creates.
Which entities fall under both CER and NIS-2, and why the overlap matters
CER and NIS-2 are explicitly designed to work as a pair: entities designated as critical under CER in sectors such as energy, transport, health and digital infrastructure are treated as essential entities under NIS-2 by virtue of Article 9 of NIS-2, which instructs Member States to make that mapping automatic. This means a hospital system designated as a critical entity faces both the physical resilience plan required by CER Article 13 and the cybersecurity risk-management measures required by NIS-2 Article 21, simultaneously and without the ability to satisfy one and defer the other.
The significance of this dual designation is that neither framework is reducible to the other. CER addresses the physical integrity of infrastructure: perimeter access, supply-chain security, staff vetting, continuity of physical operations. NIS-2 addresses network and information system security: incident detection, patch management, cryptographic controls, multi-factor authentication. An organisation that achieves strong logical security while relying on a US-hyperscaler for its core processing has satisfied some NIS-2 obligations but has simultaneously created a CER-relevant supply-chain dependency that could be exploited to disrupt critical services through foreign legal compulsion, specifically via the US CLOUD Act or FISA Section 702, which allow US authorities to compel disclosure of data held by US-controlled providers regardless of where the data physically resides.
Sovereign on-premises infrastructure, governed exclusively by the law of the Member State in which it operates, closes this gap. Physical access is controlled by domestic personnel subject to domestic law. The network stack is operated under domestic licensing. There is no contractual relationship that a foreign government can activate to redirect, intercept or suspend service.
Physical security, personnel vetting and background-check obligations under CER
CER Article 13 requires critical entities to implement measures that prevent, protect against, respond to, recover from and mitigate incidents affecting physical infrastructure. Article 14 specifically addresses the security of personnel, requiring that persons holding roles with access to critical infrastructure or sensitive operational information be subject to background checks proportionate to the sensitivity of the role.
Those background checks must include, at a minimum, verification of identity and, subject to national law, checks against criminal records. Member States may permit or require deeper security vetting for roles with access to particularly sensitive systems. For operators of sovereign data centres that host critical-entity workloads, this translates into documented vetting procedures for data-centre technicians, network engineers, security operations centre analysts and any contractor with physical access to server rooms. The resilience plan required under Article 12 must describe how personnel security is implemented and reviewed.
Physical security measures specifically relevant to data-centre and network infrastructure include: perimeter protection with access logging, CCTV coverage meeting national retention requirements, segmented access zones preventing any single individual from reaching both physical and logical control systems, and environmental controls (fire suppression, power redundancy) documented as resilience measures rather than merely as good practice.
How CER Article 5 risk assessments interface with sovereignty risk assessments
CER Article 5 requires each Member State to carry out a national risk assessment covering natural hazards, man-made incidents, accidental causes and hostile state or non-state actors, updated at least every four years. Designated critical entities must then carry out their own entity-level risk assessment under Article 12, taking the national assessment as a reference point.
Sovereignty risk assessments, conducted under GDPR Article 35 (Data Protection Impact Assessment) or as part of a broader data governance review, examine a related but distinct set of threats: foreign-jurisdiction access, third-country transfer mechanisms, contractual clauses that could be overridden by extraterritorial law, and the adequacy of technical measures to resist compelled disclosure. The evidence produced by both types of assessment overlaps substantially. A jurisdiction-mapping exercise that documents which legal systems govern each component of an infrastructure stack is directly relevant to both the CER entity-level risk assessment (supply-chain risk) and the GDPR DPIA (transfer risk). A supplier audit that identifies whether a managed-service provider is ultimately controlled by a non-EU parent company serves both assessments simultaneously.
Sovereign infrastructure operators can present competent authorities under CER with a unified risk register that maps each identified risk to its CER Article 12 classification and, where relevant, to the GDPR or national data-protection framework. This avoids the duplication of producing separate evidence bodies for separate supervisory authorities and demonstrates to both that the organisation has a coherent, integrated understanding of its threat landscape.
Incident reporting timelines and cross-border coordination
CER Article 15 requires critical entities to notify their designated competent authority without undue delay after becoming aware of an incident that significantly disrupts, or has the potential to significantly disrupt, the provision of essential services. The directive does not prescribe a fixed-hour deadline, which contrasts with NIS-2’s structured timeline: an early warning within 24 hours of awareness, a full incident notification within 72 hours and a final report within one month.
For entities subject to both regimes, the NIS-2 timeline functions as the operative clock. A reporting pipeline that triggers the 24-hour NIS-2 early warning automatically satisfies the “without undue delay” requirement of CER Article 15, provided the competent authority under CER receives the notification in parallel or immediately after. Organisations should map their incident classification procedures to both frameworks at the point of initial alert triage: if an incident affects availability of an essential service, it activates CER reporting; if it involves a network or information system, it activates NIS-2 reporting; in most critical-entity scenarios, both are triggered simultaneously.
For cross-border incidents affecting critical entities in more than one Member State, CER Article 9 establishes a coordination mechanism through the Critical Entities Resilience Group, while NIS-2 coordinates at the cyber level through EU-CyCLONe (European Cyber Crises Liaison Organisation Network), the body that links national cyber crisis management authorities during large-scale incidents. Sovereign infrastructure operators whose services cross borders should pre-register their key contacts with both mechanisms and include cross-border notification procedures in their resilience plans.
