{"id":17955,"date":"2026-06-20T11:37:57","date_gmt":"2026-06-20T11:37:57","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=17955"},"modified":"2026-06-20T17:13:09","modified_gmt":"2026-06-20T17:13:09","slug":"critical-roof-law-physical-resilience-ciso","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/06\/20\/critical-roof-law-physical-resilience-ciso\/","title":{"rendered":"KRITIS-Dachgesetz: When Resilience Becomes a CISO&#8217;s Mandatory Duty"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">7 Min. Reading Time<\/p>\n<p><strong>As of March 17, 2026, the KRITIS umbrella law has come into effect. For the first time, uniform federal minimum standards apply to the physical protection of critical facilities, parallel to the cyber regime of the BSI Act. For CISOs, this means a shift: resilience can no longer be divided into an IT column and a building column.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;\"><strong style=\"color:#69d8ed;\">New legal framework since March 2026:<\/strong> The KRITIS umbrella law implements the EU Directive 2022\/2557 (CER) and obliges operators in ten sectors to physical resilience, from risk analysis to incident reporting.<\/li>\n<li style=\"margin-bottom:12px;\"><strong style=\"color:#69d8ed;\">Two pillars, one risk model:<\/strong> Cybersecurity according to the BSI Act and physical protection according to the umbrella law are interlinked. Those who manage both separately overlook the attacks that target exactly the seam.<\/li>\n<li><strong style=\"color:#69d8ed;\">The threshold is disputed:<\/strong> The standard threshold of 500,000 served inhabitants per facility is considered too high by many countries. Those just below it still check their own criticality, as it can also be determined independently of the threshold.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#666;margin:20px 0 32px 0;border-top:1px solid #e5e5e5;border-bottom:1px solid #e5e5e5;padding:10px 0;\"><span style=\"color:#004a59;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/24\/zero-trust-at-the-energy-supplier-what-the-nis2-audits-are-now-revealing\/\" style=\"color:#333;text-decoration:underline;\">Zero Trust for Energy Suppliers<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/22\/dora-and-nis2-why-bank-audits-are-now-colliding\/\" style=\"color:#333;text-decoration:underline;\">DORA and NIS2 in Double Audit<\/a><\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What the KRITIS Umbrella Law Demands from Operators<\/h2>\n<p><strong>What is the KRITIS umbrella law?<\/strong> The KRITIS umbrella law is the first uniform federal legal framework for the physical protection of critical infrastructures in Germany. It implements the European CER Directive 2022\/2557 and obliges operators in ten sectors, including energy, water, healthcare, food supply, and transportation, to uniform minimum standards for the resilience of their facilities.<\/p>\n<p>Concretely, this means: affected operators must register with the competent authority, regularly conduct a risk analysis and risk assessment, implement technical and organizational resilience measures, and report significant disruptions. The specific design of individual procedures will be specified through subsequent ordinances. The classification is based on a standard threshold of 500,000 served inhabitants per facility. However, criticality can also be determined below this threshold if the failure would endanger a critical service.<\/p>\n<p>The parliamentary process was short and intense. The Bundestag passed the law on January 29, 2026, the Bundesrat approved it on March 6, and it was published in the Federal Law Gazette on March 16. Operators therefore have less time to prepare than the multi-year discussion might have suggested.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Two pillars that belong together<\/h2>\n<p>For those responsible for security, the actual innovation is not the physical regulatory framework itself, but its coupling to the existing cyber regime. As a large EU country, Germany is developing both pillars in parallel. Both are aimed at the same facility.<\/p>\n<div class=\"comparison\" style=\"overflow-x:auto;-webkit-overflow-scrolling:touch;margin:16px 0 32px 0;\">\n<table class=\"comparison\" style=\"width:100%;min-width:560px;border-collapse:collapse;font-size:0.95em;\">\n<thead>\n<tr style=\"background:#003340;color:#fff;\">\n<th style=\"padding:12px 16px;text-align:left;border:1px solid #003340;\">Dimension<\/th>\n<th style=\"padding:12px 16px;text-align:left;border:1px solid #003340;\">BSI Act (Cyber)<\/th>\n<th style=\"padding:12px 16px;text-align:left;border:1px solid #003340;\">KRITIS Umbrella Act (Physical)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\"><strong>Protected asset<\/strong><\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">IT systems and networks<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">Buildings, facilities, and operations<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\"><strong>EU basis<\/strong><\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">NIS2 Directive<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">CER Directive 2022\/2557<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\"><strong>Core obligation<\/strong><\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">Cyber