Blog header + LinkedIn link (1200×628)@1x

CER Risk Assessments: What the Law Actually Asks For

Under the CER Directive, a CER risk assessment is not a record of what you already have. It is an analysis of what could go wrong, why, and what it would do to your essential service.

Over the summer, competent authorities across the EU have been identifying the organisations they consider critical entities. For those organisations a clock is now running, and the first thing it counts down to is a risk assessment.

Most will produce one on time. The more useful question is whether it will meet the definition the Directive actually uses. That definition is more demanding than many people assume.

What CER is, and who it reaches

Directive (EU) 2022/2557, CER for short, obliges designated organisations to be resilient against all hazards. Not just cyber. Not just natural disasters. All of them.

The Directive defines resilience broadly. It means being able to prevent, protect against, respond to, resist, absorb and recover from incidents that disrupt an essential service.

It covers 11 sectors: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, food, digital infrastructure, public administration and space.

Organisations do not designate themselves. The national competent authority does it, based on three tests. The entity provides an essential service. It operates critical infrastructure in that Member State. And an incident would cause significant disruption.

Two points are worth getting right early. Article 8 identifies entities in banking, financial market infrastructure and digital infrastructure but exempts them from the substantive duties. Their resilience obligations sit mainly under DORA and NIS2. And CER does not apply in the UK, but it still reaches UK organisations through the EU operations they run, or as suppliers to EU critical entities.

When the CER risk assessment is due

The most common misreading I see is that the risk assessment was due on 17 July 2026. It was not. That was the date by which Member States had to identify their critical entities (Article 6(1)).

The authority then notifies each entity within a month, and the entity’s own clock starts on that date. From there:

DutyDueArticle
Risk assessmentWithin 9 months of notification12(1)
Resilience measures, resilience plan, liaison officerFrom 10 months after notification6(3), 13
Incident notification (initial report within 24 hours)From 10 months after notification6(3), 15
Review of the risk assessmentWhenever necessary, and at least every 4 years12(1)

Take an entity notified on the last possible date, 17 August 2026. Its risk assessment would be due by 17 May 2027, with resilience measures in place from 17 June 2027. Earlier notification brings both dates forward. National transposition laws can also vary the mechanics, so check the law in each Member State where you operate.

Notice how little time separates the two. Article 13(1) requires the resilience measures to rest on the risk assessment. So the assessment is not a box ticked in May. It is the foundation everything due in June is built on.

What the law means by a risk assessment

CER is precise about this. Article 2(7) defines a risk assessment as:

“the overall process for determining the nature and extent of a risk by identifying and analysing potential relevant threats, vulnerabilities and hazards which could lead to an incident and by evaluating the potential loss or disruption of the provision of an essential service caused by that incident”

Read it slowly and three things stand out. You must identify and analyse threats, vulnerabilities and hazards, not simply list them. You evaluate impact against one yardstick, the essential service. And the Directive defines risk as the magnitude of the loss or disruption combined with the likelihood of the incident.

Article 12 then sets out what the assessment must take into account:

  • Inputs: the Member State risk assessment and other relevant sources of information.
  • Scope: all relevant natural and man-made risks, including cross-sectoral and cross-border risks, accidents, natural disasters, public health emergencies, and hybrid threats and other antagonistic threats, including terrorist offences.
  • Outward dependencies: how far other sectors depend on the essential service you provide.
  • Inward dependencies: how far you depend on essential services from other sectors, including in neighbouring Member States and third countries.

It is worth being careful with language here. The articles name hybrid and antagonistic threats, including terrorism. Sabotage appears only in the recitals, and the word insider does not appear in the risk assessment articles at all. Insider risk enters through the employee security measures in Article 13(1)(e) and the background checks in Article 14. That is why a good assessment treats people as part of the threat and vulnerability picture, not as a separate HR matter.

Where assessments are likely to fall short

The good news is that existing work counts. Article 12(2) lets you reuse risk assessments and documents produced under other legal obligations. The competent authority may also declare an existing assessment compliant, in whole or in part.

That reuse carries a trap, though. Many organisations hold excellent business continuity plans, hazard registers, incident logs and control inventories. Those documents tend to be strong on natural hazards, accidents and dependencies. They are often much weaker on the two things the definition names first: threats and vulnerabilities.

An incident log tells you what has happened. It tells you very little about a capable, motivated adversary who has not yet acted. Nor does it reveal a hybrid campaign that blends cyber, physical and human activity. A control inventory tells you what exists. It does not tell you whether those controls would hold against the threats your site actually faces.

