Critical facilities are installations of major importance for supplying the general public whose failure or impairment would lead to significant supply shortages or threats to public safety. The KRITIS-Dachgesetz, to which § 2 number 22 BSIG refers for the definition of a facility, assigns them to ten sectors: energy; transport and traffic; finance; social insurance and basic income support for jobseekers; healthcare; water; food; information technology and telecommunications; space; and municipal waste management. Whether a specific facility is critical is determined by the BSI-KritisV on the basis of facility categories and thresholds; the standard threshold is 500,000 persons supplied. The existing ordinance remains in force for the time being – for the new KritisV under the KRITIS-Dachgesetz, a ministerial draft bill (Referentenentwurf) from the BMI has been available since 26 May 2026, which has no legal force yet.
Critical infrastructure in the new legal framework
What operators of critical facilities must implement under the amended BSI Act and the KRITIS-Dachgesetz – from thresholds and attack detection to verification obligations.
Critical infrastructures – in sectors such as energy, water, healthcare and transport – sustain the supply of essential services to the general public in Germany. Their legal framework was fundamentally reorganised in 2025/2026: since 6 December 2025, the BSI Act (BSIG) as amended by the NIS2 Implementation Act (NIS2-Umsetzungsgesetz) has been in force, and since 17 March 2026 the KRITIS-Dachgesetz (KRITIS umbrella act) has additionally governed physical resilience in line with the European CER Directive. Operators of critical facilities are thus automatically deemed particularly important entities within the meaning of NIS2 and, on top of that, bear additional obligations such as attack detection systems and regular verification vis-à-vis the BSI. This article puts the sectors, thresholds and obligations of both frameworks into perspective.
The new KRITIS legal framework over time
From the SzA obligation to registration with the BBK and BSI — tap a milestone for details.
Attack detection obligation begins
Since May 2023, operators of critical facilities have been required to deploy attack detection systems (SzA) — an obligation today enshrined in § 31 BSIG, in line with the state of the art and subject to a proportionality proviso.
Amended BSIG in force
The BSI Act as recast by the NIS2 Implementation Act applies — without general transition periods. Under § 28 BSIG, operators of critical facilities always qualify as particularly important entities.
KRITIS-Dachgesetz in force
The umbrella act implements the CER Directive (EU) 2022/2557 and for the first time creates a uniform federal legal framework for the physical protection of critical facilities across ten sectors.
Draft bill for the new KritisV
A ministerial draft bill (Referentenentwurf) from the BMI for the new KritisV under the KRITIS-Dachgesetz is available — with no legal force yet; the existing ordinance remains in force for the time being.
Earliest possible registration date
From this date at the earliest, operators register via the joint registration facility of the BBK and the BSI — within three months of their facility qualifying as critical (§ 8 KRITIS-DachG).
The Essentials at a Glance
Six topic blocks — tap to expand.
The regulatory layers at a glance
Core BSIG obligations, verification under § 39, the KRITIS-Dachgesetz and the interplay with NIS2 — the key points per layer.
- All core NIS2 obligations apply: risk management measures under § 30 BSIG and registration within three months of classification (§ 33 BSIG).
- Significant security incidents must be reported to the BSI — an initial report without undue delay and at the latest within 24 hours of becoming aware, a follow-up report within 72 hours and a final report no later than one month after the report (§ 32 BSIG).
- On top come obligations that go beyond the general NIS2 requirements: attack detection systems and regular verification.
- Implementation of the measures under §§ 30 and 31 BSIG must be demonstrated to the BSI by security audits, examinations or certifications — for the first time three years after the initial or renewed classification, and every three years thereafter.
- The specific date of the first verification is determined by the BSI.
- The results, including any security deficiencies identified, must be submitted; where deficiencies are found, the BSI may require a remediation plan and proof of remediation.
- Registration within three months of the facility qualifying as critical — at the earliest from 17 July 2026 — via the joint registration facility of the BBK and the BSI (§ 8 KRITIS-DachG).
- Own risk assessments as needed, but at least every four years (§ 12); appropriate and proportionate resilience measures must be implemented and documented (§ 13).
- Significant disruptions must be reported within 24 hours (§ 18) — alongside IT, structural security, access protection, redundancies and crisis organisation enter the catalogue of obligations.
- The BSIG implements the NIS2 Directive (EU) 2022/2555 and addresses cybersecurity, while the umbrella act covers physical resilience under CER.
- Critical facilities are registered uniformly under § 8 KRITIS-DachG, to which § 33(2) BSIG expressly refers.
- Operators form a subset of the entities regulated by NIS2, with additional obligations — in practice, an integrated management system that jointly governs the ISMS, business continuity and physical protection is preferable.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Gesetz über das Bundesamt für Sicherheit in der Informationstechnik (BSI-Gesetz – BSIG)
Recast by the NIS2 Implementation Act, in force since 6 December 2025; §§ 28, 30–33 and 39 are decisive for operators of critical facilities.
Verordnung zur Bestimmung kritischer Anlagen nach dem BSI-Gesetz (BSI-KritisV)
Determines critical facilities via facility categories and thresholds (standard threshold: 500,000 persons supplied); remains in force until the new KritisV under the KRITIS-Dachgesetz is enacted (ministerial draft of 26 May 2026).
Orientierungshilfe zum Einsatz von Systemen zur Angriffserkennung
Version 1.1 of 18 November 2024; requirements for logging, detection and response, including the implementation maturity model for SzA verification.
KRITIS-Dachgesetz (KRITIS-DachG)
Implements the CER Directive, in force since 17 March 2026; governs sectors, the standard threshold, registration with the BBK, risk assessments, resilience measures and reporting obligations.
Richtlinie (EU) 2022/2557 über die Resilienz kritischer Einrichtungen (CER)
European requirements for the physical resilience of critical entities and the basis of the KRITIS-Dachgesetz.
Richtlinie (EU) 2022/2555 (NIS2)
European framework for the cybersecurity obligations of essential and important entities; basis of the BSIG amendment.
Implement KRITIS obligations in a structured way?
We support operators of critical facilities from the applicability assessment through attack detection systems to verification under § 39 BSIG. Get in touch for a no-obligation initial consultation.