Ailance Alt TM Logo

KRITIS umbrella law: New requirements for operators of critical systems

The Kritis roof law brings new requirements.
Picture of  Aristotelis Zervos

Aristotelis Zervos

Aristotelis Zervos, Editorial Director at 2B Advice, combines legal and journalistic expertise in Data protection, IT-Compliance and AI regulation.

The KRITIS Framework Act (KRITIS-DachG) was adopted by the Federal Government in the fall of 2025 and passed by the Bundestag on January 29, 2026. The aim of the law is to establish uniform minimum requirements for the physical protection of critical infrastructure and to ensure their implementation through coordinated support and oversight measures. The regulations supplement existing IT security regulations by adopting an all-hazards approach. They thus provide protection against natural hazards, technical malfunctions, sabotage, terrorism, and other non-IT-related threats. Below is an overview of the key provisions of the KRITIS-DachG.

Definitions of terms: Critical service, Critical assets, Resilience, Incident

To enable companies to assess whether they are affected by the KRITIS-DachG, it is worth taking a look at central Definitions in the law:

  • Critical service: This refers to a service provided to the general public in specific sectors. These include energy, transportation and traffic, finance and insurance, social services (social insurance and basic social security), healthcare, water (drinking water/sewage), food, information technology and telecommunications, space infrastructure, and waste management. A failure or significant disruption of such a service would lead to supply shortages or threats to public safety.

  • Critical system: A facility is any place of business or installation (stationary or mobile). A facility is considered critical if it is essential to the provision of a critical service. Specifically, this means that if this facility fails, the essential service is at risk. Operators of critical facilities may be private-sector companies or public entities that have a decisive influence over the facility.

  • Resilience: The KRITIS Framework Act defines resilience as the ability of a critical infrastructure facility to prevent an incident, protect itself against it, defend against it, respond to it, mitigate its consequences, absorb the impact of the incident, and subsequently recover. It is therefore a holistic approach to resilience, ranging from preventive measures to emergency responses and the restoration of normal operations.

  • Incident: An incident, as defined by the KRITIS Framework Act, is an event that significantly impairs or could significantly impair the provision of a critical service. Important: Purely cyber incidents (IT security incidents) that fall under the BSI Act do not count as incidents as defined by this Act. The KRITIS-DachG primarily targets physical threats and traditional supply crises. Examples include natural disasters, widespread power outages, acts of sabotage, or failures due to human error, provided these significantly disrupt the supply. Cyberattacks remain subject to reporting and handling requirements under the BSIG, although there may, of course, be overlaps (e.g., combined attacks).

Obligations for Operators of Critical Infrastructure

The KRITIS Framework Act imposes extensive new obligations on operators of critical infrastructure. These are intended to ensure that they take measures to prevent and manage crises. In particular, these include:

  • Registration of systems and operators: All operators covered by the KRITIS Framework Act must register themselves and their critical infrastructure in a central registry maintained by the Federal Office for Civil Protection and Disaster Assistance (BBK). This is done via a joint online platform operated by the BBK and the BSI to avoid overlap with the existing BSIG registration. The registration includes information about the operator (name, legal form, contact information), the facility (location, industry, service area), and the critical service provided. A 24/7 point of contact must also be designated. Deadlines: Existing critical facilities must be registered by July 17, 2026, at the latest. New facilities must be reported within three months of their classification. If registration is not completed, the BBK may, after a hearing, enter the operator into the registry itself.

  • Risk analysis and risk assessment: Operators are required to conduct a systematic risk analysis of all hazards affecting their critical facilities on a regular basis. This analysis must consider all relevant risks: from natural hazards (e.g., floods, pandemics) to technical failures and intentional attacks. Based on this analysis, a risk assessment must be conducted to prioritize risks according to their probability of occurrence and potential impact. The EU directive requires that these operator risk analyses be completed within 9 months of identification. It is important that companies adapt their existing risk and BCM models to the all-hazards approach. Many industries already have standards for emergency and crisis management. These can be integrated and expanded.

