KRITIS Explained: Germany's Critical Infrastructure Security Requirements
August 3, 2026 · by Pentevo
KRITIS Explained: Germany's Critical Infrastructure Security Requirements
KRITIS (Kritische Infrastrukturen) is the German legal designation for facilities whose failure or degradation would cause severe supply disruptions for the population. Defined in the BSI Act (BSIG) and the KRITIS Regulation (BSI-KritisV), these operators face mandatory cybersecurity measures under §8a BSIG and, since December 2025, additional physical resilience duties under the KRITIS-Dachgesetz.
The Legal Basis for KRITIS
KRITIS is not a single law. It is a layered framework built from four instruments that interact with each other and with EU law.
BSI-Gesetz (BSIG) — the foundation. The Gesetz über das Bundesamt für Sicherheit in der Informationstechnik in its current version contains the core operative obligations for critical infrastructure operators in §§8a and 8b. Section §8a(1) requires operators to take appropriate technical and organisational measures to prevent disruptions to availability, integrity, authenticity, and confidentiality of their critical IT systems. Section §8b establishes the BSI's Central Contact Point for Critical Infrastructure and the mandatory incident reporting channel.
BSI-KritisV — the threshold regulation. The KRITIS-Verordnung (BSI-Kritis-Verordnung) defines which facilities actually cross the threshold to qualify as KRITIS. It enumerates sectors, subsectors, and threshold values in its annexes. Thresholds are expressed in sector-relevant units — megawatts of generation capacity for energy, cubic metres per day for water, number of fully insured persons for health insurance. The current consolidated BSI-KritisV version incorporates the amendments that extended the original list from seven to ten sectors and added Space as a new sector.
NIS2UmsuCG — the NIS2 transposition. The NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz transposes Directive 2022/2555/EU (NIS2) into German law. For KRITIS operators it layers additional obligations: a 24-hour initial incident notification to BSI (tighter than the existing four-hour disruption report window), supply chain security requirements, and vulnerability disclosure duties. KRITIS operators are automatically classified as "essential entities" under the NIS2UmsuCG, which carries the higher tier of supervisory scrutiny and sanctions.
KRITIS-Dachgesetz (KRITIS-DachG) — the physical layer. Enacted on 6 December 2025 and published in Bundesgesetzblatt 2025, Part I, the KRITIS-Dachgesetz transposes the EU CER Directive (Directive 2022/2557/EU on the resilience of critical entities). It extends oversight beyond information technology to physical infrastructure — premises, personnel, supply chains, and continuity planning — and introduces the new concept of "critical entities" (kritische Anlagen), a category that is explicitly broader than the existing KRITIS designation.
Which Sectors and Thresholds Trigger KRITIS Status
The BSI-KritisV designates ten sectors and assigns threshold values. The widely cited "500,000 people" figure is a rule of thumb that the BSI itself uses in public communications, but practitioners must consult the exact annex figures, which differ substantially by sector.
| Sector (KRITIS Sektor) | Subsector examples | Threshold basis (illustrative) |
|---|---|---|
| Energy (Energie) | Electricity generation, gas networks, oil pipelines, district heating | Installed capacity ≥ threshold MW; grid connections ≥ threshold count |
| Water (Wasser) | Drinking water supply, wastewater treatment | Volume supplied or treated per day in m³ |
| Food (Ernährung) | Food production and trade | Persons supplied per year |
| Information Technology and Telecommunications (IKT) | Carrier networks, exchange points, cloud services, DNS | Traffic volume, subscriber count, or processing capacity |
| Health (Gesundheit) | Hospitals, pharmaceutical supply, laboratories, emergency services | Number of fully insured or treatment cases per year |
| Finance and Insurance (Finanz- und Versicherungswesen) | Banking, payment infrastructure, exchanges, insurance | Transaction volume or balance sheet total |
| Transport and Traffic (Transport und Verkehr) | Rail, aviation, ports, inland waterways, road logistics | Passenger or freight volume per year |
| Media and Culture (Medien und Kultur) | Public broadcasting, news agencies, cultural heritage | Reach or archival coverage |
| Government and Public Administration (Staat und Verwaltung) | Parliamentary IT, courts, civil protection | Statutory designation |
| Space (Weltraum) | Ground control segments for European space infrastructure | Statutory designation |
The KRITIS-Dachgesetz does not replace this sector list but introduces a parallel "critical entity" designation managed jointly by the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe (BBK) and BSI.
