Book an Appointment

Critical infrastructure in the new legal framework

What operators of critical facilities must implement under the amended BSI Act and the KRITIS-Dachgesetz – from thresholds and attack detection to verification obligations.

Critical infrastructures – in sectors such as energy, water, healthcare and transport – sustain the supply of essential services to the general public in Germany. Their legal framework was fundamentally reorganised in 2025/2026: since 6 December 2025, the BSI Act (BSIG) as amended by the NIS2 Implementation Act (NIS2-Umsetzungsgesetz) has been in force, and since 17 March 2026 the KRITIS-Dachgesetz (KRITIS umbrella act) has additionally governed physical resilience in line with the European CER Directive. Operators of critical facilities are thus automatically deemed particularly important entities within the meaning of NIS2 and, on top of that, bear additional obligations such as attack detection systems and regular verification vis-à-vis the BSI. This article puts the sectors, thresholds and obligations of both frameworks into perspective.

The Essentials at a Glance

01

What critical facilities are: sectors and thresholds

Critical facilities are installations of major importance for supplying the general public whose failure or impairment would lead to significant supply shortages or threats to public safety. The KRITIS-Dachgesetz, to which § 2 number 22 BSIG refers for the definition of a facility, assigns them to ten sectors: energy; transport and traffic; finance; social insurance and basic income support for jobseekers; healthcare; water; food; information technology and telecommunications; space; and municipal waste management. Whether a specific facility is critical is determined by the BSI-KritisV on the basis of facility categories and thresholds; the standard threshold is 500,000 persons supplied. The existing ordinance remains in force for the time being – for the new KritisV under the KRITIS-Dachgesetz, a ministerial draft bill (Referentenentwurf) from the BMI has been available since 26 May 2026, which has no legal force yet.

02

The BSIG after NIS2 implementation: the new framework of obligations

The NIS2 Implementation Act recast the BSI Act with effect from 6 December 2025 – without general transition periods. Under § 28 BSIG, operators of critical facilities always qualify as particularly important entities and therefore bear all core NIS2 obligations: risk management measures under § 30 BSIG, registration within three months of classification (§ 33 BSIG), and the reporting of significant security incidents to the BSI – with an initial report without undue delay and at the latest within 24 hours of becoming aware, a follow-up report within 72 hours and a final report no later than one month after the report (§ 32 BSIG). In addition, critical facilities are subject to obligations that go beyond the general NIS2 requirements: attack detection systems and regular verification.

03

Verification obligation under § 39 BSIG: every three years

Operators of critical facilities must demonstrate to the BSI the implementation of their measures under §§ 30 and 31 BSIG by means of security audits, examinations or certifications – for the first time three years after the initial or renewed classification, and every three years thereafter. The verification cycle has thus been extended compared with the previous legal situation (§ 8a(3) BSIG, old version: every two years); the specific date of the first verification is determined by the BSI. The results of the audits, examinations or certifications, including any security deficiencies identified in the process, must be submitted to the BSI; where deficiencies are found, the BSI may require the submission of a remediation plan and proof of remediation.

04

Attack detection systems (§ 31 BSIG)

Since May 2023, operators of critical facilities have been required to deploy attack detection systems (Systeme zur Angriffserkennung, SzA); today, the obligation is enshrined in § 31 BSIG. The systems must continuously and automatically capture and evaluate suitable parameters and indicators from live operations, identify and prevent threats on an ongoing basis, and provide for remediation measures for disruptions that have occurred – in line with the state of the art and subject to a proportionality proviso: the effort must not be disproportionate to the consequences of a failure. The benchmark for implementation and auditing is the BSI guidance on the use of attack detection systems (Orientierungshilfe, version 1.1, dated 18 November 2024), with MUSS (must), SOLLTE (should) and KANN (may) requirements in the areas of logging, detection and response, plus a six-level implementation maturity model whose result feeds into the verification under § 39 BSIG.

05

KRITIS-Dachgesetz: physical resilience under the CER Directive

With the KRITIS-Dachgesetz, in force since 17 March 2026, Germany implements the CER Directive (EU) 2022/2557 and for the first time creates a uniform federal legal framework for the physical protection of critical facilities across ten sectors. The central point of contact is the Federal Office of Civil Protection and Disaster Assistance (BBK). Operators must register via a joint registration facility of the BBK and the BSI within three months of their facility qualifying as critical – at the earliest from 17 July 2026 (§ 8 KRITIS-DachG), conduct their own risk assessments as needed, but at least every four years (§ 12), implement and document appropriate and proportionate technical, security-related and organisational resilience measures (§ 13), and report significant disruptions within 24 hours (§ 18). Alongside IT, this brings structural security, access protection, redundancies and crisis organisation into the catalogue of obligations.

06

Relationship with NIS2: two frameworks, one operator

The BSIG and the KRITIS-Dachgesetz interlock: the BSIG implements the NIS2 Directive (EU) 2022/2555 and addresses cybersecurity, while the umbrella act covers physical resilience under CER. Both build on the same concept of the critical facility – critical facilities are registered uniformly under § 8 KRITIS-DachG, to which § 33(2) BSIG expressly refers. Operators of critical facilities thus form a subset of the entities regulated by NIS2, with additional obligations: attack detection, three-year verification cycles and physical resilience measures. In practice, an integrated management system that jointly governs the ISMS, business continuity and physical protection is preferable to serving both frameworks separately.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Bundesministerium der Justiz / gesetze-im-internet.de · 2025

Gesetz über das Bundesamt für Sicherheit in der Informationstechnik (BSI-Gesetz – BSIG)

Recast by the NIS2 Implementation Act, in force since 6 December 2025; §§ 28, 30–33 and 39 are decisive for operators of critical facilities.

Bundesministerium des Innern / gesetze-im-internet.de · 2016

Verordnung zur Bestimmung kritischer Anlagen nach dem BSI-Gesetz (BSI-KritisV)

Determines critical facilities via facility categories and thresholds (standard threshold: 500,000 persons supplied); remains in force until the new KritisV under the KRITIS-Dachgesetz is enacted (ministerial draft of 26 May 2026).

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2024

Orientierungshilfe zum Einsatz von Systemen zur Angriffserkennung

Version 1.1 of 18 November 2024; requirements for logging, detection and response, including the implementation maturity model for SzA verification.

Bundesgesetzblatt 2026 I · 2026

KRITIS-Dachgesetz (KRITIS-DachG)

Implements the CER Directive, in force since 17 March 2026; governs sectors, the standard threshold, registration with the BBK, risk assessments, resilience measures and reporting obligations.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2557 über die Resilienz kritischer Einrichtungen (CER)

European requirements for the physical resilience of critical entities and the basis of the KRITIS-Dachgesetz.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

European framework for the cybersecurity obligations of essential and important entities; basis of the BSIG amendment.

Implement KRITIS obligations in a structured way?

We support operators of critical facilities from the applicability assessment through attack detection systems to verification under § 39 BSIG. Get in touch for a no-obligation initial consultation.