Resilience Measures and Resilience Plan

Based on the risk analysis, appropriate and proportionate technical, organizational, and personnel measures must be taken to protect critical facilities. These range from structural security measures (e.g., access controls, redundant systems) to organizational measures (emergency plans, employee training, securing spare parts and fuel supplies) and cooperation with authorities and partners in the event of a crisis. All measures taken must be documented in a resilience plan. This plan outlines the company’s strategy for maintaining operations in the event of a crisis, the specified protective measures, and the results of the preceding risk analysis. The BBK provides samples and templates to assist companies in preparing this plan.

The resilience plan must be implemented and kept up to date. Regular reviews and adjustments to new threat scenarios are therefore mandatory.

Although all measures must be planned at the time of registration, some of them may still be in the process of being implemented. In any case, companies should begin planning early, as implementing and establishing a resilience strategy can be time-consuming.

Contact points and reporting obligation

  • Designation of contact points: As previously mentioned, the law requires each operator to designate a permanent point of contact. This is intended to ensure that authorities can quickly reach a contact person in the event of a crisis or suspected incident. In practice, this will usually be a 24/7 emergency hotline or a corresponding on-call service. The contact information must be provided at the time of registration and kept up to date at all times. For companies operating internationally, it may be advisable to establish a central point of contact internally for all KRITIS-related matters.

  • Mandatory Reporting of Significant Incidents: If an incident occurs despite all precautions, the reporting requirement under the KRITIS-DachG applies. Every significant incident must be reported to the competent authority immediately, no later than 24 hours after it is discovered. A joint reporting center operated by the BBK and the BSI will be established for this purpose. All incident reports are to be submitted through this central online portal. Duplicate reports (e.g., submitted separately to the BBK and (BSI) are thus avoided. If the initial report still contains incomplete information (which is typical in an emergency situation), it must be updated continuously in the event of ongoing disruptions.

    No later than one month after the incident becomes known, the operator must submit a detailed final report that examines the causes and all consequences.

    The content of reports must at least include the type and cause of the incident, the affected area, the duration and the extent of the disruption to supply (number of users affected, etc.). The BBK evaluates these incident reports and, if necessary, informs other member states or the EU Commission if the incident has cross-border significance. Important: This reporting obligation applies in addition to any sector-specific regulations. For example, energy suppliers may still have to inform the Federal Network Agency at the same time, healthcare services their supervisory authorities, etc., provided that corresponding requirements exist. However, the KRITIS-DachG does not create any public „naming and shaming“: reports are treated confidentially. Only if it is in the public interest can the BBK inform the public after hearing the operator, for example to warn the population.

In addition to these core obligations, the law provides for further requirements, such as participation in government resilience programs.

KRITIS supervision

Compliance with these obligations is monitored through a multi-tiered supervisory system. The Federal Office for Civil Protection and Disaster Assistance (BBK) serves as the central point of contact. Depending on the sector, various competent authorities are also designated: the Federal Network Agency for Electricity, Gas, Hydrogen, and Telecommunications; the Federal Railway Authority for rail transport; the Federal Office for Information Security (BSI) for IT/telecommunications services, the federal and state health ministries for healthcare facilities, etc.

The relevant authorities are working closely with the BBK and the BSI to avoid overlap. For example, there will be a joint reporting center, and the BBK and BSI will also coordinate their efforts through an online platform and standardized procedures when it comes to registration and auditing.

The authorities have broad powers to monitor the implementation of resilience measures. They may request evidence and information from operators, such as access to the resilience plan or internal documentation. In doing so, the supervisory authorities take a risk-based approach: targeted inspections are primarily conducted at companies whose size, risk exposure, or potential impact is particularly high.

Operators must, upon request, Audit-Submit results if they have had external audits conducted. The agency may conduct its own on-site inspections or engage independent Third to do so. Companies are obliged to grant the inspectors access to operating rooms, relevant systems and facilities and to provide information. If deficiencies are identified, the authority can oblige the operator to submit a plan to rectify the deficiencies within a certain period of time and to implement the corresponding measures.

