- Introduction
- Applicability and scope
- Identification, scope, and registration
- National and operator risk assessments
- Resilience obligations and the resilience plan
- Sector standards and minimum requirements
- Incident reporting
- Oversight, evidence, and penalties
- Challenges of implementing KRITIS
- Benefits of implementing KRITIS
- Best practices
- Conclusion
Introduction
If your organization runs power grids, hospitals, water utilities, or any other essential service in Germany, KRITIS compliance is about to stop being good practice and start being law. The KRITIS-Dachgesetz ( KRITISDachG ), or KRITIS Umbrella Act, transposes Directive (EU) 2022/2557 on the resilience of critical entities into German law. It puts cross-sector, federally uniform minimum requirements for the physical protection of critical installations on a statutory footing for the first time.
Germany has had solid rules for the cybersecurity of critical infrastructure for years through the Federal Office for Information Security (BSI) Act. However, the act lacked provisions for physical resilience, and this law closes that. It runs in parallel with the cyber rules that transpose NIS2, and it takes an all-hazards view, so natural disasters count alongside accidents and deliberate attacks. This translates into concrete duties for your organization: register, assess your risks, write a resilience plan, and report the incidents that matter.
Applicability and scope
The law covers operators of critical installations across 10 sectors: energy; transport and traffic; finance; social security and basic income support for jobseekers; health; water; food; IT and telecommunications; space; and municipal waste disposal. Not all 10 carry the same load. If your firm sits in IT and telecommunications or in finance, most of the operational duties drop away, because the NIS2 transposition and the DORA Regulation already cover that ground. Meanwhile, waste disposal and social security get a lighter set of obligations built around operator risk assessment.
Compliance levels and requirements
The KRITIS-Dachgesetz is a process, not a checklist, and you must move through it in stages. A federal ordinance first defines which installations count as critical, using sector membership, the critical service involved, and a supply threshold. After that come identification and registration, national and operator risk assessments, resilience duties captured in a plan, incident reporting, and supervision. Work through them in order and you move from being told you're in scope to proving you have a documented, audited level of physical resilience.
The core duties break down as follows:
- Identification and registration: Working out whether an installation is critical, then registering it with the federal authority.
- Risk assessment: Running operator risk analyses, grounded in the national assessments, at least every four years.
- Resilience measures and plan: Taking proportionate measures and writing them into a resilience plan.
- Incident reporting: Notifying significant incidents to the central reporting point.
- Oversight and evidence: Providing proof of compliance and allowing inspections.
Identification, scope, and registration
The first thing to establish is whether the law even applies to you: You must belong to one of the 10 sectors, support a defined critical service, and clear a supply threshold. The default threshold is a population of 500,000 residents served by the installation, carried over from the existing BSI critical-infrastructure ordinance, though lower sector- or installation-specific thresholds can apply where an installation matters more than its size suggests. The Federal Ministry of the Interior can also pull individual installations in, or let them out, case by case. Therefore, you cannot determine if the law applies to you based on the threshold alone.
Once your installation qualifies, you must register it with the Federal Office of Civil Protection and Disaster Assistance (BBK) within three months of qualifying, but not before July 17, 2026, through a joint online platform run with the BSI.
National and operator risk assessments
Risk assessment works on two levels that feed into each other. At the national level, federal and state ministries run risk analyses for the critical services in their remit, and the Federal Ministry of the Interior pulls these together into national risk analyses at least every four years, with the first due by Jan. 17, 2026. These consider natural, technical, and human-caused risks, including cross-sector dependencies, extreme events, and hybrid or hostile threats such as terrorism and sabotage.
You build on that national picture rather than starting from a blank page. If you're an operator of a critical installation, you run your own risk analysis at least every four years, and sooner when circumstances shift, drawing on the relevant parts of the national work plus other reliable sources. This operator assessment is what the resilience plan rests on, which is why the first one is due within nine months of registration.
Resilience obligations and the resilience plan
Everything else in the law leads here. You must take appropriate and proportionate technical, security-related, and organizational measures against four objectives: preventing incidents, keeping installations physically protected, responding to and containing incidents, and getting critical services back quickly. Measures should keep pace with the state of the art—the currently recognized, practically proven security measures for your sector, not necessarily the newest technology available—but the standard is proportionate throughout. You weigh the cost of a measure against the risk it addresses, and your economic capacity is part of that calculation, so you're not expected to spend more than your circumstances justify.
Rather than dictate a fixed set of controls, the law offers a menu of examples and lets you fit them to your own risk profile. Whatever measures you choose go into a resilience plan that you draw up and maintain. The plan sets out your reasoning for each measure and points back to your own risk assessment. The plan must stay current as the risks move.
Sector standards and minimum requirements
Sectors differ, so the law fills in detail at several levels while maintaining a baseline requirement. The Federal Ministry of the Interior can set cross-sector minimum requirements by ordinance, giving every critical installation a common baseline. Above that baseline, your organization and wider industry associations can develop industry-specific resilience standards, which the BBK reviews and recognizes as suitable. This mirrors the long-running approach to industry security standards under the BSI Act.
Where no recognized industry standard exists, responsible federal ministries and state governments can issue their own sector-specific ordinances, but those powers only switch on from Jan. 1, 2030. The lag is deliberate, giving industry-developed standards the first shot before top-down rulemaking steps in. And even where a standard exists, your organization can still adopt its own measures, as long as they meet the state of the art.
Incident reporting
If you're an operator of a critical installation, you're required to report significant incidents to the BBK without undue delay, and within 24 hours of becoming aware at the latest, through the joint reporting point run with the BSI. If the incident is ongoing, the initial report gets updated, and a detailed report follows within a month. The channel reuses the BSI's existing online portal, extended to cover physical incidents, sparing you from needing to learn a second system.