risk management, reporting obligation<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">Physical resilience, risk analysis, reporting obligation<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\"><strong>Typical lead responsibility<\/strong><\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;color:#0a6d80;font-weight:600;\">BSI<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;color:#0a6d80;font-weight:600;\">BBK<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>An attacker who wants to disable a substation does not ask whether the vulnerability lies in the firewall or in the door lock. This is precisely why the new law requires a common situation picture. The risk analysis under the umbrella law and the risk management under the BSI Act should access the same threat modeling instead of being conducted separately in two departments.<\/p>\n<figure style=\"margin:28px 0;clear:both;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/06\/st-17945-kritis-umspannwerk.jpg\" alt=\"Substation with high-voltage lines as critical infrastructure\" style=\"width:100%;height:auto;border-radius:6px;\" \/><figcaption style=\"font-size:0.82em;color:#888;margin-top:8px;text-align:center;\">Critical infrastructure like a substation requires both physical and digital protection. <em>Image: Pexels \/ Kris M\u00f8klebust<\/em><\/figcaption><\/figure>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Where the law remains vulnerable<\/h2>\n<p>The regulatory framework also deserves a critical look. The threshold of 500,000 inhabitants served was criticized in the process because it leaves the classification of smaller but regionally indispensable suppliers unclear. Several countries considered it too high. Since criticality can also be established below the regular threshold, a gray area is created for some smaller suppliers in which they must reliably assess and document their own affectedness.<\/p>\n<p>In addition, there is the question of responsibility. Expert observers and voices from the parliamentary process criticize that the division of tasks between BBK for physical protection, BSI for cybersecurity, and the Federal Ministry of the Interior is not always clearly regulated. For operators, this means they should clarify early on which authority is their contact in the event of an incident.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What Security Managers Need to Address in the Next 90 Days<\/h2>\n<p>From a logical perspective, the law provides a tight starting point that doesn&#8217;t require a large budget and sets the right course.<\/p>\n<div class=\"how-to\" style=\"margin:28px 0;border:1px solid #d5e8ec;border-radius:6px;overflow:hidden;\">\n<div style=\"background:#003340;color:#fff;padding:12px 18px;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.14em;\">Three Steps for the Next Quarter<\/div>\n<div style=\"padding:8px 0;\">\n<div style=\"display:flex;gap:18px;padding:14px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:34px;font-weight:800;color:#0a6d80;font-size:1.4em;line-height:1;\">1<\/div>\n<div style=\"color:#333;line-height:1.55;\"><strong>Clarify Impact.<\/strong> Based on the threshold and sector classification, check if your facilities fall under the umbrella law; in borderline cases, document and justify the criticality.<\/div>\n<\/div>\n<div style=\"display:flex;gap:18px;padding:14px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:34px;font-weight:800;color:#0a6d80;font-size:1.4em;line-height:1;\">2<\/div>\n<div style=\"color:#333;line-height:1.55;\"><strong>Combine Risk Picture.<\/strong> Establish a common threat modeling for physical risk analysis and cyber risk management to make combined attacks visible.<\/div>\n<\/div>\n<div style=\"display:flex;gap:18px;padding:14px 20px;\">\n<div style=\"min-width:34px;font-weight:800;color:#0a6d80;font-size:1.4em;line-height:1;\">3<\/div>\n<div style=\"color:#333;line-height:1.55;\"><strong>Define Reporting Channels.<\/strong> Determine in advance which authority is responsible in the event of an incident, and then simulate the reporting process in a tabletop exercise.<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>This approach keeps the effort manageable and turns obligation into a robust plan. Those who now integrate the two regimes have a clear reporting channel and a common situation picture in the event of the first reported incident.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<h3>What is the difference between NIS2 and the KRITIS Umbrella Law?<\/h3>\n<p>NIS2 and its German implementation in the BSI Act regulate the cybersecurity of critical facilities. The KRITIS Umbrella Law implements the CER Directive and regulates the physical protection and general resilience of the same facilities. Both apply in parallel and intersect for many operators.<\/p>\n<h3>When does the KRITIS Umbrella Law come into effect?<\/h3>\n<p>The law was announced in the Federal Law Gazette on March 16, 2026, and entered into force on March 17, 2026. The Bundestag had passed it on January 29, 2026, and the Bundesrat approved it on March 6, 2026.<\/p>\n<h3>Which sectors are affected?