KRITIS Act: What Critical Operators Must Do by July 2026
With the decision of the Bundesrat on March 6, 2026, the KRITIS Umbrella Act has finally come into force. For around 2,000 operators of critical infrastructures in Germany, the countdown begins now: By July 17, 2026, they must register with the Federal Office of Civil Protection and Disaster Assistance (BBK) – and prove much more than just IT security. For the first time, the law requires a cross-sectoral physical and organizational protection that goes far beyond the previous NIS2 requirements.
Key Takeaways
- The KRITIS Umbrella Act was passed by the Bundesrat on March 6, 2026, and will come into force gradually – first mandatory registration by July 17, 2026
- Around 2,000 operators of critical facilities in 11 sectors are affected – from energy to health and transport
- For the first time, physical protection measures, business continuity management, and reporting obligations are legally prescribed across sectors
- The KRITIS Umbrella Act complements NIS2: While NIS2 governs digital cybersecurity, the Umbrella Act addresses physical and organizational resilience
- Operators should now start with a GAP analysis and prepare for mandatory registration – those who miss the deadlines risk fines of up to 10 million euros
What the KRITIS Umbrella Act Regulates – and Why It’s Coming Now
The EU Directive on the Resilience of Critical Entities (CER Directive, 2022/2557) obliges all member states to create national regulations for the physical protection of critical infrastructures. Germany is implementing this requirement with the KRITIS Umbrella Act – the first federal law that makes physical security and organizational resilience binding across sectors.
So far, in Germany, the protection of critical infrastructures has primarily been regulated by the BSI in the digital domain (IT Security Act, now NIS2). Physical risks such as sabotage, natural disasters, or supply shortages were regulated on a sector-specific basis or not at all. The attacks on the Nord Stream pipelines in 2022, targeted sabotage against railway infrastructure, and the increasing hybrid threat situation have massively increased political pressure.
The result is a law that bundles physical security, personnel protection, crisis management, and reporting obligations into a single set of regulations – and deliberately goes beyond the realm of pure IT security.
“Critical infrastructures are the backbone of our society. Their protection is a national task that must consider both physical and digital resilience.”Federal Ministry of the Interior, on the adoption of the KRITIS Umbrella Act
Overview of the 11 KRITIS Sectors
The KRITIS Umbrella Act defines eleven sectors that are considered critical infrastructure. For each sector, the BBK sets specific threshold values above which an operator falls under regulation:
● Energy: Electricity, gas, oil, district heating – generation, transport, and distribution. In addition to large suppliers, municipal utilities and grid operators above the threshold values are also affected.
● Transport and Traffic: Airports, ports, rail infrastructure, and road traffic. The sabotage acts against Deutsche Bahn have shown how vulnerable this sector is.
● Banking and Financial Market Infrastructure: Systemically important banks and stock exchange infrastructure. There is significant overlap with DORA here.
● Health: Hospitals, laboratories, pharmaceutical companies, and medical device manufacturers above the threshold values.
● Drinking Water and Wastewater: Water supply and wastewater disposal – a sector particularly dependent on physical security.
● Digital Infrastructure: Data centers, DNS services, IXPs – strongly overlapping with NIS2, here the KRITIS Umbrella Act applies additionally on a physical level.
● Public Administration: Authorities at federal and state level, if they provide critical services.
● Space: Satellite infrastructure and ground facilities – a sector explicitly included only through the CER Directive.
● Food: Production, processing, and distribution of food on a large scale.
● Production: Manufacture of critical goods – such as medical devices, electronics, or chemicals.
● Research: Research institutions relevant to public safety or supply.
KRITIS Umbrella Act vs. NIS2: What Regulates What?
The distinction between the KRITIS Umbrella Act and NIS2 is the central question operators need to understand. Both laws affect some of the same companies – but regulate different risk areas.
NIS2 (implemented in Germany through the NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz) governs digital cybersecurity: network security, incident response, vulnerability management, secure supply chains in the IT sector. The KRITIS Umbrella Act, on the other hand, addresses physical and organizational resilience: perimeter protection, access controls, personnel screenings, business continuity management, and crisis communication.
„Those who view NIS2 as a pure IT project and the KRITIS Umbrella Act as a pure facility issue will miss both compliance targets. The laws interlock – and require an integrated resilience strategy.“
In practice, this means: An energy supplier must demonstrate NIS2-compliant IT security as well as meet the physical protection requirements of the KRITIS Umbrella Act. The good news: Those who already operate a functional ISMS according to ISO 27001 have a solid foundation. The bad news: Physical security, BCM, and personnel screenings are not at the level required by the law in many companies.
