At a glance

Date: 15 Jul 2026
Author: Eoliann
Reading time: 8 min
Insights

CER Directive 2026: from compliance to climate risk forecasting

The CER Directive introduces a new approach to the resilience of critical entities, requiring them to assess and manage the risks that may compromise the continuity of essential services.

Directive (EU) 2022/2557, transposed in Italy through Legislative Decree 134/2024, enters a decisive phase in 2026 with the identification of critical entities and the start of operational obligations.

For organizations, demonstrating regulatory compliance is no longer enough.

It becomes necessary to understand how natural events, climate change and other risk factors may affect infrastructure and essential services.

In this article, we analyze what the legislation provides and what implications it has for energy, transport and telecommunications infrastructure.

CER Directive: what it is and why 2026 is a decisive year

The CER Directive (Critical Entities Resilience), namely Directive (EU) 2022/2557, is the European legislation that strengthens the resilience of critical entities responsible for guaranteeing essential services.

The objective is to improve their ability to prevent, withstand, respond to and recover from events that could compromise their operation.

The Directive moves beyond the previous concept of critical infrastructure and introduces the broader concept of a critical entity, including organizations that provide essential services for the functioning of society and the economy.

In Italy, the legislation was transposed through Legislative Decree 134/2024, which defines the national implementation process for the resilience of critical entities.

2026 marks the start of the operational phase of the CER Directive. The main deadlines are:

  • 17 January 2026 – identification of entities considered critical according to the criteria established by the legislation.
  • 17 July 2026 – adoption of the national list of critical entities and subsequent notification to the entities included.

This process is part of the first “National strategy for the resilience of critical entities”, provided for by the transposing decree and aimed at strengthening the country’s ability to address natural, technological and other risks.

What obligations does compliance with the CER Directive entail?

Key obligations at a glance

  1. Assess risks that may interrupt essential services.
  2. Identify critical assets, functions and interdependencies.
  3. Adopt proportionate technical and organizational measures.
  4. Prepare and update the resilience plan.
  5. Manage and notify significant incidents.

Main obligations for critical entities

An entity is identified as a critical entity when it provides one or more essential services, operates through infrastructure located in the national territory and an interruption of its activities could produce significant negative effects for the community or the economic system.

The definition is contained in Article 2, paragraph 1, point (a), of Legislative Decree 134/2024: “‘critical entity’ means a public or private entity identified, pursuant to Article 8, among the categories of entities operating in the sectors and subsectors referred to in Annex A, which forms an integral part of this Decree”.

For these entities, the CER Directive introduces a set of obligations that go beyond simple documentary compliance.

Each organization must:

  • Carry out a risk assessment covering risks that may compromise the continuity of essential services.
  • Consider natural risks, human-made events, interdependencies and cascading effects.
  • Identify the assets and infrastructure essential to the provision of the service.
  • Adopt technical, organizational and security measures proportionate to the risks identified.
  • Provide for prevention, protection, response and recovery measures.
  • Integrate climate change adaptation measures.
  • Prepare and update a resilience plan.
  • Appoint a responsible contact person.
  • Notify significant incidents according to the established procedures.

Compliance with the CER Directive does not coincide with the production of documents. Risk assessment must translate into concrete interventions, proportionate to the level of exposure and aimed at guaranteeing the continuity of essential services.

What the CER Directive means for energy, transport and telecommunications

The CER Directive adopts an all-hazards approach, which also includes natural events and climate change.

Resilience does not concern only physical or cyber security, but also the ability of infrastructure to continue operating during events such as floods, wildfires, heatwaves, landslides or extreme weather events.

Energy

In the energy sector, the assessment concerns production plants, substations, power lines and distribution networks.

The CER Directive requires organizations to identify the assets most exposed to phenomena such as floods, extreme heat, wildfires, strong winds, landslides and drought, assessing their potential impact on service continuity.

These analyses support the definition of maintenance priorities, protection interventions, infrastructure redundancy and climate adaptation measures.

Transport

In the transport sector, the focus is on rail and road networks, ports, airports and major logistics hubs.

The objective is to identify the routes and infrastructure most vulnerable to natural events, assessing possible service interruptions, network accessibility and the availability of alternative routes.

This information makes it possible to plan investments and strengthen the operational continuity of the most strategic infrastructure.

