CER Designation Has Started: What Cable Operators Need to Know
What’s inside?
At a Glance
- The July 17, 2026 deadline for EU member states to identify critical entities under the Critical Entities Resilience (CER) Directive has passed, and notifications to designated entities are now being issued across member states.
- Member states must notify identified critical entities within one month of identification, with the CER compliance clock starting from the date of that notification.
- Designated critical entities have nine months from notification to complete a mandatory risk assessment and 10 months from notification to demonstrate full compliance with the Directive’s operational requirements.
- Notifications are not landing uniformly across the EU, meaning some cable operators have already received formal designation, others expect notification in the coming weeks, and others may not yet know whether they will be designated.
- The compliance work required after designation is substantial, including a formal resilience plan, upgraded detection capability, incident reporting workflows that satisfy the 24-hour standard, and documentation methodology that supports regulatory defense.
- Cable operators uncertain about their status can act as if designation is possible while awaiting confirmation, since the preparation work reduces exposure regardless of the eventual outcome.
The Designation Window Has Opened
The July 17, 2026 deadline set by the Critical Entities Resilience Directive has passed. Under Article 6 of the Directive, EU member states were required to identify critical entities within their jurisdictions by that date, and to notify identified entities within one month of identification. Notifications began arriving in the weeks leading up to July 17 in some member states and are continuing to arrive across the EU in the weeks after.
The regulatory picture across the EU is now bifurcated. Some cable operators have received formal designation letters from their national authorities. Others are awaiting notification as their member state finalizes and issues its designation letters within the one-month window that follows identification. Others still do not know whether they will be designated at all, either because notification is pending or because their operational footprint sits close to the essential services threshold without clearly crossing it.
For all three groups, the compliance clock is either running or about to run. Cable operators cannot afford to wait for perfect regulatory clarity before beginning preparation work, because the 10-month compliance window leaves limited room for delay once designation is confirmed.
The Post-Notification Compliance Timeline
The compliance timeline built into the Directive gives designated entities a specific sequence of obligations after notification, each with its own deadline.
| Stage | Deadline | What Happens |
| Notification | Within one month of identification. | Member states notify identified critical entities of their designation. The notification triggers the compliance clock. |
| Risk Assessment | Within nine months of notification. | The designated entity must carry out a mandatory risk assessment evaluating the risks to the essential services it provides. The risk assessment must be documented in a way that supports the resilience plan that follows. |
| Full Compliance | Within ten months of notification. | The full CER compliance requirements apply, including the resilience plan, incident detection and reporting capabilities, impact measurement methodologies, and the broader operational adaptation the Directive requires. |
For a cable operator notified on July 17, 2026, this places the risk assessment deadline at April 17, 2027, and the full compliance deadline at May 17, 2027. For operators notified later in 2026, the deadlines shift accordingly, but the fundamental sequence remains the same.
The 10 months from notification to full compliance is meaningful time in theory, but the operational work required is substantial. Cable operators that use the first three months on scoping and framework decisions rather than actual capability building are compressing the work into the second half of the window, which is where most operators will find the timeline uncomfortably tight.
What Designated Operators Should Do in the First 30 Days
For cable operators that have received a designation notification, the first 30 days set the trajectory of the compliance work that follows.
1. Confirm the Notification’s Scope and Specific Obligations
Member states have some flexibility in how they implement CER, and notification letters can vary in the specific obligations they cite. Understanding exactly what the national authority expects and by when is the foundational step.
2. Identify the Internal Owner
CER compliance spans regulatory, operational, technical, and executive domains. The designated internal owner needs the authority to coordinate across those domains. This is not a compliance-team-only exercise.
3. Begin the Risk Assessment Scoping
The nine-month risk assessment clock is the most substantive compliance obligation and the one that shapes the resilience plan that follows. Scoping the risk assessment early, including which infrastructure assets it covers, which threat categories it addresses, and which analytical methods will support it, determines whether the work can be completed within the window.
4. Assess Current Detection Capability Against the 24-Hour Standard
The 24-hour incident reporting requirement is the operational obligation that most frequently exposes gaps in existing monitoring. Operators should assess whether their current vessel monitoring can detect an incident involving a vessel with AIS disabled, surface behavioral patterns before they become incidents, and produce a defensible evidence base for regulatory reporting within the 24-hour window.
