CER Directive (Critical Entities Resilience Directive)

In telecommunications, the CER Directive is the EU framework that complements NIS2 by addressing the physical resilience of critical entities, including telecom infrastructure operators. It requires resilience measures, risk assessments, and incident reporting against non-cyber threats such as natural hazards and physical attacks.

Categories: Threats and AttacksInternet and RoutingRegulation and Compliance

CER Directive in context

Telecom threats range from opportunistic SMS phishing and SIM swap to nation-state grade location tracking. The common thread is that most attacks exploit the inherited trust model of legacy signaling protocols.

Telecom networks depend on Internet-style routing (BGP, DNS, MPLS) for interconnect. Route hijacks and DNS abuse can degrade or intercept signaling, which is why RPKI and DNSSEC are now standard hardening for carrier networks.

To place CER Directive in the wider telecom-security picture, review A5/2, ASN, BGP, BGP Hijacking, CGNAT and CVE — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.