At a glance: The EU Commission issues new guidelines specifying reporting obligations for critical infrastructure outages under the CER Directive and establishes uniform standards for member states.
The EU Commission has published guidelines on the application of Article 13(5) of the CER Directive (2022/2557). These clarify the requirements for reporting critical infrastructure outages and enable companies to adjust their compliance processes in time.
With Guidelines C/2026/4730, the European Commission clarifies the requirements pursuant to Article 13(5) of the Directive on the resilience of critical entities (CER). The guidelines are primarily addressed to operators of critical infrastructure in the sectors of energy, transport, water, health, digital infrastructure and public administration.
Article 13(5) regulates, among other things, in which cases and within what timeframes operators must report incidents with significant impact – as well as what information these reports must contain. The new guidelines define concrete thresholds, categorisations and exemptions to promote uniform interpretation across member states.
For compliance officers, this means: existing incident response and reporting procedures must be reviewed for conformity with the new requirements. This includes in particular the documentation of threshold determinations, coordination with national authorities and communication with the EU cybersecurity platform, if relevant.
The guidelines will successively be incorporated into national implementing regulations in the member states. For operators, it is recommended to review incident management processes and analyse their own criticality according to the new criteria.
Source: eur-lex.europa.eu · Published
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.