Reading tip: DORA Guidelines on the Oversight of Critical Third-Party Providers

Liability and Penalties for KRITIS Violations

Liability of the management: Section 20 KRITIS-DachG, which emphasizes the responsibility of company management, is noteworthy. The management of an operator (i.e. the board of directors, management or comparable bodies) is obliged to implement resilience measures and anchor them in the organization. If the management culpably neglects this duty, it is liable to the company for any damage incurred. This civil law Liability applies on a supplementary basis, unless corporate law provisions (such as due diligence obligations under stock corporation law) already apply to such cases. For decision-makers, this means that resilience is a top priority. Anyone who deliberately ignores these requirements risks personal liability claims. Similar to what is known from data protection or labor law, where Compliance-violations as well, a Liability of the management.

Administrative Offenses and Fines: To ensure compliance, the law includes a schedule of fines. Violations—such as failure to register, failure to conduct a risk analysis, lack of a resilience plan, or failure to report an incident—are subject to substantial fines. The maximum amounts are tiered according to the severity of the violation at €50,000, €100,000, €200,000, and €500,000, respectively. The maximum fine of €500,000 is likely to apply in cases of gross or repeated breaches of duty (e.g., complete disregard for resilience requirements). In addition, any intentional violation of official orders may be considered Administrative offense will be punished. This increases the pressure.

Industry-specific consequences: Regardless of the KRITIS Framework Act, sector-specific supervisory powers remain in effect. In highly regulated sectors (energy, telecommunications, transportation, etc.), flagrant failure to comply with security obligations could result in regulatory measures, including the revocation of licenses. This would be a last resort and is not explicitly provided for in the KRITIS-DachG. However, an energy provider that persistently violates security requirements could ultimately risk losing its operating license.

Overall, however, the legislature is signaling that the new obligations must be taken seriously, both through fines and by emphasizing management responsibility.

Source: Act Implementing Directive (EU) 2022/2557 and Strengthening the Resilience of Critical Infrastructure (KRITIS Framework Act)

Kritis makes resilience a top priority

The KRITIS Framework Act imposes new and quite demanding obligations on critical enterprises: from registration and risk analyses to reporting processes. At the same time, it offers the opportunity to bring an organization’s crisis management up to date and fortify it against a wide range of threats.

Decision-makers should take a proactive approach, use official guidelines, and implement changes step by step. With good planning and support, the requirements can be met, ultimately increasing the security of supply and ensuring legal compliance. The motto is: „Resilience is achievable if you make it a top priority and get everyone on board.”

Are you an operator of critical infrastructure, or do you suspect that your company falls within the scope of the KRITIS umbrella law? If so, it’s worth seeking clarity early on and beginning the implementation process in a structured manner. 2B Advice provides you with practical support: from assessing impact to establishing an organizational structure to creating an audit-ready Documentation.

We help you in particular with

  • Scope & impact analysis (critical services, critical infrastructure, dependencies, interfaces with BSIG/NIS-2)
  • Risk analysis & risk assessment based on the all-risk approach (methodologically sound, providing a basis for management decisions)
  • Resilience plan & program of measures (prioritization, implementation path, governance, evidence)
  • Reporting processes & crisis organization (24-hour reporting protocol, templates, exercises, communication plan)
  • Audit-Readiness (Record-keeping, internal controls, preparation for regulatory audits/on-site inspections)


If you’d like, we can schedule a brief initial consultation to assess your current situation and develop a concrete roadmap. Just send us a message—and we’ll get back to you shortly with an assessment of which next steps will have the greatest impact for your company.

Aristotelis Zervos is Editorial Director at 2B Advice, a lawyer and journalist with profound expertise in data protection, GDPR, IT-Compliance and AI governance. He regularly publishes in-depth articles on AI regulation, GDPR-Compliance and risk management. You can learn more about him on his Author profile page.

Picture of Marcus Belke

Marcus Belke

Marcus Belke is the CEO of 2B Advice GmbH. He drives innovation in data protection compliance and risk management and is responsible for the further development of Ailance, the next-generation compliance platform.

Share this post:

KRITIS umbrella law: New requirements for operators of critical systems