{"id":7517,"date":"2024-03-14T10:00:00","date_gmt":"2024-03-14T10:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-5062\/"},"modified":"2026-07-04T12:24:46","modified_gmt":"2026-07-04T12:24:46","slug":"kritis-umbrella-act-what-operators-of-critical-infrastructures-can-expect-besides-nis2","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2024\/03\/14\/kritis-umbrella-act-what-operators-of-critical-infrastructures-can-expect-besides-nis2\/","title":{"rendered":"KRITIS-Umbrella Act: What Operators of Critical Infrastructures Can Expect Besides NIS2"},"content":{"rendered":"<p><strong>While the security world focuses on NIS2, the Federal Ministry of the Interior is simultaneously working on the KRITIS-Umbrella Act  &#8211;  the physical counterpart to cyber regulation. For the first time in Germany, minimum standards for the physical protection of critical infrastructures will be legally anchored nationwide. Operators face the double burden of digital and physical resilience.<\/strong><\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li>KRITIS-Umbrella Act implements EU Directive CER (Critical Entities Resilience)<\/li>\n<li>Nationwide physical protection standards for KRITIS operators for the first time<\/li>\n<li>Affects 11 sectors: Energy, Water, Health, Transport, Digital, and others<\/li>\n<li>Risk assessments, resilience plans, and reporting obligations for physical incidents<\/li>\n<\/ul>\n<h2>NIS2 Plus KRITIS-Umbrella Act: The Double Regulation<\/h2>\n<p>NIS2 regulates cybersecurity, the KRITIS-Umbrella Act physical protection  &#8211;  but the addressees overlap significantly. An energy supplier, for example, will have to comply with both sets of regulations in the future: cyber risk management according to NIS2 AND physical resilience plans according to the KRITIS-Umbrella Act.<\/p>\n<p>For operators, this means: two compliance frameworks, two reporting obligations, potentially two supervisory authorities. The challenge lies in integrating both requirements into a coherent risk management system.<\/p>\n<h2>What the Law Specifically Requires<\/h2>\n<p>Core obligations for KRITIS operators: regular risk assessments (every 4 years), resilience plans with concrete protective measures, reporting obligations in case of incidents that significantly disrupt operations, background checks for employees in sensitive areas, and designation of a responsible contact person for the BBK (Federal Office of Civil Protection and Disaster Assistance).<\/p>\n<p>New is the all-hazards approach: the risk assessment must include not only sabotage and terrorism but also natural disasters, pandemics, and technical failures. This includes climate adaptation as a security issue.<\/p>\n<h2>The 11 Affected Sectors<\/h2>\n<p>Energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, public administration, space, and food. The precise delineation of which companies within these sectors are considered &#8220;critical facilities&#8221; is defined by threshold values.<\/p>\n<p>Important for small and medium-sized enterprises: the threshold values are oriented towards supply relevance, not company size. A small municipal utility can be affected just as much as a DAX corporation.<\/p>\n<h2>Recommendation for Implementation: Integration Instead of Double Work<\/h2>\n<p>Companies already working on NIS2 compliance should not treat the KRITIS-Umbrella Act as a separate project. The recommendation: build an integrated resilience management system that covers both cyber and physical risks.<\/p>\n<p>ISO 22301 (Business Continuity) offers a framework that combines both dimensions. Companies that certify their BCMS according to 22301 automatically meet a large part of the KRITIS-Umbrella Act requirements.<\/p>\n<h2>Key Facts<\/h2>\n<p><strong>EU Basis:<\/strong> CER Directive (Critical Entities Resilience), to be implemented by October 2024<\/p>\n<p><strong>Sectors:<\/strong> 11 sectors with an estimated 2,000+ affected operators in Germany<\/p>\n<p><strong>Reporting Obligation:<\/strong> 24 hours for significant disruptions to operations<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Does the KRITIS-Umbrella Act also apply to IT companies?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Yes, the &#8220;Digital Infrastructure&#8221; sector includes data centers, DNS services, TLD registries, and IXPs. Cloud providers and managed service providers can also be affected, depending on threshold values.<\/p>\n<\/details>\n<details>\n<summary><strong>How does this relate to the existing IT Security Act?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The IT Security Act 2.0 regulates cybersecurity for KRITIS (will be replaced by NIS2 implementation). The KRITIS-Umbrella Act complements the physical dimension. Both laws apply in parallel.<\/p>\n<\/details>\n<details>\n<summary><strong>How much does implementation cost?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Depending on the maturity level: companies with existing BCM according to ISO 22301 have minimal additional effort. Without existing structures: 6-12 months project duration, \u20ac100,000-\u20ac500,000 for small and medium-sized enterprises (consulting, measures, documentation).<\/p>\n<\/details>\n<h2>Related Articles<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2025\/02\/28\/post_id-3707\/\">Case Study: NIS2-Readiness in 6 Months  &#8211;  A Municipal Utility Shows How It&#8217;s Done<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/06\/post_id-3837\/\">Cybersecurity Trends 2026: The 7 Developments Security Decision-Makers Need to Know<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/14\/post_id-3519\/\">NIS2 Checklist 2026: What Companies Need to Implement Now<\/a><\/li>\n<\/ul>\n<p style=\"font-weight:700;color:#e6e3da;font-size:1.05em;margin:48px 0 16px;\">More from the MBF Media Network<\/p>\n<div style=\"display:flex;flex-direction:column;gap:14px;margin-bottom:40px;\"><a href=\"https:\/\/www.cloudmagazin.com\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#0bb7fd;\">cloudmagazin<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">Cloud Magazine<\/span><\/a><a href=\"https:\/\/www.mybusinessfuture.com\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#aa8ac2;\">MyBusinessFuture<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">MyBusinessFuture<\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#d65663;\">Digital Chiefs<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">Digital Chiefs<\/span><\/a><\/div>\n","protected":false},"excerpt":{"rendered":"While the security world focuses on NIS2, the Federal Ministry of the Interior is simultaneously working on the KRITIS-Umbrella Act &#8211; the physical counterpart to cyber regulation. For the first time in Germany, minimum standards for the physical protection of critical infrastructures will be legally anchored nationwide. Operators face the double burden of digital and [&hellip;]","protected":false},"author":55,"featured_media":5061,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"kritis-umbrella act","_yoast_wpseo_title":"KRITIS-Umbrella Act: What Operators of Critical Infrastructures Can Expect Besid","_yoast_wpseo_metadesc":"KRITIS-Umbrella Act: Ensure physical security compliance alongside NIS2\u2014discover key requirements and prepare now. Learn more today!","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-5062"],"footnotes":""},"categories":[259],"tags":[245,230],"class_list":["post-7517","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-strategie-governance-en","tag-compliance","tag-nis2"],"evm_reading_time_minutes":4,"wpml_language":"en","wpml_translation_of":5062,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7517","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=7517"}],"version-history":[{"count":5,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7517\/revisions"}],"predecessor-version":[{"id":19813,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7517\/revisions\/19813"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/5061"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=7517"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=7517"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=7517"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}