THREAT BRIEFING · 10.09.2026 DEENFRES

Security Glossary

What Is Critical Infrastructure? Operators, Duties & Thresholds

By Alec Chizhik · July 14, 2026 · 6 min read

6 Min. read time

KRITIS obligations do not start with a label, but with the question of which supply would be jeopardized by a failure and how operators inform the BSI.

What is KRITIS (critical infrastructures)? KRITIS stands for critical infrastructures, i.e., organizations and facilities of central importance to the state’s public sphere. If their operation fails or is disrupted, persistent supply bottlenecks or threats to public safety arise. Who is considered an operator is regulated in Germany by the BSI Act (BSI-Gesetz) together with the BSI‑Kritis Ordinance (BSI-Kritisverordnung).

Key Takeaways

  • Who is affected: Operators in ten sectors from energy to state and administration, as soon as they exceed defined thresholds.
  • Core duty: Appropriate technical and organizational measures according to the state of the art, plus a reporting obligation for significant incidents to the BSI.
  • Context: KRITIS is the German framework for cybersecurity in supply. NIS2 and the planned KRITIS‑Dachgesetz (proposed KRITIS umbrella law) expand it, but do not replace it.

Which Sectors Does KRITIS (Critical Infrastructure) Cover

The legislator assigns critical infrastructure to ten sectors: Energy, Water, Food, Information Technology and Telecommunications, Health, Financial and Insurance Services, Transport and Logistics, Waste Management, as well as State and Administration, and the Media and Culture sector. What matters is not the industry alone, but the supply relevance of each facility.

Whether a company falls under these rules depends on thresholds. The BSI (Federal Office for Information Security) KRITIS regulation defines concrete thresholds for each type of facility, often measured by the number of people served. The benchmark threshold is 500,000 people served. Companies exceeding this figure are considered operators under the law.

10 Sectors

From Energy to State and Administration, Germany’s legal classification of critical infrastructure spans ten sectors

Source: BSI KRITIS Regulation

What Obligations Operators Face

Operators must implement appropriate organizational and technical measures to prevent disruptions to the availability, integrity, authenticity, and confidentiality of their systems. The benchmark is the state of the art. These measures must be regularly demonstrated to the BSI (Federal Office for Information Security), in practice every two years.

Additionally, there is a reporting obligation. Significant disruptions that could cause a failure or impairment of a critical service must be reported to the BSI. The BSI aggregates these reports into a situational overview and issues warnings to other operators.

Initial Steps for Potential Operators

  • Check facilities against the thresholds of the BSI Critical Infrastructure Regulation
  • Designate and register a contact point with the BSI
  • Establish and document proof procedures according to the state of the art
  • Set up and practice a reporting process for significant incidents

How KRITIS, NIS2, and the Framework Law Interrelate

KRITIS has overseen the security of critical infrastructure for years. The EU directive NIS2 expands the scope of regulated entities significantly and tightens reporting and leadership obligations. Germany transposes it into national law through the NIS2 Implementation Act, incorporating the existing KRITIS framework.

At the same time, the proposed KRITIS framework law addresses the physical protection of critical infrastructure, such as against sabotage or natural disasters. Cyber and physical resilience thus coalesce into a unified duty framework. For operators, this means they should view the three regulations as a single system rather than separate projects.

What Happens if You Breach the Rules

The obligations under the KRITIS framework are no paper tiger. If an operator fails to meet its proof or reporting obligations, BSI can issue directives and impose fines. With the NIS2 Implementation Act, the scope of possible sanctions increases significantly and is tied to revenue size, similar to what the General Data Protection Regulation introduced.

A new element is especially the responsibility of senior management. NIS2 explicitly holds the executive board accountable for approving risk‑management measures and monitoring their implementation. Security thus becomes a management issue rather than just an IT concern. Those who address the requirements early and structure them properly not only reduce cyber risk but also their personal liability.

How Operators Prepare Structuredly

The path to KRITIS (Critical Infrastructure) compliance rarely starts from scratch. Many operators already have an information security management system (ISMS), such as ISO 27001 or IT-Grundschutz (a German IT security baseline), which serves as a foundation. A sensible approach is an honest maturity assessment: Where does the existing security organization already meet the requirements, and where are there gaps in reporting channels, evidence, or the protection of individual facilities?

Exchanging with other operators is helpful. Through the UP KRITIS platform (a platform for critical infrastructure operators), government and industry collaborate across sectors and share experiences on threats and protective measures. Those who use this framework do not have to reinvent the wheel alone and can learn early which attacks are currently relevant in their sector.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

From when is my company a critical infrastructure operator (KRITIS)?

As soon as a facility exceeds the thresholds set out in the BSI-Critical Infrastructure Regulation. These thresholds vary by sector and plant type and are often based on the number of people supplied.

What is the difference between KRITIS and NIS2?

KRITIS (Critical Infrastructure) refers to the existing German framework for particularly critical facilities. NIS2 (Network and Information Systems Directive 2) is the EU directive that expands the scope of regulated entities and is transposed into German law through the national implementing act.

Which authority is responsible?

Critical infrastructure cybersecurity falls under the purview of the Federal Office for Information Security, abbreviated BSI. There, documentation and incident reports converge.

How often must the proof be provided?

Operators regularly verify the measures taken, in practice every two years. Proof is typically provided through security audits, inspections or certifications.

What is the KRITIS roof law?

A proposed law that consolidates the physical protection of critical infrastructure and supplements existing cybersecurity obligations with resilience against physical threats.

Lesetipps der Redaktion

LesetippWelche Entscheidungsrechte des CISO schriftlich geregelt sein müssenLesetippLieferkettenrisiko ist ein Programm, keine Audit-ListeLesetippWas die Geschäftsführung unter NIS2 dokumentieren muss

Mehr aus dem MBF Media Netzwerk

Digital ChiefsGeopolitik trifft die Datacenter-Roadmap: Was CIOs jetzt absichernMyBusinessFutureEU AI Act: Was der Mittelstand kennzeichnen musscloudmagazinXFS4IoT trifft Cloud: Der Geldautomat wird Plattform

Bildquelle: KI-generiert (Juli 2026)

Further reading

A magazine by Evernine Media GmbH