Telecommunications

For entities formally identified as critical, the assessment concerns towers, radio base stations, network nodes and distributed connections. In Italy, however, Legislative Decree 134/2024 provides that critical entities in this sector are subject to specific sectoral legislation rather than the main operational obligations under the CER framework.

Climate risk assessment requires organizations to identify the assets most exposed to extreme heat, wind, wildfires, landslides and floods, also considering energy, territorial and logistical dependencies.

These analyses support the definition of maintenance priorities, protection interventions, network redundancy and the adaptation measures needed to guarantee service continuity.

How Airis supports climate risk assessment and management

The CER Directive requires natural risk to be assessed in a structured way, considering asset exposure and their ability to guarantee the continuity of essential services.

Analyses based exclusively on historical data are not sufficient.

Climate change is modifying the frequency, intensity and distribution of extreme events, making it necessary to integrate future scenarios and predictive assessments.

Airis is Eoliann’s platform that makes climate risks predictable by analyzing the probability, intensity and physical and economic impact of events on infrastructure assets and networks.

The platform integrates satellite data, geospatial information and proprietary artificial intelligence models to analyze both current conditions and future climate scenarios, with European coverage and projections up to 2050.

Airis is designed to manage both point assets, such as plants and substations, and linear infrastructure, such as power grids, roads and railways. This makes it possible to assess extensive asset portfolios while maintaining a consistent view of risk.

The analysis provides exposure maps, compares climate scenarios and identifies the hotspots where expected impacts are most significant.

Assets are classified according to their vulnerability and potential impact on operational continuity, supporting the definition of intervention priorities.

This information helps infrastructure operators to:

  • Plan resilience and adaptation measures
  • Guide investments
  • Schedule maintenance
  • Make decisions based on objective data and forward-looking scenarios

Would you like to understand how Airis can support the climate risk assessment of your assets?
Request a demo

Airis and the CER Directive

CER Directive requirementHow Airis supports it
Assess natural risk affecting critical assetsAnalyzes the probability, intensity and physical and economic impact of climate events.
Move beyond analyses based only on historical dataIntegrates future climate scenarios and projections up to 2050.
Analyze complex asset portfoliosManages point assets and linear infrastructure on a single platform.
Identify the most vulnerable assetsClassifies assets according to exposure and potential impact on operational continuity.
Identify the most critical areasProvides exposure maps and identifies risk hotspots.
Define intervention prioritiesSupports the prioritization of maintenance, investments and resilience measures.
Plan adaptation interventionsCompares current and future climate scenarios to guide decisions.
Base decisions on objective dataCombines satellite data, geospatial information and proprietary artificial intelligence models.

Assess the climate risk of your assets.

Try Airis

FAQ

What is the CER Directive?

The CER Directive (Critical Entities Resilience) is the European legislation that strengthens the resilience of critical entities that manage essential services. It requires them to assess risks, adopt protection measures and prepare plans to guarantee operational continuity.

What obligations does the CER Directive establish for critical entities?

Critical entities must assess natural and human-made risks, identify essential assets, adopt resilience measures, prepare a resilience plan and notify significant incidents in accordance with the legislation.

What is the difference between the CER Directive and the NIS2 Directive?

The CER Directive concerns the physical and operational resilience of critical entities against natural events and other threats. The NIS2 Directive instead regulates the security of networks and information systems. The two pieces of legislation address different but complementary aspects of infrastructure resilience.

Does the CER Directive also apply to telecommunications infrastructure?

Yes. Digital infrastructure is among the sectors identified by the CER Directive. In Italy, however, critical entities in this sector are subject to specific sectoral legislation rather than the main operational obligations under the CER framework.

How often must the risk assessment be updated?

The CER Directive requires the risk assessment to be kept up to date and reviewed periodically, as well as whenever significant changes may alter the risk profile of the organization or its infrastructure.

How can predictive models support the resilience of critical infrastructure?

Predictive models make it possible to estimate how climate risk may evolve over time and the potential impact it may have on assets. By integrating satellite data, geospatial information and future climate scenarios, they support the prioritization of interventions, maintenance planning and adaptation decisions, strengthening the continuity of essential services.

Want to go deeper?

The best time to prepare for the future
is now.