5. Engage Regulatory Counsel With CER-Specific Expertise
The Directive’s requirements interact with member state implementation, sector-specific regulations, and adjacent regulatory frameworks such as NIS2. Getting the regulatory picture right requires specialist input.
What the Nine-Month Risk Assessment Should Cover
The mandatory risk assessment is the analytical foundation for CER compliance. It should cover several distinct dimensions.
Threat Identification
The risk assessment should identify the specific threats to the essential services the operator provides, drawing on threat intelligence relevant to the operator’s infrastructure. For subsea cable operators, this includes both direct physical threats to cables and indirect threats through the ecosystem of vessels operating near cable corridors.
Vulnerability Analysis
Where in the operator’s current infrastructure, monitoring, and response capabilities are the vulnerabilities that could be exploited to disrupt essential services? Vulnerability analysis needs to be honest and specific rather than boilerplate.
Impact Assessment
If a threat exploits a vulnerability, what is the potential impact on the essential services the operator provides? Impact assessment should account for both direct disruption and cascading effects on other critical entities and end users.
Detection Capability Evaluation
Can the operator’s current systems detect the threats identified? This is where AIS-only monitoring most frequently falls short of the CER standard, particularly for cable-proximate threats involving vessels operating dark.
Resilience Gap Analysis
Where do the current capabilities fall short of the resilience the Directive requires? The gap analysis is what informs the resilience plan and the specific investments and process changes required.
Why AIS-Only Detection Still Falls Short
The AIS-based monitoring that has historically anchored maritime infrastructure protection cannot meet the CER standard on its own, and the risk assessment process is where this shortfall will become documented and formal for many operators.
AIS is a cooperative signal. Vessels broadcast their identity, position, and course voluntarily. Vessels can switch AIS off, jam the surrounding GPS environment, or manipulate the signal in ways that make broadcast positions unreliable. The vessels most likely to threaten cable infrastructure are precisely the vessels most likely to operate dark or spoof their AIS.
The operational consequence for CER compliance is direct. A monitoring posture that depends entirely on AIS data cannot reliably detect incidents involving vessels that have switched off AIS, cannot distinguish jamming-affected positions from genuine vessel movements, and cannot surface behavioral patterns that indicate cable-proximate risk before an incident occurs.
The 24-hour reporting obligation compounds the challenge. Article 15 of the CER Directive ties the 24-hour clock to the moment the entity becomes aware of an incident, not to when the incident itself occurred, with an initial notification due within 24 hours of that awareness and a more detailed report due within one month.
If an operator’s detection systems only surface an incident well after it began, awareness comes late, and the clock still starts running from that delayed moment, compressing the time left to investigate and report. The result is a reporting process built on reconstructing what happened during the detection gap, rather than one grounded in real-time visibility, which weakens the documentation an operator can put in front of regulators.
The regulatory expectation the Directive creates is for detection capability that does not depend on the adversary’s cooperation. That is the case for multi-source intelligence, fusing AIS, satellite imagery (SAR and EO), radio frequency detection, and behavioral context into a single operational picture that verifies what vessels actually do rather than what they broadcast.
The Operational Threat Environment Is Not Waiting
Even as designation notifications arrive, the underlying threat environment against which CER was designed continues to evolve.
A Russian-linked research vessel was documented loitering above a major trans-Atlantic telecommunications cable for 41 days between February and April 2026, with AIS broadcasting continuously, a valid flag, and clean filings throughout. Conventional document-based screening would not have flagged the vessel. The behavioral pattern is what surfaced the picture, and the pattern is recurring across European subsea infrastructure.
The pattern extends well beyond a single vessel. Windward recorded 3,667 loitering events over 12 hours above subsea cables in Q2 2026, averaging roughly 40 a day. More than half concentrated in the Red Sea, Gulf of Aden, and the Malacca Strait.
GPS jamming has become a persistent feature of global shipping rather than an episodic one. In Q2 2026, 171,286 distinct vessels were affected by jamming at least once worldwide. Since Operation Epic Fury began on February 28, 2026, Windward has detected 3.35 million false ship-to-ship meetings globally, in which injected positioning coordinates made vessels appear to rendezvous when no meeting took place. AIS-based situational awareness now carries embedded uncertainty in exactly the regions where cable-proximate risk is most concentrated.