<\/h3>\n<p>The law covers ten sectors with critical infrastructures, including energy, water, healthcare, food supply, transport, and traffic. The decisive factor is whether a facility provides a critical service for the population&#8217;s supply.<\/p>\n<h3>What does the threshold of 500,000 inhabitants mean?<\/h3>\n<p>The standard threshold applies: a facility must supply at least 500,000 people. Facilities above this threshold usually fall under the law. However, criticality can also be established below this threshold, which is why smaller operators should also check their classification.<\/p>\n<h3>Who is responsible for implementation?<\/h3>\n<p>For physical protection, the Federal Office for Civil Protection and Disaster Assistance is usually responsible, while the BSI is responsible for cybersecurity. The exact demarcation between the authorities is disputed in the expert community, which is why operators should clarify their specific contact person early on.<\/p>\n<h3>What penalties are threatened in the event of violations?<\/h3>\n<p>The law provides for fines for breaches of duty, such as missing registration or failure to report. The specific amount depends on the individual case and the type of violation, which is why operators should take the obligation to provide evidence seriously from the outset.<\/p>\n<h3>Editor&#8217;s Reading Tips<\/h3>\n<ul style=\"list-style:none;margin:0;padding:0;\">\n<li style=\"padding:10px 0;border-bottom:1px solid #eee;\"><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/10\/the-emergency-plan-that-nobody-practiced\/\" style=\"color:#1a1a1a;text-decoration:none;\">The Emergency Plan Nobody Has Tested<\/a><\/li>\n<li style=\"padding:10px 0;border-bottom:1px solid #eee;\"><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/04\/rsa-conference-2026-wrap-up-dach-ciso-hausaufgaben-pqc\/\" style=\"color:#1a1a1a;text-decoration:none;\">RSA Conference 2026: DACH CISOs&#8217; Homework<\/a><\/li>\n<li style=\"padding:10px 0;\"><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/18\/oracle-peoplesoft-actively-exploited-vulnerability-cisa-warns\/\" style=\"color:#1a1a1a;text-decoration:none;\">Oracle PeopleSoft: Actively Exploited Vulnerability<\/a><\/li>\n<\/ul>\n<p style=\"margin:32px 0 12px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.18em;color:#666;\">More from the MBF Media Network<\/p>\n<div style=\"padding:14px 18px;border-left:3px solid #0bb7fd;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#0bb7fd;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">cloudmagazin<\/div>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/2026\/06\/20\/cada-cloud-souveraenitaet-assurance-levels\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">CADA: When Cloud Sovereignty Becomes a Procurement Requirement<\/a>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #202528;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#202528;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">mybusinessfuture<\/div>\n<p><a href=\"https:\/\/mybusinessfuture.com\/schatten-ki-mittelstand-prozess-signal\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Shadow AI in the Mid-Market: What the Covert Use Reveals<\/a>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #d65663;background:#fafafa;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#d65663;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">digital-chiefs<\/div>\n<p><a href=\"https:\/\/www.digital-chiefs.de\/industrie-4-0-edge-iot-architektur-cio\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Smart Factory: Why Edge Depends on the Process<\/a>\n<\/div>\n<p style=\"text-align:right;font-style:italic;color:#666;\"><em>Image source: AI-generated (June 2026)<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"The KRITIS umbrella law has been in effect since March 2026 and makes physical resilience mandatory.","protected":false},"author":50,"featured_media":17946,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"Critical Infrastructure Act","_yoast_wpseo_title":"KRITIS-Dachgesetz: When Resilience Becomes a CISO's Mandatory Duty","_yoast_wpseo_metadesc":"The KRITIS umbrella law, effective March 2026, mandates physical resilience. Discover how CISOs must integrate this with the cyber regime now.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/06\/kritis-dachgesetz-physische-resilienz-ciso-cover-hero.jpg","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/06\/kritis-dachgesetz-physische-resilienz-ciso-cover-hero.jpg","_yoast_wpseo_twitter-image-id":0,"_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[3],"tags":[196],"class_list":["post-17955","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aktuelles","tag-reboot-germany"],"evm_reading_time_minutes":7,"wpml_language":"en","wpml_translation_of":17945,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17955","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=17955"}],"version-history":[{"count":1,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17955\/revisions"}],"predecessor-version":[{"id":17956,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17955\/revisions\/17956"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/17946"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=17955"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=17955"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=17955"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}