THREAT BRIEFING · 23.09.2026 DEENFRES

News

KRITIS Umbrella Law: When Physical Resilience Becomes a Cyber Discipline

By Benedikt Langer · March 16, 2026 · 7 min read

Since 16 March 2026, Germany’s KRITIS Umbrella Act has been in force, giving the physical protection of critical infrastructure a nationwide framework for the first time. Around 1,300 operators must now harden their facilities against every conceivable threat – from natural disasters to deliberate sabotage. For security officers, this means the fence around the substation and the firewall in front of it now belong in the same risk assessment. Cyber and physical resilience are merging into a single discipline.

Key Takeaways

  • Physical protection becomes mandatory. The KRITIS Umbrella Act transposes the EU CER Directive and establishes nationwide minimum standards for the physical resilience of critical facilities for the first time.
  • Two pillars, one risk. Alongside the cyber regime under BSIG and NIS2, a physical pillar now stands in parallel. Germany is building both layers of protection simultaneously.
  • Responsibilities remain blurred. The BBK, BSI and Interior Ministry share oversight, and according to the Bundestag the boundaries between them have yet to be drawn clearly.

Related:KRITIS Umbrella Act in Force: What Operators Must Implement Now  /  Ransomware Resilience: Why German Companies Are Paying Less Often

What the KRITIS Umbrella Act changes

Until 2026, the protection of critical infrastructure in Germany was fragmented. Cybersecurity was governed by the BSI Act; physical protection depended on a patchwork of sector-specific rules and state-level requirements. The KRITIS Umbrella Act consolidates this physical layer under a single national framework for the first time.

What is the KRITIS Umbrella Act? The KRITIS Umbrella Act is Germany’s transposition of EU Directive 2022/2557 on the resilience of critical entities, known as the CER Directive. It obliges operators of critical facilities to strengthen their physical resilience against every type of hazard – natural disasters, technical failure, sabotage and terrorism alike. Reporting obligations and state supervision come with it.

The scope is defined by a threshold of 500,000 people supplied per facility. This brings an estimated 1,300 operators within the law’s reach. The all-hazards approach is the real break from the past: operators can no longer tick off individual scenarios but must instead prepare their facilities against the entire spectrum of conceivable disruptions.

approx. 1,300
operators of critical facilities fall under the KRITIS Umbrella Act and must demonstrate their physical resilience.
Source: Bundestag / KRITIS Umbrella Act

Physical Resilience Becomes a Cyber Discipline

The most striking effect of the law is not the new obligation itself, but its proximity to cybersecurity. Anyone operating a substation or a waterworks now faces two parallel regimes: the KRITIS Umbrella Act for physical protection and the BSIG with NIS2 for the digital side. Both demand risk analyses, reporting channels, and documentation. In practice, they are nearly impossible to separate.

An attack on the power grid rarely starts with bolt cutters and ends in the data centre – or the other way around. Sabotage of hardware and intrusion into control software are simply two routes to the same destination. That is precisely why the division between physical and digital resilience is artificial. The KRITIS Umbrella Act forces operators to consolidate both dimensions into a single operational picture, and that changes who inside an organisation is actually responsible for security.

With the KRITIS Umbrella Act and the cyber regime built around the BSIG and NIS2, Germany is implementing both pillars in parallel, each with its own legislation. The compliance burden is real, but it closes a gap that attackers have been deliberately exploiting.

Where Responsibilities Remain Blurred

As sensible as dual-layer protection is, its governance is far from clear. Under the KRITIS Umbrella Act, the Federal Office for Civil Protection and Disaster Assistance (BBK) becomes the supervisory authority for the physical pillar, while the BSI handles the cyber side and the Federal Ministry of the Interior provides overarching direction. The Bundestag itself has noted that the division of responsibilities between these bodies is not cleanly drawn.

For operators, this is more than an administrative footnote. Anyone reporting an incident that touches both levels needs to know who to contact. Duplicate notifications, conflicting requirements, or gaps between authorities are a genuine risk as long as the interfaces between them remain undefined. The coming months of supervisory practice will show whether the roof actually holds.

What Operators Should Do Now

Regardless of the open questions around jurisdiction, there is every reason to start. Three steps make sense before regulators come knocking for the first time.

First, build a unified operational picture: consolidate physical and cyber risks into a single analysis rather than maintaining them in separate departments. Second, clarify the reporting chain: define which type of incident goes to which authority and rehearse the process before it actually matters. Third, consolidate responsibility: as physical and digital security converge, a single function needs oversight of both sides – not two siloed teams pointing at each other when something goes wrong.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

When did the KRITIS Umbrella Act take effect?

The law entered into force on 16 March 2026. The Bundestag passed it on 29 January 2026, and the Bundesrat approved it on 6 March 2026. It transposes the EU’s CER Directive into national law.

Who falls under the KRITIS Umbrella Act?

The law covers operators of critical facilities that supply at least 500,000 residents per installation. Estimates put the number of affected operators at around 1,300 – all of whom must demonstrate physical resilience.

What distinguishes the Umbrella Act from NIS2?

The KRITIS Umbrella Act governs the physical protection of critical facilities; NIS2 and the BSIG govern cybersecurity. Both apply simultaneously, both require risk analyses and reporting obligations, and both hit many of the same operators at the same time.

Which authority is responsible for supervision?

The BBK becomes the supervisory authority for the physical pillar; the BSI handles the cyber side. According to the Bundestag, the precise delineation between the bodies involved is still considered insufficiently defined.

What should operators tackle first?

Build a unified operational picture combining physical and cyber risks, clarify and rehearse the reporting chain for each incident type, and consolidate responsibility for both security layers under a single function rather than maintaining them in separate silos.

Editor’s Reading Tips

Editor’s Picks

Editor’s PickZero Trust at the energy supplier: What the NIS2 audits are now revealingEditor’s PickOT Security: Why IEC 62443 & EU Cyber Act Must Be Read TogetherEditor’s PickRansomware Resilience: Why German Companies Pay Less Frequently

More from the MBF Media Network

cloudmagazinBSI KRITIS and the Cloud 2026: NIS2, the Umbrella Law and CMyBusinessFutureHospital Digitalization: Synaforce Connects CareDigital ChiefsIndustry 5.0 as a Leadership Decision: Key Takeaways for CIOs from Hannover Messe 2026

Further reading

A magazine by Evernine Media GmbH