Book an Appointment

Critical infrastructure in the new legal framework

What operators of critical facilities must implement under the amended BSI Act and the KRITIS-Dachgesetz – from thresholds and attack detection to verification obligations.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

10sectors of critical facilities under the KRITIS-Dachgesetz
500,000persons supplied — the standard threshold of the BSI-KritisV
24hours at the latest for the initial report of significant security incidents
3years between § 39 BSIG verifications (previously every two years)

Critical infrastructures – in sectors such as energy, water, healthcare and transport – sustain the supply of essential services to the general public in Germany. Their legal framework was fundamentally reorganised in 2025/2026: since 6 December 2025, the BSI Act (BSIG) as amended by the NIS2 Implementation Act (NIS2-Umsetzungsgesetz) has been in force, and since 17 March 2026 the KRITIS-Dachgesetz (KRITIS umbrella act) has additionally governed physical resilience in line with the European CER Directive. Operators of critical facilities are thus automatically deemed particularly important entities within the meaning of NIS2 and, on top of that, bear additional obligations such as attack detection systems and regular verification vis-à-vis the BSI. This article puts the sectors, thresholds and obligations of both frameworks into perspective.

The new KRITIS legal framework over time

From the SzA obligation to registration with the BBK and BSI — tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

The regulatory layers at a glance

Core BSIG obligations, verification under § 39, the KRITIS-Dachgesetz and the interplay with NIS2 — the key points per layer.

since 6 Dec 2025
  • All core NIS2 obligations apply: risk management measures under § 30 BSIG and registration within three months of classification (§ 33 BSIG).
  • Significant security incidents must be reported to the BSI — an initial report without undue delay and at the latest within 24 hours of becoming aware, a follow-up report within 72 hours and a final report no later than one month after the report (§ 32 BSIG).
  • On top come obligations that go beyond the general NIS2 requirements: attack detection systems and regular verification.
§ 28 BSIG§ 30 BSIG§ 32 BSIG§ 33 BSIGinitial reportfollow-up reportfinal report

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Bundesministerium der Justiz / gesetze-im-internet.de · 2025

Gesetz über das Bundesamt für Sicherheit in der Informationstechnik (BSI-Gesetz – BSIG)

Recast by the NIS2 Implementation Act, in force since 6 December 2025; §§ 28, 30–33 and 39 are decisive for operators of critical facilities.

Bundesministerium des Innern / gesetze-im-internet.de · 2016

Verordnung zur Bestimmung kritischer Anlagen nach dem BSI-Gesetz (BSI-KritisV)

Determines critical facilities via facility categories and thresholds (standard threshold: 500,000 persons supplied); remains in force until the new KritisV under the KRITIS-Dachgesetz is enacted (ministerial draft of 26 May 2026).

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2024

Orientierungshilfe zum Einsatz von Systemen zur Angriffserkennung

Version 1.1 of 18 November 2024; requirements for logging, detection and response, including the implementation maturity model for SzA verification.

Bundesgesetzblatt 2026 I · 2026

KRITIS-Dachgesetz (KRITIS-DachG)

Implements the CER Directive, in force since 17 March 2026; governs sectors, the standard threshold, registration with the BBK, risk assessments, resilience measures and reporting obligations.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2557 über die Resilienz kritischer Einrichtungen (CER)

European requirements for the physical resilience of critical entities and the basis of the KRITIS-Dachgesetz.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

European framework for the cybersecurity obligations of essential and important entities; basis of the BSIG amendment.

Implement KRITIS obligations in a structured way?

We support operators of critical facilities from the applicability assessment through attack detection systems to verification under § 39 BSIG. Get in touch for a no-obligation initial consultation.