Critical Entities Resilience (CER) Directive Compliance Services
Critical Entities Resilience (CER) Directive & Greek Law 5236/2025
The Critical Entities Resilience (CER) Directive (EU) 2022/2557 establishes a common European framework aimed at strengthening the resilience of organizations that provide essential services critical to society, public safety, economic activity and national security. The Directive requires organizations to identify, assess and manage risks that could disrupt essential services, implement resilience measures, establish business continuity capabilities and ensure effective incident response and recovery. It adopts an all-hazards approach, addressing risks arising from natural disasters, sabotage, terrorism, insider threats, public health emergencies, technological failures and other disruptive events.
In Greece, the Directive has been incorporated into national legislation through Law 5236/2025, which establishes the national framework for the protection and resilience of Critical Entities. The Law designates the General Secretariat for the Protection of Critical Entities as the competent national authority responsible for the implementation, supervision and enforcement of the CER framework.
Critical Entities
The Directive applies to organizations operating across eleven sectors critical to society and economy, including:
- Energy
- Transport
- Banking
- Financial Market Infrastructure
- Health
- Drinking Water
- Waste water
- Digital Infrastructure
- Public Administration
- Space
- Food Production, Processing and Distribution
Objective and Scope
The main objective of the CER framework is to ensure the uninterrupted delivery of essential services by helping organizations strengthen their resilience and preparedness against threats that may affect critical infrastructure. Through risk management, business continuity, crisis management and security measures organizations can secure their physical security, improve their ability to respond to disruptions, achieve compliance with regulatory requirements and enhance operational resilience.
The Greek legal framework focuses on:
- Identifying and designating Critical Entities.
- Developing a national resilience strategy for Critical Entities.
- Conducting national and organizational risk assessments.
- Enhancing preparedness, prevention, protection, response and recovery capabilities.
- Strengthening cooperation between public authorities and private-sector organizations.
- Establishing supervisory, compliance and enforcement mechanisms.
- Protecting essential services and critical infrastructure from physical and operational disruptions.
Our Services
We help organizations achieve compliance with the CER Directive and the Greek regulatory framework by providing comprehensive consulting services and end-to-end solutions that ensure operational resilience, security and readiness for physical threats.
CER Readiness Assessments & Gap Analysis
Evaluate the organization’s current level of compliance and identify areas requiring improvement.
Risk & Vulnerability Assessments
Identify threats, vulnerabilities and risks that may impact critical services and infrastructure.
Critical Service & Asset Identification
Determine the services, processes, assets and dependencies that are essential to business operations.
Business Impact Analysis (BIA)
Assess the operational, financial and reputational impact of potential disruptions.
Resilience Plan Development
Design and implement resilience plans to enhance preparedness, response and recovery capabilities.
Business Continuity Management (BCM)
Develop business continuity strategies and plans to ensure the uninterrupted delivery of essential services.
Crisis Management & Incident Response Planning
Establish frameworks and procedures for effective crisis response, incident management and recovery.
Physical Security & Critical Infrastructure Protection
Strengthen the protection of facilities, assets and critical infrastructure against physical threats.
Resilience Testing, Exercises & Training
Validate resilience capabilities through exercises, simulations and staff awareness programs.
Alignment with NIS2 & International Standards
Integrate CER requirements with frameworks such as NIS2 Directive, ISO 22301 (Business Continuity), ISO 31000 (Risk Management), ISO22361 (Crisis Management) and ISO 27001 (Information Security).
Through a practical and risk-based approach, we assist critical organizations to maintain continuous delivery of essential services by strengthening operational resilience, protecting critical infrastructure and ensuring compliance with CER directive.
