Auditors ✓ Lawyers ✓ Tax advisors ✓ and business consultants ✓ : Four perspectives. One solution. Worldwide. Learn …
Auditing and audit-related advice for companies ✓ Experienced auditors ✓ Excellent advice ✓ Tailor-made solutions » …
Our clients entrust us with their most important legal matters. Learn more about our legal services!
Tax laws are complex and dynamic. We face the challenge of tax law together with you - find out more.
Business consulting for companies ✓ Experienced consultants ✓ Excellent advice ✓ Tailor-made solutions » more
Germany’s KRITISDachG Now in Force, Implementing Regulations Still Pending: What Operators Need to Know
Bafin Publishes WpI MaRisk: New Supervisory Framework for Small and Medium Investment Firms
No Unlimited Right to Disclosure: Employer’s Information Claims in Default-of-Acceptance Wage Disputes
EmpCo Directive: New Requirements for Environmental Claims Apply from September
Baker Tilly Advises SEVEST on Acquisition of Majority Stake in IBG HydroTech
E-Invoicing in Germany: Countdown to January 2027
Baker Tilly Strengthens Mid-Market Tax Advisory with Markus Krinninger
ICT risks when using AI: New BaFin guidance
One year of DORA: What's next for financial companies
Survey: Two thirds of German automotive suppliers anticipate a market shakeout
Cross-industry expertise for individual solutions ✓ Our interdisciplinary teams combine expertise & market …
Baker Tilly advises CERTANIA on the Acquisition of InnoDiab
New SGEI Decision: Key Changes at a Glance
SGEI Decision: New Funding Opportunities for Affordable Housing
Risk management ✓ Compliance and controls ✓ Increase and ensure security & conformity ✓ more»
Baker Tilly offers a wide range of individual and innovative consulting services. Find out more!
Germany’s Critical Infrastructure Act (KRITISDachG) took effect this year, setting minimum standards for the physical protection of critical infrastructure. Significant uncertainty remains over the specific obligations it imposes on operators. Here is what they need to know.
The debate over the security of critical infrastructure in Germany has reached the broader public this year. The federal government, like its predecessors, is working to enshrine resilience requirements in law for energy suppliers, transport, healthcare and drinking water.
A key element is the Critical Infrastructure Act (KRITISDachG), which has been in force since 17 March 2026 (BGBl. 2026 I Nr. 66). It transposes the European CER Directive (EU) 2022/2557 on the resilience of critical entities into German law, creating a uniform, cross-sector legal framework for the physical protection of critical infrastructure.
Key implementing regulations are still missing, however, and parallel regulatory regimes create overlapping compliance requirements that make the legal landscape difficult to navigate. This article provides a concise overview of the current status, the core obligations and the practical steps operators should take now.
The statutory authority for the implementing regulation has not yet been exercised. The planned central regulation (KritisV) is intended to define which facilities qualify as critical, set the relevant thresholds and thereby determine the scope of the physical resilience obligations. Only once the KritisV enters into force will the registration obligation under Section 8, and the subsequent deadlines for risk analysis and resilience planning, be triggered.
At present, only a ministerial draft dated 26 May 2026 is available. It already contains specific facility categories, thresholds and sector classifications, offering a reliable basis for operators looking to prepare now.
Operators should use this draft to carry out a preliminary impact assessment. The key threshold of 500,000 persons served is politically contested: the Bundesrat considers it too high and has called for it to be lowered to capture regionally significant infrastructure.
The BBK template for resilience plans under Section 13(2) is also still outstanding. This leaves operators in a paradoxical position: the Act applies, but the specific obligations cannot yet be finally determined without the implementing regulation. Waiting is not advisable. Preparatory analysis can and should begin now.
Where a preliminary analysis indicates that a facility is likely to fall within the scope of the Act, operators should prepare to meet the following core obligations:
Of particular importance is the management liability provision under Section 20. Senior management bears personal responsibility for implementing resilience measures and is liable to the company under the general rules on directors’ duties. KRITIS compliance is not simply an IT or facilities management issue; it must be embedded at the leadership level.
Although the core obligations relating to risk analysis, resilience and incident reporting do not currently carry administrative fines, material liability and compliance risks remain. Regulatory inspections and orders can give rise to independent exposure, and civil liability claims may follow in the event of harm. Directors and officers should therefore familiarise themselves with the requirements early and ensure clear allocation of compliance responsibilities within the organisation.
The KRITISDachG does not operate in isolation. It supplements an already complex regulatory framework and is designed as a complement to the revised Federal IT Security Act (BSIG), which implements NIS 2. While the BSIG addresses cybersecurity and the KRITISDachG covers physical resilience, the two regimes use different triggers: the BSIG looks to company size and revenue, while the KRITISDachG applies a threshold based on the number of persons served. In practice, risk analyses, reporting obligations and governance structures overlap, creating parallel compliance requirements.
In the financial sector, the Digital Operational Resilience Act (DORA) adds a third regulatory layer. Operators subject to multiple regimes should adopt an integrated compliance approach that maps overlaps and leverages synergies across the different obligation sets.
The overlap is especially pronounced in the energy sector. Alongside the KRITISDachG and BSIG, the Energy Industry Act (EnWG) applies as a sector-specific layer. Section 5f EnWG provides for a separate compliance verification procedure for resilience obligations. The Federal Network Agency (Bundesnetzagentur) is also preparing new IT security catalogues under Section 5c EnWG. Energy suppliers, grid operators and municipal utilities should assess their exposure early and systematically map the interactions between the applicable regimes.
The KRITISDachG marks a paradigm shift in the protection of critical infrastructure. Even though key implementing regulations remain outstanding, potentially affected operators should use the preparation window actively. Impact assessments, a stocktake of existing security measures and mapping overlapping regulatory requirements are all possible now, and strongly recommended.
Baker Tilly advises affected operators across the full spectrum, from impact assessments and the embedding of management-level responsibility through to integrated compliance strategies spanning the KRITISDachG, BSIG, DORA and EnWG.
We bring particular expertise in the energy and infrastructure sectors. Get in touch. We look forward to advising you.
Alexandra Sausmekat
Partner
Attorney-at-Law (Rechtsanwältin), Certified Tax Advisor
Michelle Reddiar, LL.M.
Senior Manager
Attorney-at-Law (Rechtsanwältin)
Nicolas Plinke
Attorney-at-Law (Rechtsanwalt)
Talk to us. Simply without obligation
Get in touch
View all news