CER Directive – Complete Guide to Critical Infrastructure Compliance
Understand the CER Directive (EU 2022/2557) and learn how SnapKey helps secure your critical infrastructure with advanced access control and compliance.

The CER Directive (Critical Entities Resilience, EU 2022/2557) came into force in the EU in October 2024. It sets enhanced requirements for critical societal systems (electricity, water, transport, healthcare) to be resilient against threats such as cyberattacks, natural disasters, and technical failures.
SnapKey helps you meet all requirements by providing automatic and documented access control.
Who is Covered by the CER Directive?
Sectors
- Energy & electricity grid (power plants, distribution networks)
- Water supply (waterworks, treatment plants)
- Healthcare & hospitals (acute and specialist clinics)
- Digital infrastructure & data centers (telecom, server rooms)
- Transport, airports & ports (terminals, facilities)
Are you a critical entity? Read more about the CER Directive on EUR-Lex for details.
CER Requirements for Physical Security and Access Control
Enhanced Requirements
- Documented access history
- Vulnerability analysis & risk assessment
- Emergency plans & operational continuity
- Restricted access to critical facilities
- Audit readiness for authorities
How SnapKey Meets CER Requirements
SnapKey delivers a unified platform that not only meets the CER Directive's minimum requirements but also supports your operational needs with advanced features:
SnapKey builds on iLOQ technology – a battery-free lock system that works without power, ideal for off-grid installations. This makes SnapKey particularly suitable for critical infrastructure where operational reliability and maintenance-free operation are crucial.
Real-time Monitoring
Follow all access events live with detailed metadata and geographic location.
Time-limited Access
Create precise access windows for staff and external contractors.
Two-factor Authentication
Combine QR, BLE, and biometric authentication for extra security levels.
Automated Reports
Generate compliance reports with a single click, including history and trends.
Alarm & Event Log
Receive instant notifications for suspicious attempts or breaches.
Integrations & API
Seamless integration with your existing CMDB, SIEM, and ERP via RESTful API.
Comparison: CER Requirements vs. SnapKey
| CER Requirement | SnapKey Solution |
|---|---|
| Documented access | Real-time log & tracking |
| Risk assessment | Usage patterns & access analysis |
| Operational contingency plan | Automatic access control & backup |
| Authorized access | Time-limited, user-specific keys |
| Audit readiness | Export to compliance reports |
Getting Started Quickly
4 Steps to Implementation
- Map your critical access points
- Install SnapKey on doors, cabinets & system rooms
- Set up access profiles & roles
- Receive immediate logging & monitoring
Ready for Audit?
SnapKey documents and protects all physical access from day one. You're always ready for audits and ensure operational security in compliance with CER.
FAQ
What is the CER Directive?
The CER Directive (EU 2022/2557) strengthens resilience in critical societal systems.
When does it apply?
The directive applies to EU member states from October 2024, with national implementation varying by country.
How does SnapKey help with compliance?
SnapKey provides documented access control, automated reports, and audit-ready logs.
Contact Us Today
Related articles
The CER Directive after 17 July 2026 – designated as a critical entity? The clock is running
The deadline for designating critical entities expired on 17 July 2026. If your organisation has been notified, you have 9 months for the risk assessment and 10 months to comply. Here is what CER requires of your physical security.
Energy Legislation and Access Control – Requirements for Critical Infrastructure
Understand energy legislation requirements for physical security and access control. Learn how SnapKey helps energy companies achieve compliance.
NIS2 Directive – Access Control and Cybersecurity Requirements 2025
The NIS2 law introduces enhanced requirements for cybersecurity and access control for businesses in critical infrastructure. Learn about the new requirements and how to achieve compliance.