The vessels exhibiting cable-proximate behavior in European waters are continuing to operate under exactly the conditions the CER Directive is intended to address. The regulatory framework is a response to that threat environment, not an isolated compliance exercise. The operators that treat CER preparation as an operational adaptation to a real threat picture will produce risk assessments and resilience plans that hold up. The operators that treat CER as a documentary exercise will produce compliance files that meet the letter of the Directive but fail to close the actual detection and response gaps that led to the regulation.
How Windward Supports CER Compliance
Windward’s Critical Maritime Infrastructure Protection solution is built to help cable operators address key detection elements of the CER Directive. Cable operators working through the nine-month risk assessment and 10-month compliance window are grappling with the same operational reality the solution is designed to address: high-value assets fixed in position, distributed across vast offshore areas that cannot be persistently monitored, with adversary activity that blends into routine maritime traffic in congested corridors or remote offshore zones.
The core capability is active threat detection. The operator provides Windward with the coordinates of the cable infrastructure. Windward monitors a defined polygon around those coordinates continuously, applying behavioral pattern recognition to vessel activity within the zone. When a high-risk vessel exhibits suspicious behavior near the infrastructure, an alert is sent to the operator’s team, paired with an Organization Defined Risk (ODR) configuration that reflects the operator’s specific threat priorities.
The solution supports four operational needs that map directly to CER’s risk assessment and resilience plan requirements. Active monitoring around critical assets delivers vessel tracking near critical infrastructure, proximity and zone breach detection, vessel behavior and intent analysis, and identification of dark activity and AIS gaps within the defined zone. This is the detection capability that supports the 24-hour reporting standard in ways AIS-only monitoring cannot.
Incident investigation and operational analysis delivers full vessel movement reconstruction, behavioral anomaly detection, event timeline and pattern analysis, and multi-source activity verification. Following a cable damage event, the operator can reconstruct what actually happened, identify potential culprits, and validate findings against satellite-based data.
Operational resilience and ongoing risk assessment delivers vessel and fleet activity pattern tracking, high-risk vessel identification, deceptive shipping practice detection, and exposure mapping across regions and operational zones. This feeds the ongoing threat intelligence input that the CER risk assessment methodology requires.
Customization and organization-specific configuration include several capabilities. Data layers with Bring Your Own Data (BYOD) support let operators search for suspicious vessels and activities near cables that matter to them. Organization Defined Risk configuration applies to specific vessels or activity types. In-system vessel of interest lists are updated daily with shadow fleet designations. Behavioral anomaly notifications support timely risk assessment. MAI Expert™ provides immediate Gen AI-generated reports on vessels of interest.
For cable operators preparing risk assessments and resilience plans under CER, the operational fit is direct. The solution provides the detection capability that supports the 24-hour reporting standard, the behavioral pattern recognition that surfaces threats before incidents occur, the multi-source verification that supports defensible regulatory reporting, and the customization that allows the operator’s specific infrastructure and risk profile to shape the monitoring configuration.
The presence of a vessel in a GPS jamming-affected area is not, by itself, a behavioral risk indicator. GPS jamming is something happening to a geographic area, not something a vessel is doing. Cable operators evaluating vessel risk should assess each vessel independently based on its own behavioral patterns and operating history.
What Cable Operators Not Yet Designated Should Do
Operators that have not yet received a designation notification should not treat that as an indication of non-designation. Member state identification and notification processes are still in progress across the EU, and notifications continuing to arrive through Q3 2026 and beyond are expected.
The preparation work that reduces exposure regardless of eventual designation status includes the following.
- Scope assessment: Operators should be working with regulatory counsel to assess whether their operations are likely to meet the essential services threshold in the member states where they have cable infrastructure. If the answer is likely yes, the preparation work should begin now.
- Gap analysis on detection capability: The same 24-hour reporting standard that binds designated entities is the analytical benchmark for what adequate cable monitoring looks like in 2026. Operators that map their current monitoring against this standard identify the operational gaps that either designation or a future incident will surface.
