{"id":17898,"date":"2026-03-16T09:00:00","date_gmt":"2026-03-16T09:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=17898"},"modified":"2026-07-09T17:15:29","modified_gmt":"2026-07-09T17:15:29","slug":"critical-roof-law-physical-cyber-resilience","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/03\/16\/critical-roof-law-physical-cyber-resilience\/","title":{"rendered":"KRITIS Umbrella Law: When Physical Resilience Becomes a Cyber Discipline"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">6 min. read<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\"><strong>Since 16 March 2026, Germany&#8217;s KRITIS Umbrella Act has been in force, giving the physical protection of critical infrastructure a nationwide framework for the first time. Around 1,300 operators must now harden their facilities against every conceivable threat &#8211; from natural disasters to deliberate sabotage. For security officers, this means the fence around the substation and the firewall in front of it now belong in the same risk assessment. Cyber and physical resilience are merging into a single discipline.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Physical protection becomes mandatory.<\/strong> The KRITIS Umbrella Act transposes the EU CER Directive and establishes nationwide minimum standards for the physical resilience of critical facilities for the first time.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Two pillars, one risk.<\/strong> Alongside the cyber regime under BSIG and NIS2, a physical pillar now stands in parallel. Germany is building both layers of protection simultaneously.<\/li>\n<li style=\"color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Responsibilities remain blurred.<\/strong> The BBK, BSI and Interior Ministry share oversight, and according to the Bundestag the boundaries between them have yet to be drawn clearly.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#b8c5ce;margin:20px 0 32px 0;border-top:1px solid rgba(230,227,218,0.12);border-bottom:1px solid rgba(230,227,218,0.12);padding:10px 0;\"><span style=\"color:#69d8ed;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/15\/kritis-umbrella-act-in-force-what-operators-of-critical-facilities-must-implement-by-july-2026\/\" style=\"color:#333;text-decoration:underline;\">KRITIS Umbrella Act in Force: What Operators Must Implement Now<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/04\/ransomware-resilience-why-german-companies-pay-less-often\/\" style=\"color:#333;text-decoration:underline;\">Ransomware Resilience: Why German Companies Are Paying Less Often<\/a><\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What the KRITIS Umbrella Act changes<\/h2>\n<p>Until 2026, the protection of critical infrastructure in Germany was fragmented. Cybersecurity was governed by the BSI Act; physical protection depended on a patchwork of sector-specific rules and state-level requirements. The KRITIS Umbrella Act consolidates this physical layer under a single national framework for the first time.<\/p>\n<p><strong>What is the KRITIS Umbrella Act?<\/strong> The KRITIS Umbrella Act is Germany&#8217;s transposition of EU Directive 2022\/2557 on the resilience of critical entities, known as the CER Directive. It obliges operators of critical facilities to strengthen their physical resilience against every type of hazard &#8211; natural disasters, technical failure, sabotage and terrorism alike. Reporting obligations and state supervision come with it.<\/p>\n<p>The scope is defined by a threshold of 500,000 people supplied per facility. This brings an estimated 1,300 operators within the law&#8217;s reach. The all-hazards approach is the real break from the past: operators can no longer tick off individual scenarios but must instead prepare their facilities against the entire spectrum of conceivable disruptions.<\/p>\n<div class=\"evm-stat-highlight\" style=\"text-align:center;background:#003340;border-radius:12px;padding:32px 24px;margin:32px 0;\">\n<div style=\"font-size:48px;font-weight:700;color:#69d8ed;letter-spacing:-0.03em;\">approx. 1,300<\/div>\n<div style=\"font-size:15px;color:#fff;margin-top:8px;max-width:430px;margin-left:auto;margin-right:auto;\">operators of critical facilities fall under the KRITIS Umbrella Act and must demonstrate their physical resilience.<\/div>\n<div style=\"font-size:12px;color:#69d8ed;margin-top:8px;\">Source: Bundestag \/ KRITIS Umbrella Act<\/div>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Physical Resilience Becomes a Cyber Discipline<\/h2>\n<p>The most striking effect of the law is not the new obligation itself, but its proximity to cybersecurity. Anyone operating a substation or a waterworks now faces two parallel regimes: the KRITIS Umbrella Act for physical protection and the BSIG with NIS2 for the digital side. Both demand risk analyses, reporting channels, and documentation. In practice, they are nearly impossible to separate.<\/p>\n<p>An attack on the power grid rarely starts with bolt cutters and ends in the data centre &#8211; or the other way around. Sabotage of hardware and intrusion into control software are simply two routes to the same destination. That is precisely why the division between physical and digital resilience is artificial. The KRITIS Umbrella Act forces operators to consolidate both dimensions into a single operational picture, and that changes who inside an organisation is actually responsible for security.<\/p>\n<p>With the KRITIS Umbrella Act and the cyber regime built around the BSIG and NIS2, Germany is implementing both pillars in parallel, each with its own legislation. The compliance burden is real, but it closes a gap that attackers have been deliberately exploiting.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Where Responsibilities Remain Blurred<\/h2>\n<p>As sensible as dual-layer protection is, its governance is far from clear. Under the KRITIS Umbrella Act, the Federal Office for Civil Protection and Disaster Assistance (BBK) becomes the supervisory authority for the physical pillar, while the BSI handles the cyber side and the Federal Ministry of the Interior provides overarching direction. The Bundestag itself has noted that the division of responsibilities between these bodies is not cleanly drawn.<\/p>\n<p>For operators, this is more than an administrative footnote. Anyone reporting an incident that touches both levels needs to know who to contact. Duplicate notifications, conflicting requirements, or gaps between authorities are a genuine risk as long as the interfaces between them remain undefined. The coming months of supervisory practice will show whether the roof actually holds.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What Operators Should Do Now<\/h2>\n<p>Regardless of the open questions around jurisdiction, there is every reason to start. Three steps make sense before regulators come knocking for the first time.