How to Determine Whether Your Facility Qualifies
Qualification is facility-specific, not organisation-specific. A utility that operates three water treatment plants may find that one plant exceeds the threshold while two do not. Each plant is assessed individually against the annex table values for the relevant subsector. If an installation crosses the threshold in any one calendar year, the operator must notify BSI and begin compliance within two years (§8a(3) BSIG). Voluntary early registration is recommended in practice because BSI will eventually identify operators through market data.
What KRITIS Operators Must Do: The §8a BSIG Obligations
Implement State-of-the-Art Security Measures
Section §8a(1) BSIG requires "appropriate organisational and technical precautions" aligned with the "state of the art" (Stand der Technik). BSI does not publish a definitive checklist, but it maintains orientation documents and references external standards that it considers indicative:
- BSI IT-Grundschutz (BSI-Standard 200-1 through 200-4): Germany's structured baseline methodology covering organisational, personnel, infrastructure, and IT controls. BSI-Standard 200-2 defines the core IT-Grundschutz methodology. Operators can use BSI-Standard 200-4 for business continuity planning.
- ISO/IEC 27001: International information security management system standard, widely accepted by BSI as evidence of state-of-the-art implementation when scoped correctly to critical systems.
- IEC 62443: Operational technology and industrial control system security standard, increasingly cited by BSI for energy, water, and manufacturing KRITIS operators.
The obligation under §8a(1) is technology-neutral: if the state of the art evolves, operators are expected to follow. Freezing controls at the 2020 level is not compliant in 2026.
Audit Every Two Years and Submit Results to BSI
Under §8a(3) BSIG, operators must provide BSI with evidence of compliance at least every two years. Accepted forms include:
- Security audits conducted by a BSI-qualified auditor or accredited certification body
- IT security certifications (ISO/IEC 27001 scope letter covering critical systems; BSI IT-Grundschutz certificate; sector-specific certifications recognised by BSI)
- Self-assessments in the form defined by BSI — allowed only where BSI has explicitly approved this mechanism for the sector
The two-year clock starts from the date of the most recent submission, not from the date of original KRITIS notification. An operator that submitted in March 2024 must submit again by March 2026. BSI tracks submission dates and will remind operators approaching expiry.
Report Significant Disruptions Within Four Hours
Section §8b(4) BSIG requires operators to report significant disruptions to availability, integrity, authenticity, or confidentiality of their critical IT systems to BSI without undue delay. The BSI guidance operationalises "without undue delay" as a maximum of four hours from the point at which the operator becomes aware that a significant disruption has occurred.
Reportable events are not limited to successful attacks. The obligation covers:
- Unplanned outages of critical systems lasting beyond an operator-defined threshold
- Detection of malware in critical system environments even before impact materialises
- Denial-of-service attacks affecting supply continuity
- Insider incidents affecting confidentiality of critical system data
BSI operates a 24/7 incident reporting portal (Meldestelle) that KRITIS operators must register with. Reports must include the affected installation, the nature and estimated impact of the disruption, any initial attribution assessment, and the containment status at the time of reporting.
Under the NIS2UmsuCG, the timeline splits into a two-stage obligation: a preliminary notification within 24 hours, and a detailed report within 72 hours — aligning with the broader NIS2 framework while preserving the four-hour BSIG notification for the most severe categories.
KRITIS vs. NIS2: How They Overlap
The relationship between KRITIS (BSIG) and NIS2 (NIS2UmsuCG) is additive, not substitutive. Operators subject to both sets of rules must satisfy both.
| Dimension | KRITIS under BSIG | Essential Entity under NIS2UmsuCG |
|---|---|---|
| Who qualifies | Facilities above BSI-KritisV thresholds in ten sectors | Large and medium enterprises in covered sectors; KRITIS operators automatically included |
| Estimated German entities | ~2,000 operators (pre-Dachgesetz estimate) | ~29,000 entities (including non-KRITIS) |
| Cybersecurity obligations | §8a(1) BSIG state-of-the-art measures | Art. 21 NIS2 / §30 NIS2UmsuCG supply chain, encryption, access control, vulnerability handling |
| Incident reporting | 4 hours (§8b(4) BSIG) + preliminary 24h under NIS2UmsuCG | 24h initial / 72h detailed report |
| Audit frequency | Every 2 years (§8a(3) BSIG) | Competent authority supervisory cycles |
| Sanctions cap | €10 million or 2% global turnover (NIS2UmsuCG §65) | Same (essential entities share the cap) |
| Supervisory body | BSI | BSI (and sector regulators where applicable) |
The practical consequence is that a hospital qualifying as KRITIS and as an "essential entity" under the NIS2UmsuCG must maintain both the §8a BSIG audit trail and the §30 NIS2UmsuCG risk management documentation. Where the two overlap — for example on supply chain security — a single supplier assessment can satisfy both obligations if it is scoped to cover both.