Aligning CER resilience plans with DORA and NIS-2 in a single sovereign architecture
The three frameworks impose overlapping but distinct planning requirements. CER Article 12 requires a resilience plan covering prevention, protection, response, recovery and mitigation. DORA Regulation (EU) 2022/2554 Article 11 requires financial entities to maintain ICT business-continuity plans with defined recovery time objectives (RTOs) and recovery point objectives (RPOs). NIS-2 Article 21 requires documented business continuity management, backup management and crisis management as part of the mandatory cybersecurity risk-management baseline.
| Framework | Planning instrument | Key content requirements | Testing obligation |
|---|---|---|---|
| CER (EU) 2022/2557 | Resilience plan (Art. 12) | Physical threats, personnel security, supply chain, cross-sector dependencies | Regular review; Member State may require exercises |
| NIS-2 (EU) 2022/2555 | BCM within cybersecurity risk management (Art. 21) | Backup, disaster recovery, crisis management, multi-factor authentication, encryption | Implied by risk-management review cycle |
| DORA (EU) 2022/2554 | ICT business continuity plan (Art. 11) and recovery plan (Art. 17) | RTO/RPO, communication procedures, alternative processing capacity, post-incident review | Annual testing; TLPT for significant entities |
A sovereign on-premises architecture satisfies all three simultaneously when it is designed around three principles. First, physical and logical controls must be co-documented: the same facility that houses servers must have documented access controls, CCTV retention schedules and personnel vetting records that appear in the CER resilience plan and are cross-referenced in the NIS-2 risk register. Second, backup and recovery infrastructure must be geographically separated, domestically governed and capable of meeting the RTOs and RPOs specified in the DORA plan, which for systemically important financial entities can be as tight as two hours for critical functions. Third, the entire evidence base, including audit logs, access records, incident timelines and test results, must be stored in a way that is accessible to domestic competent authorities and inaccessible to foreign legal process.
According to the IBM Cost of a Data Breach Report 2023, the average total cost of a data breach reached USD 4.45 million, the highest in the eighteen-year history of that report. ENISA’s Threat Landscape 2023 found that over 40 percent of surveyed critical infrastructure organisations reported a significant cybersecurity incident in 2022. These figures make the cost-benefit calculation for sovereign infrastructure investment concrete: the capital expenditure of a dedicated on-premises or co-location arrangement in a jurisdiction without extraterritorial access obligations is measurable and bounded, while breach costs are open-ended and carry regulatory penalties on top.
The ENISA Critical Sectors Cybersecurity Handbook notes that “the security of network and information systems, and the physical security of those systems, are increasingly intertwined,” and calls for a holistic approach. CER Directive (EU) 2022/2557 Article 13(1) states directly that “critical entities must implement technical and organisational measures to ensure their resilience, including measures to prevent, protect against, respond to, recover from and mitigate the effects of incidents.” Taken together, these positions establish that physical and digital resilience are not separable disciplines managed by different teams with different documentation. They are one discipline, and sovereign infrastructure is the architecture that makes unified governance of both practically achievable.
Frequently asked questions
Does every entity designated as ‘critical’ under CER Directive (EU) 2022/2557 automatically qualify as an ‘essential entity’ under NIS-2?
Not automatically by label alone, but Article 9 of NIS-2 explicitly requires Member States to ensure that entities identified as critical under CER are treated as essential entities under NIS-2. In practice, the eleven sectors covered by CER map directly onto NIS-2’s essential-entity sectors, so dual designation is the norm rather than the exception.
What background-check obligations does the CER Directive impose on staff with access to sovereign infrastructure?
Article 14 of CER Directive (EU) 2022/2557 requires critical entities to carry out background checks on persons in sensitive roles, including identity verification and, where national law permits, criminal-record checks and security vetting. The depth of vetting must be proportionate to the sensitivity of the role and documented within the resilience plan.
How does the CER Article 5 national risk assessment relate to a GDPR Data Protection Impact Assessment?
They address overlapping but distinct threat categories. The CER national risk assessment covers physical, environmental and hybrid threats to essential services; the GDPR DPIA focuses on risks to personal data including third-country transfer and foreign-jurisdiction access. Evidence gathered for one, particularly jurisdiction mapping and supplier audits, is directly reusable in the other, reducing duplication when presented to competent authorities.
What are the incident reporting deadlines under CER compared with NIS-2, and how should operators handle both?
NIS-2 sets fixed deadlines: early warning within 24 hours, full notification within 72 hours and a final report within one month. CER Article 15 requires notification “without undue delay,” with no fixed-hour limit. Operators should treat the NIS-2 timeline as the operative clock and route the same incident record to both competent authorities within that window, clearly labelling each notification with the relevant directive.
Can a single sovereign infrastructure architecture genuinely satisfy CER, NIS-2 and DORA in one design?
Yes. The conditions are unified documentation that maps each physical and logical control to the specific article it satisfies in each framework; geographically separated, domestically governed backup and recovery capacity meeting DORA RTO and RPO obligations; and an audit log that is accessible only to domestic authorities. A single resilience plan that cross-references CER Article 12, NIS-2 Article 21 and DORA Articles 11 and 17 is both legally defensible and operationally coherent.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