A comprehensive overview of the NIS2 requirements is provided in our article NIS2 in Deutschland: Was Unternehmen jetzt wissen und umsetzen müssen.
The Five Core Obligations of the KRITIS Umbrella Act
The law defines five central areas of obligation that every affected operator must fulfill:
1. Mandatory Registration with the BBK
By July 17, 2026, all operators of critical infrastructure must register with the Federal Office for Civil Protection and Disaster Assistance (BBK). The registration includes information on the operated facilities, the critical services provided, and the existing protective measures. The BBK will create a national overview of all KRITIS operators based on this registration – for the first time with such comprehensiveness.
2. Risk Assessment and Resilience Planning
Operators must conduct a comprehensive risk assessment that covers not only cyber risks but also physical threats: natural disasters, sabotage, terrorism, pandemics, and supply shortages. Based on this assessment, a resilience plan must be created that defines specific protective measures.
3. Physical Protective Measures
The law requires technical, organizational, and personnel measures for physical protection: perimeter security, access control systems, video surveillance, detection systems, and structural protective measures. The scope is determined by the criticality of the facility and the result of the risk assessment.
4. Business Continuity Management (BCM)
Operators must establish a BCM system that ensures the continuity of critical services even in the event of disruptions and failures. This includes business impact analyses, emergency plans, restart procedures, and regular exercises. The BCM standard ISO 22301 serves as a guideline here.
5. Reporting Obligations
Security incidents that impair or could impair the provision of critical services must be reported to the BBK. The initial report must be made within 24 hours, and a detailed report within 72 hours. There are parallels to the NIS2 reporting obligations at the BSI – however, with different reporting systems and contact persons.
Personnel Screening: The Underestimated Effort
One area that many operators have not yet considered is personnel screening. The KRITIS umbrella law provides that employees in security-relevant areas undergo a reliability check. This not only affects their own personnel but also service providers and contractors who have access to critical facilities.
The details of the check will be regulated in a separate legal ordinance. However, it is already clear: operators must establish processes that ensure that only checked persons gain access to security-relevant areas. In industries with high personnel turnover or many external service providers – such as logistics or healthcare – this is a significant organizational effort.
The Roadmap: What Needs to be Done and by When
The implementation of the KRITIS umbrella act follows a staggered timeline. Here are the key milestones:
● March 2026 – Immediate: Check if your company falls under the KRITIS definition. The thresholds will be defined in the law’s implementing regulation – drafts are already available.
● April-May 2026: Conduct a GAP analysis. Which of the five core obligations are already covered (e.g., through ISO 27001, ISO 22301, or industry-specific regulation)? Where are there gaps?
● June 2026: Prepare registration documents. Registration with the BBK requires detailed information on facilities, services, and protective measures – this is not a form to be filled out in an hour.
● July 17, 2026: Mandatory registration deadline. From this date, all affected operators must be registered with the BBK.
● Q3-Q4 2026: Create a risk assessment and resilience plan. The BBK will provide guidelines and templates – but operational implementation is the operator’s responsibility.
● 2027: First checks by the BBK. The Federal Office can conduct audits and demand improvements if necessary.
Leveraging Synergies with Existing Standards
The good news for companies that are already regulated or voluntarily work according to recognized standards: Many requirements of the KRITIS umbrella act can be covered by existing management systems.
● ISO 27001 (ISMS): Covers risk assessment, access controls, and incident management – primarily for information security, though. Physical security is only partially covered (Annex A.7 and A.11).
● ISO 22301 (BCM): Directly applicable to the BCM requirements of the KRITIS umbrella act. Business impact analysis, recovery strategies, and exercises are already defined here.
● BSI Baseline Protection: The BSI Compendium contains modules for physical security (INF modules) and emergency management that can be directly mapped to KRITIS requirements.
● Industry-specific standards: EnWG (energy), IT-SRRL (telecommunications), or KHG (hospitals) already contain sector-specific security requirements that can serve as a basis.
Companies that consistently utilize these standards can significantly reduce the implementation effort for the KRITIS umbrella act. The key lies in integration: A unified management system that combines physical security, IT security, and BCM under one roof, rather than running three parallel compliance projects.
„Companies that see the KRITIS umbrella act as an opportunity to consolidate their overall resilience strategy will ultimately have less effort than those that just tick off the minimum requirements.“
Fines and Liability: Consequences of Non-Compliance
The KRITIS Umbrella Act provides for severe penalties. Operators who fail to register, conduct risk assessments, or comply with reporting obligations risk fines of up to 10 million euros. This is on par with NIS2 – underscoring the seriousness of the regulation.