The KRITIS-Dachgesetz Layer: Physical Resilience
The KRITIS-Dachgesetz of 6 December 2025 addresses the persistent gap between German cyber rules (BSIG) and physical infrastructure protection. It transposes the EU CER Directive 2022/2557/EU and introduces five new core duties for designated "critical entities":
Risk assessment. Critical entities must conduct a comprehensive risk assessment covering physical threats — natural disasters, terrorism, insider threats, supply disruption — as well as cyber-physical interactions. BSI-Standard 200-4 (business continuity) and the BBK's risk assessment methodology are referenced as guiding frameworks, though harmonised technical specifications under the CER Directive are still under development as of mid-2026.
Business continuity and crisis response. Entities must maintain documented continuity plans, test them at defined intervals, and ensure that emergency contacts are registered with the BBK.
Personnel security. Background checks for staff with access to critical physical assets are required in risk-proportionate form. The exact legal basis for data processing in this context is regulated in the KRITIS-DachG itself rather than left to general employment law.
Physical security. Perimeter protection, access control to critical installations, and protection against deliberate physical interference must be commensurate with the risk assessment findings.
Supply chain resilience. Entities must identify single points of failure in their supplier base and implement contingency sourcing or contractual resilience requirements. This obligation partially overlaps with the NIS2UmsuCG supply chain security duty for ICT suppliers.
Operators that already hold KRITIS status under BSIG are not automatically designated as "critical entities" under the Dachgesetz. Designation is a separate process managed by BBK in coordination with sector ministries and BSI. However, in practice, the overlap is expected to be very high.
Common Mistakes and What BSI Inspectors Look For
Based on published BSI inspection findings and publicly available KRITIS audit guidance, the following weaknesses recur in operator submissions and on-site assessments:
Scope creep left undefined. Operators frequently submit audit evidence covering the entire IT environment rather than scoping it precisely to the critical information infrastructure (KRITIS-relevante Systeme) as defined in their own asset register. BSI expects operators to maintain and regularly update a documented scope boundary that explains which systems are in scope and why. Under-scoping (excluding interdependent systems) is equally problematic.
Asset inventory outdated. §8a(1) BSIG requires operators to secure their critical IT systems, but doing so is impossible without a current and complete inventory. BSI inspectors routinely find that infrastructure changes — cloud migrations, new operational technology integrations, third-party managed services — have not been reflected in the KRITIS asset register.
Incident response not tested. Documented procedures without tested evidence of execution are rated inadequate. BSI expects table-top exercises or live drills for critical disruption scenarios at a cadence appropriate to the sector risk level — typically at least annually.
Audit evidence not granular enough. Submitting an ISO 27001 certificate as sole evidence is insufficient unless the certification scope letter explicitly covers the critical systems and processes. BSI can and does request the detailed audit report. A certificate with a generic scope ("the information security management system of [Operator] GmbH") provides much weaker evidence than one with a scope that enumerates critical system categories.
4-hour report not exercised. Incident reporting procedures are often designed but never practised. A four-hour notification window under incident-stress conditions requires pre-approved report templates, designated decision-makers reachable at all times, and a tested technical pathway to BSI's Meldestelle — none of which should be assembled for the first time during an actual incident.
Third-party and cloud risks underestimated. When a KRITIS operator outsources management of a critical system to a cloud provider or managed service provider, the operator remains the responsible party under §8a BSIG. Contracts with providers must include the right to audit, security requirements at least equivalent to the operator's own §8a obligations, and an incident notification obligation to the operator that fits within the four-hour window.
Further Reading
For complementary compliance topics relevant to organisations subject to KRITIS obligations, the following resources provide additional guidance:
- NIS2 in Germany: Scope, Deadlines, and Obligations — detailed breakdown of the NIS2UmsuCG for essential and important entities
- BSI IT-Grundschutz: Practical Implementation Guide — step-by-step methodology for applying BSI's structured baseline approach
The BSI publishes sector-specific KRITIS implementation guidance and orientation documents at bsi.bund.de. The BBK publishes KRITIS-Dachgesetz transition guidance and the risk assessment methodology at bbk.bund.de. Both are authoritative primary sources that should be consulted alongside this article.
This article is for informational purposes only and does not constitute legal advice. KRITIS threshold values and obligations change when the BSI-KritisV is amended or when new implementing acts are issued. Always verify current annex figures against the officially published version of the BSI-KritisV in force at the time of your compliance assessment.