<\/p>\n<p>First, build a unified operational picture: consolidate physical and cyber risks into a single analysis rather than maintaining them in separate departments. Second, clarify the reporting chain: define which type of incident goes to which authority and rehearse the process before it actually matters. Third, consolidate responsibility: as physical and digital security converge, a single function needs oversight of both sides &#8211; not two siloed teams pointing at each other when something goes wrong.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>When did the KRITIS Umbrella Act take effect?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The law entered into force on 16 March 2026. The Bundestag passed it on 29 January 2026, and the Bundesrat approved it on 6 March 2026. It transposes the EU&#8217;s CER Directive into national law.<\/p>\n<\/details>\n<details>\n<summary><strong>Who falls under the KRITIS Umbrella Act?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The law covers operators of critical facilities that supply at least 500,000 residents per installation. Estimates put the number of affected operators at around 1,300 &#8211; all of whom must demonstrate physical resilience.<\/p>\n<\/details>\n<details>\n<summary><strong>What distinguishes the Umbrella Act from NIS2?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The KRITIS Umbrella Act governs the physical protection of critical facilities; NIS2 and the BSIG govern cybersecurity. Both apply simultaneously, both require risk analyses and reporting obligations, and both hit many of the same operators at the same time.<\/p>\n<\/details>\n<details>\n<summary><strong>Which authority is responsible for supervision?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The BBK becomes the supervisory authority for the physical pillar; the BSI handles the cyber side. According to the Bundestag, the precise delineation between the bodies involved is still considered insufficiently defined.<\/p>\n<\/details>\n<details>\n<summary><strong>What should operators tackle first?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Build a unified operational picture combining physical and cyber risks, clarify and rehearse the reporting chain for each incident type, and consolidate responsibility for both security layers under a single function rather than maintaining them in separate silos.<\/p>\n<\/details>\n<h3>Editor&#8217;s Reading Tips<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/24\/zero-trust-at-the-energy-supplier-what-the-nis2-audits-are-now-revealing\/\">Zero Trust at Energy Utilities: What NIS2 Audits Are Revealing Now<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/20\/ot-security-2026-why-iec-62443-and-the-eu-cyber-resilience\/\">Zones and Conduits Become Mandatory in OT Environments<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/04\/ransomware-resilience-why-german-companies-pay-less-often\/\">Ransomware Resilience: Why German Companies Are Paying Less Often<\/a><\/li>\n<\/ul>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/24\/zero-trust-at-the-energy-supplier-what-the-nis2-audits-are-now-revealing\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/adaptive-mfa-nis2-bsi-zero-trust-mittelstand-fido2-2026-hero-250x167.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Zero Trust at the energy supplier: What the NIS2 audits are now revealing<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/20\/ot-security-2026-why-iec-62443-and-the-eu-cyber-resilience\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/04\/st-20-04-ot-security-iec-62443-cra-2026-250x167.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">OT Security: Why IEC 62443 &#038; EU Cyber Act Must Be Read Together<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/04\/ransomware-resilience-why-german-companies-pay-less-often\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/03\/ransomware-resilienz-reboot-germany-250x166.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Ransomware Resilience: Why German Companies Pay Less Frequently<\/span><\/span><\/a><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/22\/bsi-kritis-and-the-cloud-2026-nis2-the-umbrella-law-and-c\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-bsi-kritis-cloud-2026-nis2-dachgesetz-c5-90008061.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">BSI KRITIS and the Cloud 2026: NIS2, the Umbrella Law and C<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/hospital-digitalization-synaforce-connects-care\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-wie-synaforce-krankenhaeuser-transformie-89285657-250x156.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Hospital Digitalization: Synaforce Connects Care<\/span><\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/en\/industry-5-0-as-a-leadership-decision-key-takeaways-for-cios-from-hannover\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-industrie-5-0-als-fuehrungsentscheidung-61355365-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Industry 5.0 as a Leadership Decision: Key Takeaways for CIOs from Hannover Messe 2026<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n","protected":false},"excerpt":{"rendered":"KRITIS protection becomes physical: The umbrella law obliges around 1,300 operators to be resilient against all hazards.","protected":false},"author":50,"featured_media":17790,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"Critical Infrastructure Act","_yoast_wpseo_title":"KRITIS Umbrella Law: When Physical Resilience Becomes a Cyber Discipline","_yoast_wpseo_metadesc":"Protect KRITIS physically: New law mandates 1,300 operators to enhance resilience against all threats. Why cybersecurity and fences unite.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[3,2,259],"tags":[],"class_list":["post-17898","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aktuelles","category-innovation","category-strategie-governance-en"],"evm_reading_time_minutes":7,"wpml_language":"en","wpml_translation_of":17789,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17898","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=17898"}],"version-history":[{"count":3,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17898\/revisions"}],"predecessor-version":[{"id":21705,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17898\/revisions\/21705"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/17790"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=17898"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=17898"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=17898"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}