So the risk is not that organisations produce nothing. It is that they compile records and call the result a risk assessment. Then they build a resilience plan on a picture that never analysed the threat at all.

What a compliant CER risk assessment looks like

If you build the method from the definition outwards, the shape of a compliant assessment becomes fairly clear. In our own work we follow this sequence. It maps directly onto what Articles 2, 12 and 13 ask for.

First, build the picture

  • Start with the essential service. Define what the entity delivers and the sites, systems, processes and people behind it. Set out what loss or disruption would actually look like. Map dependencies in both directions, including cross-border and third-country suppliers.
  • Assess the threat. Use the Member State risk assessment as a formal input. Then add current intelligence: location-based crime data, open source reporting and the wider geopolitical and hybrid picture. For antagonistic threats, ask who could act against this specific service, and with what intent and capability. Assess natural hazards and accidents alongside them, on the same basis.
  • Test vulnerabilities against those threats. A structured risk library of assets, threats and controls makes this repeatable. Physical, cyber and people vulnerabilities belong in one converged view, because that is how a capable adversary will look at you. The question is not whether a control exists. It is whether the control would stop the threats you have just identified, including where contractors’ staff have access.

Then evaluate, trace and review

  • Evaluate the risk against the service. Score likelihood and the magnitude of disruption on a consistent, ISO 31000-aligned scale. That lets you compare and prioritise sites and assets across a whole portfolio.
  • Trace every measure back to a risk. Link each resilience measure to a specific risk and to one of the six Article 13 areas: prevent, protect, respond, recover, employee security and awareness. That trail turns a resilience plan into evidence.
  • Define your review triggers. At least every four years is the minimum. Set out what else counts as “whenever necessary”: a change in the threat picture, a change to the estate, an incident, or a revised Member State assessment.
  • Make it readable at board level. CER places accountability on the entity. Show leadership where the exposure sits and why the measures are proportionate, in language they can act on.

Where technology fits

Technology helps a great deal with threat, vulnerability and risk evaluation, particularly across large portfolios. AI can take on much of the heavy lifting in gathering and structuring threat data. But judging what a threat means for a specific essential service still needs an experienced security professional. The law asks for analysis, and analysis is a human responsibility.

If you supply critical entities

CER places no direct duties on suppliers, but that does not mean suppliers are untouched. Critical entities must assess how far they depend on others (Article 12(2)), plan for alternative supply chains (Article 13(1)(d)), and manage the security of external service providers’ personnel (Article 13(1)(e)).

In practice, security providers, facilities contractors and specialist suppliers should expect questions. Clients will ask about continuity, access control, vetting and exercising, and add contract terms that pass those requirements down. You may not be designated, but you will very likely be asked for evidence.

The real test

The test of a CER risk assessment is not whether it exists by the deadline. It is whether you can trace every measure in your resilience plan back to a threat, a vulnerability or a hazard you actually analysed.

If your competent authority asked you tomorrow to show that trail, could you?


Source: Directive (EU) 2022/2557 on the resilience of critical entities, EUR-Lex. Article references are to the Directive; national transposition laws may vary the detail.

hybrid-conflict-blog-hero

War, crime or terrorism? Hostile state acts need a name, and a plan

When a hostile state acts on British soil, is it war, crime or terrorism? How we answer shapes how we prepare.

In the early hours of Sunday morning, police received a report of three suspicious vehicles heading towards RAF Fairford. One local resident has described finding the road blocked by three vans and a group of hooded, masked men, who ran when they saw her. Five men were arrested, first on suspicion of explosives offences and then on suspicion of preparing a terrorist act. Police evacuated around 85 households while Army bomb disposal teams examined the vehicles.

Fairford isn’t just any airfield. It hosts US heavy bombers, and the US has flown operations against Iran from it since February. In July, Iran’s Revolutionary Guard publicly warned Britain that any base used against Iranian territory was a legitimate target. ITV News reports that one line of inquiry is whether representatives of the Iranian regime paid others to carry out the plot on their behalf. At the time of writing, no connection has been confirmed. The five men remain in custody, and it’s right that we let investigators establish the facts.

But whatever they find, the incident exposes a problem I’ve been thinking about for some time. Judging by the discussion on my recent posts, it clearly resonates with many of you.

An academic argument with practical consequences

When I argued that we are, in effect, at war with states using hybrid methods against the UK, people rightly challenged me on the word “war”. War has a legal meaning, and using it loosely carries real risk, not least the risk of escalation with nuclear-armed states.