Frequently asked questions
What does KRITIS mean in Germany?
KRITIS stands for Kritische Infrastrukturen (critical infrastructures). It is the legal designation under the BSI Act (BSIG) and the KRITIS Regulation (BSI-KritisV) for facilities whose failure would cause severe supply disruptions for the German population. Operators of KRITIS installations must implement state-of-the-art IT security, undergo audits every two years, and report significant incidents to the BSI within four hours.
Which sectors are covered by KRITIS?
The BSI-KritisV currently designates ten sectors: Energy, Water, Food, Information Technology and Telecommunications, Health, Finance and Insurance, Transport and Traffic, Media and Culture, Government and Public Administration, and Space. The KRITIS-Dachgesetz adds a broader physical resilience layer that covers the same sectors plus additional public-interest entities.
What is the KRITIS threshold?
Most sectors use a rule-of-thumb threshold of facilities supplying or serving at least 500,000 people. However, the exact threshold values are sector-specific and defined in Annex tables of the BSI-KritisV. For example, energy installations are measured in megawatts of installed capacity, water utilities in cubic metres of water delivered per day, and hospitals in number of cases per year. Always consult the current BSI-KritisV annex figures rather than relying on the 500,000-person shorthand.
What are KRITIS operators required to do under §8a BSIG?
Under §8a(1) BSIG, KRITIS operators must implement technical and organisational measures appropriate to the state of the art to avoid disruptions to availability, integrity, authenticity, and confidentiality of their critical IT systems. They must submit proof of compliance to BSI every two years (§8a(3) BSIG), using audits, certifications, or self-assessments approved by BSI. Significant IT disruptions must be reported to BSI without undue delay and no later than four hours after detection (§8b(4) BSIG).
What is the KRITIS-Dachgesetz?
The KRITIS-Dachgesetz (KRITIS-DachG) is a federal framework law enacted on 6 December 2025 that transposes the EU CER Directive (Critical Entities Resilience Directive 2022/2557/EU) into German law. It adds physical resilience obligations — risk assessments, business continuity, personnel security, supply chain measures — on top of the existing cyber-only rules under BSIG. The law introduces a new category of 'critical entities' that is broader than the KRITIS designation under BSIG.
How does KRITIS relate to NIS2?
NIS2 (Directive 2022/2555/EU) was transposed into German law primarily through the NIS2UmsuCG (NIS2 Implementation and Cybersecurity Strengthening Act). KRITIS operators automatically qualify as 'essential entities' under NIS2UmsuCG and face its obligations — 24-hour initial incident notification, supply chain security, vulnerability disclosure — in addition to existing BSIG §8a duties. In practice the NIS2UmsuCG extended the KRITIS logic to roughly 29,000 additional important entities that are not KRITIS but operate in the same sectors.
How often must KRITIS operators be audited?
Every two years. Under §8a(3) BSIG, operators must submit to the BSI evidence of compliance obtained no more than two years previously. Acceptable forms include third-party audits, IT security certifications (such as ISO/IEC 27001 or BSI's own IT-Grundschutz certification), and inspections. BSI may also conduct its own on-site inspections under §8a(4) BSIG at any time.
What happens if a KRITIS operator fails to comply?
Non-compliance can result in administrative fines under §14 BSIG. Fines for KRITIS violations can reach up to €10 million or two percent of global annual turnover for essential entities under the NIS2UmsuCG framework. Beyond fines, BSI can issue binding orders requiring operators to implement specific measures or halt operations of non-compliant systems.
Related reading
EU Cyber Resilience Act (CRA) Explained: Who It Affects and What It Requires
The CRA applies to all products with digital elements sold in the EU. Essential requirements, SBOM mandate, 24-hour vulnerability reporting, and the December 2027 deadline.
complianceWhat Is an ISMS? ISO 27001 Information Security Management System Explained
An ISMS is the documented management system ISO 27001 requires. Clauses 4–10, the 93 Annex A controls, the Statement of Applicability, and how it maps to NIS2 Article 21.
complianceNIS2 Explained: Who Is Affected, What You Must Do, and by When
NIS2 in practice — Annex I and II sectors, size thresholds, essential vs important entities, the ten Article 21 measures, the 24/72-hour reporting cascade, and management liability.
complianceSBOM Explained: Software Bill of Materials, Formats, and Why the CRA Requires One
What an SBOM is, what belongs in one, CycloneDX vs SPDX, how to generate and maintain one, and exactly what the EU Cyber Resilience Act mandates.
Practice this hands-on
Pentevo Academy turns these concepts into guided lessons, videos and quizzes — free.
Start learning free