The reporting regime exists for situational awareness. It gives the BBK and the responsible authorities a nationwide view of incidents and threats, and what they learn flows back into the national risk assessments. A report has to carry enough to make sense of an incident's nature, cause, and possible cross-border effects: the share of users hit, how long it's expected to last, and the geographic area involved.
Oversight, evidence, and penalties
Supervision is risk-based. The responsible authority can first ask for evidence already filed under the BSI Act, then request further proof from your organization, including your resilience plan. It picks whom to check based on risk exposure, operator size, and how likely and severe a possible incident would be. Evidence can come through audits by qualified assessors, and the authority can make an inspection by entering the installation and reviewing documentation during normal business hours. If it finds a deficiency, it can order a remediation plan within a reasonable deadline. In electricity, gas, and hydrogen supply, the Federal Network Agency runs the equivalent process through a physical-resilience security catalog under the Energy Act.
The fines have teeth. The law creates administrative offenses with penalties scaled to how serious the breach is, so that they land as effective, proportionate, and dissuasive, which is what the CER Directive demands.
Challenges of implementing KRITIS
Reaching KRITIS compliance can be hard work, particularly if your physical protection was built without a formal statutory baseline.
Uncertainty until the ordinances land
A lot of what will drive real cost hasn't been published yet. The ordinance defining critical services and installations, the national risk assessments, and the cross-sector minimum requirements are all still to come, so the exact shape of your resilience obligations is not fully knowable today. The government's own estimate is around 1,700 critical installations in scope, but each operator's burden hangs on standards that arrive later.
The two-level risk assessment is a real effort
You can't just file the national assessment and be done. It has to be translated into your own installation-level work, and if you run a lot of installations, that means assessing continuously rather than once a year. Standing up risk matrices, risk profiles, and a management review process from scratch is a heavy first-time effort, and there's no way around it.
Legacy installations resist retrofitting
Older installations were often never built for the perimeter hardening, monitoring, and access controls the law has in mind. You may discover that retrofitting physical protection across a spread-out estate is expensive, and that it has to go installation by installation, because differing layouts make a single template useless.
Keeping step with the cyber regime
The physical and cyber regimes share the registration and reporting plumbing, but they stay separate duties under separate authorities. Your resilience plans have to stay coherent with the risk management measures required under the BSI Act, and the timelines have to be reconciled, or you end up with gaps and contradictory paperwork.
Proportionality is a judgment call
The law asks only for proportionate measures, cost weighed against risk, which sounds reasonable until you're the one deciding without a fixed spec. The catch is that you have to document why you chose each measure, and why you ruled others out, so an inspector can follow the logic later.
Benefits of implementing KRITIS
The payoff from KRITIS compliance reaches past keeping a regulator happy.
Fewer disruptions, and cheaper ones
Proportionate resilience measures head off costs that an incident would otherwise dump on you, from lost output to scramble-mode recovery. The whole law is built around keeping operations running and restoring services fast, which is what any well-run business wants anyway, mandate or no mandate.
One honest view of your risk
After working through the two-level assessment, your organization will come out understanding its dependencies, cross-sector and cross-border ones included. That kind of systemic picture is genuinely hard to assemble any other way, and it earns its keep well beyond compliance.
Less administrative friction over time
Because registration and incident reporting run through single shared channels, you must file core details and reports once instead of duplicating them across regimes. Recognized industry standards and equivalence provisions go further, letting you reuse certifications you already hold rather than rebuild the evidence.
A better footing with authorities
When you're compliant, inspections go faster and hurt less, since the resilience plan and audit trail already exist. Sitting at the table for industry standard-setting has its own upside too: you help shape the requirements you'll later be measured against.
Best practices
If you're aiming past bare-minimum compliance, a few habits earn their keep over the long run.
Governance and risk foundations
- Treat the operator risk assessment as a living process you review on a rolling basis, so new installations and shifting threats don't slip through between the four-year cycles.
- Tie every resilience measure back to a documented risk rationale in the plan, so the reasoning outlasts staff turnover and holds up under inspection.
- Put clear board-level ownership in place, since management is legally on the hook for implementing and overseeing resilience measures.
Operational resilience and continuity
- Pressure-test crisis and alarm procedures with tabletop exercises before a real incident does it for you.
- Map alternative supply chains and backup power for each critical installation rather than leaning on one group-wide assumption.
- Train your people, external service staff included, and repeat it, so the procedures hold when things go sideways.
Coordination and evidence
- Line up your physical resilience documentation with the risk management measures the cyber regime requires to kill duplication and contradictions.
- Reuse existing audits, certificates, and equivalence findings anywhere the law lets you count them as proof.
- Get into industry standard-setting early, so your organization helps write the recognized standard instead of inheriting one.
Conclusion
The KRITIS-Dachgesetz changes what critical infrastructure resilience means in Germany, because it puts the physical protection of the installations behind power, water, and hospital care on a legal footing rather than leaving it to goodwill. Treat it as a one-off documentation exercise and you'll likely be back patching the same gaps after every supervision cycle, since the law is built around continuous risk assessment and living resilience plans, not a certificate you frame and forget.
The better bet is to build the capability once and keep it. If your risk assessment, resilience planning, incident reporting, and evidence processes become durable operational functions, you meet what the regulation asks and end up with operations that actually hold together under stress. Line that work up with your existing cyber obligations, get involved in the standards that will fill in the detail, and the obligation starts paying you back as continuity.