So let me come at it from a different direction.

What is the difference between a state-sponsored terrorist act and an act of war? The objective is often identical: to coerce another country into changing its behaviour. Clausewitz described war as the continuation of policy by other means, and a proxy with a van full of explosives is simply another means.

The real difference isn’t the implement. It’s the rulebook each one triggers.

An act of war falls under the laws of armed conflict and can justify a state-level response. We treat an act of terrorism as a crime, for the police and the courts to handle. The first can reach the state that ordered it. The second, in practice, reaches the people caught holding the tools.

That distinction can look academic, but it decides who can respond, and how.

Choosing the box you land in

Hostile states understand this better than we do. If you want to pressure the UK without paying a state-level price, you don’t send your own forces. You recruit criminals or sympathisers, often online and often for modest sums, and you make sure the act looks like arson, vandalism or terrorism. Once it lands in the criminal box, police arrest the proxy, the courts prosecute them, and the state that directed it pays nothing.

We’ve already seen this pattern. In 2025, men recruited on behalf of Russia’s Wagner Group were convicted over an arson attack on a London warehouse storing equipment bound for Ukraine. The organisers were the first people convicted under the National Security Act 2023. MI5’s Director General has said publicly that Iran, like the Russian services, makes extensive use of criminals as proxies. In 2025 he reported more than twenty potentially lethal Iran-backed plots in a single year. Different states, same method.

Put simply, we’ve built a system for catching the hand, not the head.

The National Security Act 2023 was a genuine step forward, creating offences for foreign-directed sabotage and interference. But it still works at the level of the individual. It punishes the proxy more effectively without changing the calculation for the state behind them.

A third category

This is where Kenneth Smart’s challenge changed my thinking. Framing these acts as war, within the current framework, does risk rapid escalation, and that’s a serious concern. But the answer can’t be to fall back on treating them as ordinary crime when a state is clearly directing them.

I think we need a third category: hostile state acts below the threshold of armed conflict, with rules of their own.

We already have the tools. Diplomatic expulsions, targeted sanctions, asset freezes, proportionate cyber operations and, under international law, lawful countermeasures against a state that has committed a wrongful act. What we lack is a framework that says when we’ll use them.

We already do this for threats we have defined. When the national terrorism threat level changes, nobody improvises. The government publishes the level, and organisations plan the protective measures that follow it in advance. Hostile state acts deserve the same treatment. Whatever we choose to call them, they need to become policy, with responses agreed before the next incident rather than after it.

Salisbury in 2018 shows it can be done. The government attributed the attack to Russia on a “highly likely” intelligence assessment, rather than waiting for a conviction. It then responded at state level alongside its allies. The problem is that the government built the response after the fact, and ad hoc responses deter very little.

A framework for hostile state acts

A proper framework would do three things.

First, define what a hostile state act is, so that incidents are assessed as part of a campaign rather than one at a time.

Second, set a published standard for attribution: a high-confidence assessment rather than proof beyond reasonable doubt. It should run alongside any criminal investigation instead of waiting for it.

Third, declare the kinds of proportionate, graduated response a state can expect when that threshold is met.

The honest counterargument is that publishing a threshold tells an adversary exactly where to stop. That’s a real risk. But I’d argue the current position is worse. Right now there is no threshold at all, and the fog of uncertainty is doing our adversaries’ work for them.

Why this matters beyond defence

Businesses are already on this battlefield. Critical infrastructure, defence supply chains and the companies around them are obvious targets, but anyone whose disruption creates pressure is in scope. Organisations can’t plan properly against a threat their own government hasn’t defined. A clear national framework would give security leaders something concrete to assess risk against and to explain to their boards. It is the same need for clear definitions that sits behind Martyn’s Law for terrorism at public venues.

I don’t claim to have all the answers, and I’d genuinely welcome challenge. Is a third category the right approach? And if it is, where would you set the threshold?


A note of thanks

I’d like to thank everyone who took the time to respond to my recent posts on this subject. The volume and quality of the discussion made it clear this is something that matters to many of us working in security, defence and resilience.

In particular, I’d like to thank Kenneth Smart. His thoughtful academic input on the challenges of framing these acts as war made me think harder about the problem. His challenge is a large part of why this piece explores a third category of conflict, rather than simply arguing that we are at war.

A note on how this was written

These are my own views, shaped by that discussion. I used AI to help research and draft this piece. Mainly, that let me get it out while the conversation is still live and people are still engaged with it. It has also helped me organise my thinking and put it across more clearly. The arguments, and any errors, are mine.