Germany’s KRITISDachG Now in Force, Implementing Regulations Still Pending: What Operators Need to Know

Ein Strommast steht im organge-roten Sonnenuntergang.
  • 09/24/2026
  • Reading time 5 Minutes

Germany’s Critical Infrastructure Act (KRITISDachG) took effect this year, setting minimum standards for the physical protection of critical infrastructure. Significant uncertainty remains over the specific obligations it imposes on operators. Here is what they need to know.

The debate over the security of critical infrastructure in Germany has reached the broader public this year. The federal government, like its predecessors, is working to enshrine resilience requirements in law for energy suppliers, transport, healthcare and drinking water.

A key element is the Critical Infrastructure Act (KRITISDachG), which has been in force since 17 March 2026 (BGBl. 2026 I Nr. 66). It transposes the European CER Directive (EU) 2022/2557 on the resilience of critical entities into German law, creating a uniform, cross-sector legal framework for the physical protection of critical infrastructure.

Key implementing regulations are still missing, however, and parallel regulatory regimes create overlapping compliance requirements that make the legal landscape difficult to navigate. This article provides a concise overview of the current status, the core obligations and the practical steps operators should take now.

1. Which Facilities Qualify as Critical? The Missing Implementing Regulation (KritisV) Leaves Key Questions Open

The statutory authority for the implementing regulation has not yet been exercised. The planned central regulation (KritisV) is intended to define which facilities qualify as critical, set the relevant thresholds and thereby determine the scope of the physical resilience obligations. Only once the KritisV enters into force will the registration obligation under Section 8, and the subsequent deadlines for risk analysis and resilience planning, be triggered.

At present, only a ministerial draft dated 26 May 2026 is available. It already contains specific facility categories, thresholds and sector classifications, offering a reliable basis for operators looking to prepare now.

Operators should use this draft to carry out a preliminary impact assessment. The key threshold of 500,000 persons served is politically contested: the Bundesrat considers it too high and has called for it to be lowered to capture regionally significant infrastructure.

The BBK template for resilience plans under Section 13(2) is also still outstanding. This leaves operators in a paradoxical position: the Act applies, but the specific obligations cannot yet be finally determined without the implementing regulation. Waiting is not advisable. Preparatory analysis can and should begin now.

2. What Are the Obligations for Operators of Critical Facilities?

Where a preliminary analysis indicates that a facility is likely to fall within the scope of the Act, operators should prepare to meet the following core obligations:

  • Registration with the Federal Office of Civil Protection and Disaster Assistance (BBK) within three months of being identified as affected (Section 8)
  • Risk analysis within nine months of registration (Section 12)
  • Resilience measures, covering technical, organisational and personnel safeguards, to ensure the continued provision of critical services (Section 13)
  • Resilience plan based on the BBK template (Section 13(2))
  • Incident reporting for significant disruptions within 24 hours to the joint reporting office of the BBK and BSI (Section 18)
  • Compliance audits (Section 16)

 

Of particular importance is the management liability provision under Section 20. Senior management bears personal responsibility for implementing resilience measures and is liable to the company under the general rules on directors’ duties. KRITIS compliance is not simply an IT or facilities management issue; it must be embedded at the leadership level.

Although the core obligations relating to risk analysis, resilience and incident reporting do not currently carry administrative fines, material liability and compliance risks remain. Regulatory inspections and orders can give rise to independent exposure, and civil liability claims may follow in the event of harm. Directors and officers should therefore familiarise themselves with the requirements early and ensure clear allocation of compliance responsibilities within the organisation.

3. Overlapping Regulation: How the KRITISDachG Intersects with Other Regimes

The KRITISDachG does not operate in isolation. It supplements an already complex regulatory framework and is designed as a complement to the revised Federal IT Security Act (BSIG), which implements NIS 2. While the BSIG addresses cybersecurity and the KRITISDachG covers physical resilience, the two regimes use different triggers: the BSIG looks to company size and revenue, while the KRITISDachG applies a threshold based on the number of persons served. In practice, risk analyses, reporting obligations and governance structures overlap, creating parallel compliance requirements.

In the financial sector, the Digital Operational Resilience Act (DORA) adds a third regulatory layer. Operators subject to multiple regimes should adopt an integrated compliance approach that maps overlaps and leverages synergies across the different obligation sets.

The overlap is especially pronounced in the energy sector. Alongside the KRITISDachG and BSIG, the Energy Industry Act (EnWG) applies as a sector-specific layer. Section 5f EnWG provides for a separate compliance verification procedure for resilience obligations. The Federal Network Agency (Bundesnetzagentur) is also preparing new IT security catalogues under Section 5c EnWG. Energy suppliers, grid operators and municipal utilities should assess their exposure early and systematically map the interactions between the applicable regimes.

4. Conclusion: Operators Should Use the Preparation Window Now

The KRITISDachG marks a paradigm shift in the protection of critical infrastructure. Even though key implementing regulations remain outstanding, potentially affected operators should use the preparation window actively. Impact assessments, a stocktake of existing security measures and mapping overlapping regulatory requirements are all possible now, and strongly recommended.

Baker Tilly advises affected operators across the full spectrum, from impact assessments and the embedding of management-level responsibility through to integrated compliance strategies spanning the KRITISDachG, BSIG, DORA and EnWG.

We bring particular expertise in the energy and infrastructure sectors. Get in touch. We look forward to advising you.

Share this article:

Authors of this article

Alexandra Sausmekat

Partner

Attorney-at-Law (Rechtsanwältin), Certified Tax Advisor

Michelle Reddiar, LL.M.

Senior Manager

Attorney-at-Law (Rechtsanwältin)

Nicolas Plinke

Senior Manager

Attorney-at-Law (Rechtsanwalt)

What can we do for you?

Talk to us. Simply without obligation

Get in touch