API 780 Second Edition is here, and an ISO 31000 tool can’t run it. We’ve built a proof of concept on the HawkSight platform. Before taking it into production, we want to hear from the people who run these assessments.
CER Risk Assessments: What the Law Actually Asks For
Under the CER Directive, a CER risk assessment is not a record of what you already have. It is an analysis of what could go wrong, why, and what it would do to your essential service.
Over the summer, competent authorities across the EU have been identifying the organisations they consider critical entities. For those organisations a clock is now running, and the first thing it counts down to is a risk assessment.
Most will produce one on time. The more useful question is whether it will meet the definition the Directive actually uses. That definition is more demanding than many people assume.
What CER is, and who it reaches
Directive (EU) 2022/2557, CER for short, obliges designated organisations to be resilient against all hazards. Not just cyber. Not just natural disasters. All of them.
The Directive defines resilience broadly. It means being able to prevent, protect against, respond to, resist, absorb and recover from incidents that disrupt an essential service.
It covers 11 sectors: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, food, digital infrastructure, public administration and space.
Organisations do not designate themselves. The national competent authority does it, based on three tests. The entity provides an essential service. It operates critical infrastructure in that Member State. And an incident would cause significant disruption.
Two points are worth getting right early. Article 8 identifies entities in banking, financial market infrastructure and digital infrastructure but exempts them from the substantive duties. Their resilience obligations sit mainly under DORA and NIS2. And CER does not apply in the UK, but it still reaches UK organisations through the EU operations they run, or as suppliers to EU critical entities.
When the CER risk assessment is due
The most common misreading I see is that the risk assessment was due on 17 July 2026. It was not. That was the date by which Member States had to identify their critical entities (Article 6(1)).
The authority then notifies each entity within a month, and the entity’s own clock starts on that date. From there:
| Duty | Due | Article |
|---|---|---|
| Risk assessment | Within 9 months of notification | 12(1) |
| Resilience measures, resilience plan, liaison officer | From 10 months after notification | 6(3), 13 |
| Incident notification (initial report within 24 hours) | From 10 months after notification | 6(3), 15 |
| Review of the risk assessment | Whenever necessary, and at least every 4 years | 12(1) |
Take an entity notified on the last possible date, 17 August 2026. Its risk assessment would be due by 17 May 2027, with resilience measures in place from 17 June 2027. Earlier notification brings both dates forward. National transposition laws can also vary the mechanics, so check the law in each Member State where you operate.
Notice how little time separates the two. Article 13(1) requires the resilience measures to rest on the risk assessment. So the assessment is not a box ticked in May. It is the foundation everything due in June is built on.
What the law means by a risk assessment
CER is precise about this. Article 2(7) defines a risk assessment as:
“the overall process for determining the nature and extent of a risk by identifying and analysing potential relevant threats, vulnerabilities and hazards which could lead to an incident and by evaluating the potential loss or disruption of the provision of an essential service caused by that incident”
Read it slowly and three things stand out. You must identify and analyse threats, vulnerabilities and hazards, not simply list them. You evaluate impact against one yardstick, the essential service. And the Directive defines risk as the magnitude of the loss or disruption combined with the likelihood of the incident.
Article 12 then sets out what the assessment must take into account:
- Inputs: the Member State risk assessment and other relevant sources of information.
- Scope: all relevant natural and man-made risks, including cross-sectoral and cross-border risks, accidents, natural disasters, public health emergencies, and hybrid threats and other antagonistic threats, including terrorist offences.
- Outward dependencies: how far other sectors depend on the essential service you provide.
- Inward dependencies: how far you depend on essential services from other sectors, including in neighbouring Member States and third countries.
It is worth being careful with language here. The articles name hybrid and antagonistic threats, including terrorism. Sabotage appears only in the recitals, and the word insider does not appear in the risk assessment articles at all. Insider risk enters through the employee security measures in Article 13(1)(e) and the background checks in Article 14. That is why a good assessment treats people as part of the threat and vulnerability picture, not as a separate HR matter.
Where assessments are likely to fall short
The good news is that existing work counts. Article 12(2) lets you reuse risk assessments and documents produced under other legal obligations. The competent authority may also declare an existing assessment compliant, in whole or in part.
That reuse carries a trap, though. Many organisations hold excellent business continuity plans, hazard registers, incident logs and control inventories. Those documents tend to be strong on natural hazards, accidents and dependencies. They are often much weaker on the two things the definition names first: threats and vulnerabilities.
An incident log tells you what has happened. It tells you very little about a capable, motivated adversary who has not yet acted. Nor does it reveal a hybrid campaign that blends cyber, physical and human activity. A control inventory tells you what exists. It does not tell you whether those controls would hold against the threats your site actually faces.
So the risk is not that organisations produce nothing. It is that they compile records and call the result a risk assessment. Then they build a resilience plan on a picture that never analysed the threat at all.