Moreover, the management is personally liable for compliance with the regulations. Managing directors and board members can be held accountable for breaches of duty. This personal liability is a strong incentive not to delegate the issue to a specialist department and forget about it.
How companies can protect themselves against the financial consequences of security incidents is explored in our article Cyber Insurance 2026: What Companies Need to Know.
Concrete Recommendations for Operators
What should affected companies do now? Here is a pragmatic action plan:
● Start impact analysis immediately: Check whether your company falls under the law based on the sector definitions and thresholds. If in doubt, consult the BBK – it’s better to ask too many questions than to miss the registration deadline.
● Define responsibilities: The KRITIS Umbrella Act requires a designated resilience officer. Clarify now who will take on this role and what authority and resources the person will have.
● GAP analysis against the five core obligations: Use the five duty areas as a checklist and honestly assess where your company stands. Physical security and personnel screening are often underdeveloped in many companies.
● Leverage NIS2 synergies: If you are already working on NIS2 implementation, integrate the KRITIS requirements into the same project framework. Duplicate work can be avoided if the governance structure is right.
● Involve suppliers and service providers: Physical security does not end at the factory gate. Check which external service providers have access to critical facilities and start personnel screenings.
● Secure budget early: Building BCM, physical protection measures, and personnel screenings cost money. Those who start the budgeting process only in June 2026 will not meet the July deadline.
Outlook: KRITIS Protection as a Competitive Factor
The KRITIS Umbrella Act is more than just another compliance requirement. It forces companies to systematically address their resilience – at a time when hybrid threats, geopolitical tensions, and climate events demonstrate the vulnerability of critical infrastructures daily.
Companies that use the law as an opportunity to raise their physical and organizational security to a professional level will not only be compliant. They will also fare better in tenders, insurance premiums, and customer trust than competitors who only meet the minimum requirements.
The deadline is approaching: July 17, 2026. That’s four months away. Those who don’t start now won’t finish on time. Read about more cybersecurity trends shaping 2026 in our overview Cybersecurity Trends 2026: Seven Developments.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
Who is affected by the KRITIS Umbrella Act?
Operators of critical facilities in eleven sectors that exceed certain thresholds: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, food, production, and research. In total, around 2,000 operators in Germany are affected.
What is the difference between the KRITIS umbrella law and NIS2?
NIS2 regulates digital cybersecurity (networks, IT systems, incident response). The KRITIS umbrella law addresses physical and organizational resilience (perimeter protection, BCM, personnel checks, crisis communication). Both laws can apply to the same company and complement each other.
What are the specific deadlines?
The mandatory registration with the BBK must be completed by July 17, 2026. Risk assessments and resilience plans must be created subsequently, with initial audits by the BBK planned for 2027. The exact deadlines for individual measures will be specified in the law’s implementing regulation.
What happens in case of non-compliance with the KRITIS umbrella law?
Fines of up to 10 million Euro are possible. Additionally, the management is personally liable for compliance with the regulations. The BBK can conduct audits and order corrective measures in case of deficiencies.
How are the KRITIS umbrella law and DORA related?
DORA (Digital Operational Resilience Act) is considered lex specialis for the financial sector and addresses digital operational resilience. The KRITIS umbrella law may also apply if a financial institution is classified as a KRITIS operator – for example, in the case of systemically relevant banks or exchange infrastructure. In this case, both sets of regulations must be fulfilled in parallel.
Editor’s Reading Recommendations
- NIS2 in Germany: What companies need to know and implement now
- Supply Chain Security 2026: How companies protect their software supply chain
- DORA: BaFin audits financial institutions – MyBusinessFuture
Editor’s Picks
Editor’s PickSupply Chain Security 2026: Protecting Software Supply Chains
More from the MBF Media Network
cloudmagazinFinOps: How Companies Finally Gain Control Over Cloud CostsDigital ChiefsAI Governance 2026: System‑Level, Not Excel ComplianceMyBusinessFuturePSD3 in SMEs: Preparing Finance Chiefs for Banking APIs
Further reading
WithSecure: From Antivirus Pioneer to Cloud Security Specialist
WithSecure has been F-Secure’s B2B spin-off since 1 July 2022. Its Elements platform, co-security services and European data-protection focus aim to give security teams …
Shadow AI Often Emerges Due to Governance Itself
Shadow AI: 40% already avoided it because approvals are useless. Patricia Leppert (TeamViewer) in an interview on risks, fake AI, and CISO measures.
NIS2 Patchwork: Four States Face EU Court
The EU Commission sues Ireland, Spain, France, and the Netherlands over incomplete NIS2 implementation. What this means for CISOs.



