Threat feed liveUpdated — 30.07.2026 12:36 CET58 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 30.07.2026 12:36 CET58 dossiersMITRE ATT&CK mapping

Regulatory explainer — no hostile actormedium

The CER Directive: Italy has its list of critical entities, and now the clock starts

While all the attention goes to NIS2, its less-discussed twin has entered the phase that counts. The CER Directive on the resilience of critical entities, transposed in Italy by Legislative Decree 134/2024, requires member states to identify their critical entities and notify them: from that moment a countdown of months begins for the risk assessment and the resilience plan. The difference from NIS2 comes down to one word: here physical risk and cyber risk live in the same document. An explainer on what changes, for whom, and by when.

The directive nobody talks about

If you have followed European compliance over the past two years, you have heard about NIS2 to the point of exhaustion. Far less about the CER Directive, Critical Entities Resilience, Directive (EU) 2022/2557. And yet the two were born together, on the same day, as two halves of the same argument: NIS2 deals with the cybersecurity of important and essential entities, CER with their overall resilience — the ability to keep delivering an essential service whatever happens, be it a cyberattack, sabotage, a flood, an accident or a health emergency.

It is a shift of perspective with precise practical consequences. A NIS2 plan talks about vulnerability management, access control, systems continuity. A CER plan also talks about fences, personnel screening, site redundancy, dependence on physical suppliers. Cyber risk does not disappear: it moves into a bigger document, alongside everything else.

What it says, in three lines

The directive establishes harmonised rules to ensure the provision of essential services in the internal market, increase the resilience of critical entities and improve cross-border cooperation between competent authorities. Italy transposed it with Legislative Decree No. 134 of 4 September 2024, published in the Official Journal on 23 September 2024.

  1. 01
    The state
    assesses risks, adopts a national strategy, identifies critical entities
  2. 02
    The notification
    the identified entity is informed of its status and its duties
  3. 03
    The entity
    assesses its own risks, adopts a resilience plan, reports incidents

The sectors covered are the ones where disruption is felt immediately: energy (electricity, gas, oil, district heating, hydrogen), transport (road, rail, air, waterborne), health, drinking water and waste water, digital infrastructure, banking and financial markets, space, production, processing and distribution of food, plus public administration.

The countdown

This is why CER is back on the agenda right now. The path has two stages: first the state does its work, then the companies begin theirs.

  1. 17 January 2026
    Identification of critical entities

    Sector authorities identify them for their respective sectors.

  2. 17 July 2026
    Adoption of the national list

    The directive's deadline for identification by member states.

  3. Within one month of identification
    Notification to the entities

    The entity officially learns it is critical.

  4. From notification
    The clock starts

    Risk assessment and resilience plan within the statutory deadlines.

The operational point to hold on to is that the countdown does not start when the decree is published, but at the individual notification. A company that has received nothing is not late; a company that has been notified has a counted number of months ahead — in the order of nine to ten, depending on the obligation — to produce a documented risk assessment and a working resilience plan. Those deadlines look generous until you try to genuinely map the critical dependencies of a plant.

A caveat on the dates. The deadlines above combine the European directive's calendar with the Italian implementation schedule; the exact timing of individual notifications depends on the competent sector authorities and can vary from sector to sector. Anyone planning should refer to their own sector authority and to the text of Decree 134/2024, not to a summary table — including this one.

The duties, concretely

The core of what a critical entity must do comes down to four items.

1
risk assessment
physical and cyber, natural, accidental and intentional
2
resilience plan
measures to prevent, resist, mitigate and recover
3
incident reporting
when there is significant impact on essential services
4
personnel screening
for sensitive roles, within the limits set by law

The risk assessment must consider all relevant threats — natural, accidental, intentional — and not only cyber ones: this is where CER differs most from NIS2. The resilience plan is the document that turns that assessment into concrete measures: prevent, protect, respond, recover. Incident reporting covers events that significantly disrupt the provision of the essential service. Personnel screening is the least palatable novelty for many organisations, and must be applied within the limits and safeguards national law provides.

Why it is good news, if taken well

There is a lazy reading of every new compliance duty: another document to produce. There is a more useful reading, though, and it is that CER forces something almost nobody does spontaneously — putting the people responsible for physical security and the people responsible for cybersecurity at the same table. In most organisations these are two functions that do not talk to each other, with separate budgets and two risk maps that never overlap. A credible resilience plan cannot be written without sitting them down together.

And that is exactly where this explainer meets the daily news: an equipment failure and a management console exposed to the internet can produce the same outcome — an essential service that stops. CER is the rule that asks you to see them as a single problem. It is a regulatory explainer, not the attack of the day; but it is the frame within which, for many Italian entities, the coming months will mean real work.

More dossiers