What a compliant CER risk assessment looks like
If you build the method from the definition outwards, the shape of a compliant assessment becomes fairly clear. In our own work we follow this sequence. It maps directly onto what Articles 2, 12 and 13 ask for.
First, build the picture
- Start with the essential service. Define what the entity delivers and the sites, systems, processes and people behind it. Set out what loss or disruption would actually look like. Map dependencies in both directions, including cross-border and third-country suppliers.
- Assess the threat. Use the Member State risk assessment as a formal input. Then add current intelligence: location-based crime data, open source reporting and the wider geopolitical and hybrid picture. For antagonistic threats, ask who could act against this specific service, and with what intent and capability. Assess natural hazards and accidents alongside them, on the same basis.
- Test vulnerabilities against those threats. A structured risk library of assets, threats and controls makes this repeatable. Physical, cyber and people vulnerabilities belong in one converged view, because that is how a capable adversary will look at you. The question is not whether a control exists. It is whether the control would stop the threats you have just identified, including where contractors’ staff have access.
Then evaluate, trace and review
- Evaluate the risk against the service. Score likelihood and the magnitude of disruption on a consistent, ISO 31000-aligned scale. That lets you compare and prioritise sites and assets across a whole portfolio.
- Trace every measure back to a risk. Link each resilience measure to a specific risk and to one of the six Article 13 areas: prevent, protect, respond, recover, employee security and awareness. That trail turns a resilience plan into evidence.
- Define your review triggers. At least every four years is the minimum. Set out what else counts as “whenever necessary”: a change in the threat picture, a change to the estate, an incident, or a revised Member State assessment.
- Make it readable at board level. CER places accountability on the entity. Show leadership where the exposure sits and why the measures are proportionate, in language they can act on.
Where technology fits
Technology helps a great deal with threat, vulnerability and risk evaluation, particularly across large portfolios. AI can take on much of the heavy lifting in gathering and structuring threat data. But judging what a threat means for a specific essential service still needs an experienced security professional. The law asks for analysis, and analysis is a human responsibility.
If you supply critical entities
CER places no direct duties on suppliers, but that does not mean suppliers are untouched. Critical entities must assess how far they depend on others (Article 12(2)), plan for alternative supply chains (Article 13(1)(d)), and manage the security of external service providers’ personnel (Article 13(1)(e)).
In practice, security providers, facilities contractors and specialist suppliers should expect questions. Clients will ask about continuity, access control, vetting and exercising, and add contract terms that pass those requirements down. You may not be designated, but you will very likely be asked for evidence.
The real test
The test of a CER risk assessment is not whether it exists by the deadline. It is whether you can trace every measure in your resilience plan back to a threat, a vulnerability or a hazard you actually analysed.
If your competent authority asked you tomorrow to show that trail, could you?
Source: Directive (EU) 2022/2557 on the resilience of critical entities, EUR-Lex. Article references are to the Directive; national transposition laws may vary the detail.
Martyn’s Law and Truro’s cancelled Bonfire Night: what it really tells us
Truro City Council has cancelled its Bonfire Night and fireworks display for the second year in a row, and Martyn’s Law sits at the centre of the decision.
With up to 5,000 people expected, the council treated the event as Enhanced Tier under Martyn’s Law. After a summer of planning around venue, road closures, ticketed entry and crowd management, it concluded it couldn’t stage the event safely within budget while keeping tickets affordable.
It’s a disappointing outcome for the community. I suspect it won’t be the last decision of its kind as councils and community groups plan their winter events.
So it’s worth slowing down and looking at what the law actually asks for, where the uncertainty sits, and how organisers can reach proportionate decisions rather than default ones.
Where Martyn’s Law stands today
The Terrorism (Protection of Premises) Act 2025 received Royal Assent in April 2025. It’s expected to come into force in spring 2027, with the Security Industry Authority (SIA) as regulator.
The Home Office published its statutory guidance in April 2026. The SIA has consulted on its own guidance covering how it will inspect and enforce, and the final version is still to come but rumoured to be this autumn.
Nobody is legally required to comply yet. The government is, however, encouraging organisers to prepare as if the law were already in force. That’s sensible advice, and it’s exactly what Truro tried to do.
Not every large event is in scope
This is the point I think gets lost most often. A crowd of 5,000 doesn’t automatically make an event a “qualifying event”.
For events not held at premises already in scope, two conditions matter. There must be a reasonable expectation of 800 or more people present at the same time. There must also be measures in place to check a condition of entry, such as a ticket, pass or payment. A suggested donation doesn’t count.
That creates a real tension. Organisers often introduce ticketed or controlled entry for good crowd safety reasons, to manage numbers and flow, and it’s also what can bring an event within the Act.
Organisers should understand that trade-off early and make the decision with their eyes open, rather than discover it halfway through planning.
