In short: The KRITIS Umbrella Act (KRITIS-Dachgesetz, KRITISDachG) transposes the EU Directive on the resilience of critical entities (CER Directive, (EU) 2022/2557) into German law. It governs the physical resilience of critical facilities against all hazards, from floods to sabotage to power outages. The act has applied since 17 March 2026. Which facilities are critical is set by an ordinance that, according to the Federal Office of Civil Protection and Disaster Assistance (BBK), is still being drafted. Until then there is no registration or reporting obligation under this act. That time is your preparation window.

Legislative status on 29 September 2026

  • Bundestag: adopted on 29 January 2026 based on the recommendation of the Committee on Internal Affairs (printed paper 21/3906).
  • Bundesrat: consent on 6 March 2026.
  • Promulgation: Federal Law Gazette 2026 I No. 66 of 16 March 2026.
  • Entry into force: 17 March 2026.
  • Pending: the ordinance under Section 4(3) and Section 5(1) KRITISDachG that defines facility categories and thresholds. The BBK states that there is currently no registration obligation under the KRITISDachG and that operators of critical facilities do not yet need to act.

The act is therefore law in force, but its operator duties only start once the ordinance is promulgated. Anyone planning today plans against a fixed legal text with an open start date.

Who is affected

Section 4(1) lists ten sectors: energy, transport and traffic, finance, social security and basic income support for jobseekers, health, water, food, information technology and telecommunications, space, and municipal waste disposal. A facility is critical if it is significant for a critical service and reaches the threshold set by the ordinance. Section 5(2) sets the standard threshold at, in principle, 500,000 people served. The Federal Ministry of the Interior can also designate a facility as critical in individual cases (Section 5(3)).

Section 4(2) sets out important exemptions: financial entities covered by the EU DORA regulation and the information technology and telecommunications sector are exempt from most operator duties. The more specific rules of DORA and the BSI Act apply to them.

Operator duties at a glance

Once a facility counts as critical under the ordinance, a fixed sequence begins (Section 8(7)):

  1. Registration (Section 8) no later than three months after the facility counts as critical. Registration is made with the BBK through a joint registration facility of the BSI and the BBK. Required data include location, supply area, critical service, contact point and IP address ranges. Changes must be reported within two weeks.
  2. Risk analysis (Section 12) for the first time nine months after registration, then as needed and at least every four years. It follows an all-hazards approach: natural, technical and human-made risks, including dependencies on other operators and sectors.
  3. Resilience measures and resilience plan (Section 13) for the first time ten months after registration. The measures must prevent incidents, ensure physical protection, enable response and secure recovery. Examples in the act are site protection with fences, detection and access control, emergency power, alternative supply chains, crisis management, personnel security, and training and exercises. The benchmark is the state of the art, proportionate to the operator's capacity. All measures go into a resilience plan, for which the BBK provides templates.
  4. Reporting obligation (Section 18) also from ten months after registration. Incidents go to the joint reporting office of the BSI and the BBK: initial report without undue delay, at the latest 24 hours after becoming aware, detailed report at the latest one month after becoming aware.
  5. Management responsibility (Section 20) from ten months after registration. Management must implement the measures and monitor their implementation. In case of breach it is liable under company law.

Authorities can check implementation on a risk basis and request evidence and the resilience plan, including through audits (Section 16). Evidence already provided under other obligations is recognised as equivalent under Section 17. Fines are set out in Section 24, with a maximum of EUR 1 million.

Link to NIS 2 and the BSI Act

Germany's NIS 2 implementation act with the revised BSI Act (BSIG) has applied since 6 December 2025. The two laws interlock:

  • Shared definition. What counts as a critical facility is determined for both laws by the KRITIS Umbrella Act and its ordinance (Section 2 BSIG).
  • Clear division of tasks. The KRITIS Umbrella Act governs physical resilience. The BSIG governs cybersecurity. Pure IT security incidents within the meaning of the BSIG are not incidents under the Umbrella Act (Section 2 No. 9 KRITISDachG).
  • Dual classification. Under Section 28(1) BSIG, operators of critical facilities count as particularly important entities regardless of size. They must implement the cybersecurity measures under Section 30 BSIG and additionally use attack detection systems (Section 31(2) BSIG).
  • One registration, one reporting office. Registration runs through the joint BSI and BBK platform (Section 33(2) BSIG, Section 8 KRITISDachG). The reporting office is also joint, but the deadlines differ: 24 hours, 72 hours and one month under the BSIG, 24 hours and one month under the KRITISDachG.

In practice, an operator needs risk management that covers cyber and physical hazards together. A power outage, a fire in the server room and a ransomware attack end in the same problem: a service the population depends on fails.

The European side

The CER Directive should have been transposed by 17 October 2024. On 28 November 2024, the European Commission opened infringement procedures against 24 Member States, including Germany, for failing to transpose NIS 2 and CER. With the KRITIS Umbrella Act, Germany has now transposed the directive. The ordinance identifying the facilities is still outstanding.

What operators should do now

  1. Check scope in advance. Which of your facilities could fall under the ordinance by sector and supply level? Are you already an operator of a critical facility under the BSIG?
  2. Collect master data. Locations, supply areas, critical services, IP address ranges and contact point. Registration requires these details.
  3. Prepare an all-hazards risk analysis. Natural hazards, technical failures, sabotage, dependencies on suppliers and other sectors.
  4. Use existing evidence. An information security management system under ISO/IEC 27001:2022 and business continuity management under ISO 22301 cover parts of the requirements. Business continuity management (BCM) plans how critical processes keep running or restart quickly after a failure.
  5. Draft the resilience plan. Site protection, emergency power, crisis team, recovery and exercises in one document with clear owners.
  6. Merge reporting channels. One process for reports under the BSIG and the KRITISDachG, with deputies and 24/7 availability.
  7. Involve management. A resolution on responsibilities and budget, plus training for the leadership.

How GermanAI Defense supports you

We assess scope under the KRITIS Umbrella Act and the BSIG together, build the risk analysis and business continuity management under ISO 22301 and link both to your ISMS. On the cyber side, we provide a 24/7 SOC and penetration testing, so that attack detection and reporting channels hold up in an emergency.

→ More on our GRC and compliance consulting: germanaidefense.com/grc

Sources

As of 29 September 2026. This article is a professional overview and does not replace legal advice in individual cases.