- Resilience plan groundwork: Even before designation, drafting the structure of a resilience plan covering prevention, detection, response and repair, and deterrence gives the operator a framework that can be refined quickly once designation occurs. Plans built from scratch under the 10-month clock are much harder to build well.
- Funding strategy: CEF Digital supports the EU Action Plan on Cable Security through specific funding calls for cable infrastructure, repair capacity, and smart cable monitoring. Operators building business cases for security and monitoring investments before designation can explore CEF Digital funding pathways for eligible infrastructure components.
Operators that used the July 17 deadline as the trigger to begin their preparation, rather than waiting for individual designation letters, are positioning themselves for compliance regardless of the specific notification timing.
What to Watch Over the Next Quarter
Several developments in the coming months are worth tracking.
- Member state notification patterns: The pace and specificity of notifications will vary across member states through Q3 2026. Operators with cable infrastructure in multiple member states may receive different notifications on different timelines with different specific obligations. Multi-jurisdiction operators should be tracking each national implementation separately.
- Regulatory guidance and clarifications: The Directive’s operational requirements will be clarified over time through member state guidance, sector-specific technical standards, and enforcement signaling. Operators should build monitoring for these developments into their compliance workflow rather than treating the Directive text as the final word.
- Adjacent regulatory activity: NIS2 obligations for cybersecurity resilience apply in parallel to CER, and cable operators are typically in scope of both. Regulatory activity around adjacent frameworks, including data protection, sector-specific security requirements, and international standards work, all interact with CER implementation.
- The operational threat picture: The vessels and behaviors that CER was designed to address are continuing to operate in European waters. Cable operators should be monitoring the evolving threat picture as an input to their risk assessments, not as background context.
The cable operators best positioned for CER over the coming year will be those treating designation as the operational trigger for adaptation that was already needed, rather than as a compliance obligation to be managed narrowly.
Frequently Asked Questions (FAQs)
The July 17, 2026 deadline has passed. What happens now?
The July 17 deadline was for EU member states to identify critical entities under CER, and notifications to those identified entities are now being issued across the EU. Once notified, a critical entity has nine months to complete a mandatory risk assessment and 10 months to demonstrate full compliance with the Directive’s operational requirements.
My cable operation has not received a designation notification. Does that mean we are not designated?
Not necessarily. Notifications are continuing to arrive across the EU, and operators that have not received notification yet may still receive one in the coming weeks. Operators uncertain about their status can act as if designation is possible, since preparation work reduces exposure regardless of eventual outcome.
What is the risk assessment critical entities must complete?
The risk assessment is a mandatory analysis required within nine months of notification, covering threat identification, vulnerability analysis, impact assessment, detection capability evaluation, and resilience gap analysis. It forms the analytical foundation for the resilience plan that must be in place by month 10.
How does the 24-hour incident reporting requirement affect cable operators?
Designated entities must report any incident that disrupts or could disrupt essential services within 24 hours of detection. This means operators need detection capability that surfaces incidents in real time or near real time, which AIS-only monitoring often cannot deliver when vessels operate dark or manipulate their broadcasts.
What if we cannot complete all compliance requirements within 10 months of notification?
The 10-month deadline is fixed by the Directive, and operators unable to meet it face potential enforcement action from their national authority. Operators that anticipate difficulty should engage their national authority proactively and document the specific work being undertaken, since the defensibility of the preparation process supports mitigation arguments if enforcement questions arise.
How does multi-source intelligence support CER compliance?
Multi-source intelligence fuses AIS with satellite imagery (SAR and EO), radio frequency detection, and behavioral context, providing sensor-verified vessel activity that does not depend on the integrity of AIS broadcasts. This supports both the detection capability evaluation in the risk assessment and the ongoing 24-hour reporting requirement, closing the gap that AIS-only monitoring leaves open.
Trending
- The EU’s 18th Sanctions Package Lookback Started. Trading Russian Products? You're At Risk. Nov 24, 2025
- Tanker Freight Rates Hit Five-Year High Amid Russian Oil Sanctions Shake-Out Nov 6, 2025
- Sanctioned, Stateless, and Still Sailing: Expert Insights from the Frontlines of Maritime Sanctions Nov 3, 2025