What Martyn’s Law asks of enhanced tier events
Every in-scope premises and event needs public protection procedures: evacuation, invacuation, lockdown and communication. These cover what staff and volunteers do if an attack is happening or about to happen. Hotels are a good example of premises in scope, which I looked at in a recent post on hotel security risk.
Enhanced Tier premises and qualifying events go further. They need public protection measures, so far as reasonably practicable, to reduce both the vulnerability of the event and the risk of harm.
Where the responsible person is an organisation, it must appoint a designated senior individual. It must also prepare a document setting out its procedures and measures, including an assessment of how it expects those to reduce the risk.
One detail matters here. The statutory guidance is explicit that the Act assumes an attack could happen anywhere, so the requirements aren’t tied to how likely an attack is at a particular site.
That’s a different starting point from a traditional threat-led security risk assessment. The question is closer to this: if something happened here, how vulnerable would we be, and what reasonable steps would reduce the harm?
The threats Martyn’s Law is designed around
Martyn’s Law is specifically about terrorism, and it helps to be precise about the attack methods it targets. Recent history gives clear examples.
Vehicle as a weapon. In Nice in July 2016, an attacker drove a lorry through crowds on the Promenade des Anglais on Bastille Day. An attacker struck the Berlin Christmas market the same way that December. For outdoor events with road access, this is often the first vulnerability to consider.
Person-borne improvised explosive device. At Manchester Arena in May 2017, the attacker detonated his device in the foyer outside the ticketed area as the audience was leaving. Twenty-two people were killed, including Martyn Hett.
Marauding attacks with firearms or bladed weapons. Examples include the Bataclan in Paris in 2015, and London Bridge and Borough Market in 2017, where a knife attack followed a vehicle attack.
Hostile reconnaissance sits underneath all of these. Attackers plan, and visible, well-run security is a deterrent in its own right.
It does show how exposed a dense, celebrating crowd is to a vehicle, whatever the motive. Good event planning will address that regardless of what the law requires.
NPSA and ProtectUK already publish a great deal of free guidance on these threats, including hostile vehicle mitigation. I’d expect that material to sit closely alongside the SIA’s regulatory guidance.
The cost question
This is where Truro’s story will generate the most debate. The Home Office’s position is that compliance should be proportionate. Its impact assessment put average annual costs for the enhanced tier at around £5,200, mostly staff time rather than physical upgrades.
Many security professionals, me included, will find that difficult to square with an open-air event for thousands of people. That’s particularly true if the chosen answer involves vehicle mitigation, search regimes, extra stewarding and road closures.
But the Act doesn’t require every possible measure. It requires what is reasonably practicable, which the guidance equates with proportionate.
The risk is that, without clear examples of what proportionate looks like for a community event, organisers price in the maximum and conclude the event can’t happen.
The answer to that is evidence. You can’t protect what you don’t understand, and you can’t defend a decision you haven’t recorded.
An organiser who can show how they assessed their vulnerabilities, which measures they chose, which they considered and set aside, and why, is in a far stronger position than one who either gold-plates everything or does nothing.
Where support can help
Until the SIA publishes its final guidance, we’re all in something of a holding pattern on the detail. Anyone responsible for an event should watch for it and engage with it.
In the meantime, the people carrying this responsibility are often council officers and volunteers rather than security professionals. What they need is a simple, structured way to work through their vulnerabilities, set them against the current threat level and their local context, and record the reasoning behind the measures they choose.
That’s an area we’ve been exploring at HawkSight. That work includes how organisers could tailor templated procedures for evacuation, invacuation, lockdown, communication and crowd management to an event, rather than writing them from scratch.
It won’t replace the SIA’s guidance, or professional judgement where an event is genuinely complex. It could take a lot of the blank-page anxiety out of the process.
Keeping sight of why this matters
Figen Murray has spent years campaigning so that other families don’t go through what hers did. The law named after her son deserves to be taken seriously, and it deserves to work.
A community losing its Bonfire Night isn’t the outcome anyone wants.
If you’re with the SIA, NPSA, a local authority or an events team and I’ve got any of this wrong, or you can see how the final guidance will address it, I’d welcome the correction.
And if you’re planning an event now, what would help you most in reaching a proportionate answer?
Sources
- Truro City Council, Statement on 2026 Bonfire Night and Fireworks Display: https://truro.gov.uk/press-release/statement-on-2026-bonfire-night-and-fireworks-display/
- Home Office, Terrorism (Protection of Premises) Act 2025 statutory guidance: https://www.gov.uk/government/publications/the-terrorism-protection-of-premises-act-2025/terrorism-protection-of-premises-act-2025-statutory-guidance
- Terrorism (Protection of Premises) Act 2025: https://www.legislation.gov.uk/ukpga/2025/10/enacted
- ProtectUK, Martyn’s Law frequently asked questions: https://www.protectuk.police.uk/martyns-law/martyns-law-frequently-asked-questions



