01What critical facilities are: sectors and thresholds
Critical facilities are installations of major importance for supplying the general public whose failure or impairment would lead to significant supply shortages or threats to public safety. The KRITIS-Dachgesetz, to which § 2 number 22 BSIG refers for the definition of a facility, assigns them to ten sectors: energy; transport and traffic; finance; social insurance and basic income support for jobseekers; healthcare; water; food; information technology and telecommunications; space; and municipal waste management. Whether a specific facility is critical is determined by the BSI-KritisV on the basis of facility categories and thresholds; the standard threshold is 500,000 persons supplied. The existing ordinance remains in force for the time being – for the new KritisV under the KRITIS-Dachgesetz, a ministerial draft bill (Referentenentwurf) from the BMI has been available since 26 May 2026, which has no legal force yet.
02The BSIG after NIS2 implementation: the new framework of obligations
The NIS2 Implementation Act recast the BSI Act with effect from 6 December 2025 – without general transition periods. Under § 28 BSIG, operators of critical facilities always qualify as particularly important entities and therefore bear all core NIS2 obligations: risk management measures under § 30 BSIG, registration within three months of classification (§ 33 BSIG), and the reporting of significant security incidents to the BSI – with an initial report without undue delay and at the latest within 24 hours of becoming aware, a follow-up report within 72 hours and a final report no later than one month after the report (§ 32 BSIG). In addition, critical facilities are subject to obligations that go beyond the general NIS2 requirements: attack detection systems and regular verification.
03Verification obligation under § 39 BSIG: every three years
Operators of critical facilities must demonstrate to the BSI the implementation of their measures under §§ 30 and 31 BSIG by means of security audits, examinations or certifications – for the first time three years after the initial or renewed classification, and every three years thereafter. The verification cycle has thus been extended compared with the previous legal situation (§ 8a(3) BSIG, old version: every two years); the specific date of the first verification is determined by the BSI. The results of the audits, examinations or certifications, including any security deficiencies identified in the process, must be submitted to the BSI; where deficiencies are found, the BSI may require the submission of a remediation plan and proof of remediation.
04Attack detection systems (§ 31 BSIG)
Since May 2023, operators of critical facilities have been required to deploy attack detection systems (Systeme zur Angriffserkennung, SzA); today, the obligation is enshrined in § 31 BSIG. The systems must continuously and automatically capture and evaluate suitable parameters and indicators from live operations, identify and prevent threats on an ongoing basis, and provide for remediation measures for disruptions that have occurred – in line with the state of the art and subject to a proportionality proviso: the effort must not be disproportionate to the consequences of a failure. The benchmark for implementation and auditing is the BSI guidance on the use of attack detection systems (Orientierungshilfe, version 1.1, dated 18 November 2024), with MUSS (must), SOLLTE (should) and KANN (may) requirements in the areas of logging, detection and response, plus a six-level implementation maturity model whose result feeds into the verification under § 39 BSIG.
05KRITIS-Dachgesetz: physical resilience under the CER Directive
With the KRITIS-Dachgesetz, in force since 17 March 2026, Germany implements the CER Directive (EU) 2022/2557 and for the first time creates a uniform federal legal framework for the physical protection of critical facilities across ten sectors. The central point of contact is the Federal Office of Civil Protection and Disaster Assistance (BBK). Operators must register via a joint registration facility of the BBK and the BSI within three months of their facility qualifying as critical – at the earliest from 17 July 2026 (§ 8 KRITIS-DachG), conduct their own risk assessments as needed, but at least every four years (§ 12), implement and document appropriate and proportionate technical, security-related and organisational resilience measures (§ 13), and report significant disruptions within 24 hours (§ 18). Alongside IT, this brings structural security, access protection, redundancies and crisis organisation into the catalogue of obligations.
06Relationship with NIS2: two frameworks, one operator
The BSIG and the KRITIS-Dachgesetz interlock: the BSIG implements the NIS2 Directive (EU) 2022/2555 and addresses cybersecurity, while the umbrella act covers physical resilience under CER. Both build on the same concept of the critical facility – critical facilities are registered uniformly under § 8 KRITIS-DachG, to which § 33(2) BSIG expressly refers. Operators of critical facilities thus form a subset of the entities regulated by NIS2, with additional obligations: attack detection, three-year verification cycles and physical resilience measures. In practice, an integrated management system that jointly governs the ISMS, business continuity and physical protection is preferable to serving both frameworks separately.