/ KRITIS requirements
What are the legal requirements for KRITIS operators?
Critical infrastructure (KRITIS) forms the backbone of our modern society. Energy supply, healthcare, water, information technology, and transportation: A failure or disruption of these systems can have far-reaching consequences for the economy, the government, and the public. The legal requirements for KRITIS operators are correspondingly stringent.

But what specific KRITIS requirements does the new KRITIS umbrella law entail? And what organizational, technical, and strategic KRITIS measures are actually necessary to ensure the long-term protection of critical infrastructure?
For operators of critical infrastructure, this is no longer just about IT security in the narrow sense. What is required is a holistic approach to resilience—ranging from risk analysis and appropriate technical and organizational measures to reporting requirements and regular verification. Protecting critical infrastructure is therefore a core business responsibility that must be strategically embedded.
The KRITIS Framework Act complements other regulatory requirements for cybersecurity—in particular the European NIS 2 Directive. While NIS 2 primarily sets requirements for the IT and cybersecurity of many companies and organizations, the KRITIS Framework Act focuses more on the physical and organizational resilience of critical infrastructure. We will examine the specific requirements under NIS 2 in a separate article.
It is particularly important to note that responsibility does not lie solely with the IT department or plant security. Management is obligated to implement appropriate organizational measures to ensure the security and resilience of the company’s systems and processes. If management fails to adequately fulfill this obligation, the company faces not only substantial fines of up to 1 million euros. Under certain circumstances, personal liability of management may also be considered.
Furthermore, the financial damage caused by preventable security incidents—such as production downtime, reputational damage, or contractual penalties—can far exceed the statutory fines.
This makes it all the more important to analyze regulatory requirements in a structured manner at an early stage and translate them into robust, practical measures. In this article, you will learn which legal KRITIS requirements currently apply, which KRITIS measures must be implemented under the umbrella law, and how you can design the protection of critical infrastructure to be legally compliant and future-proof.
Registration of KRITIS companies
Under the KRITIS Framework Act, affected companies must self-register within three months. This process is overseen by a registration office jointly operated by the Federal Office for Civil Protection and Disaster Assistance (BBK) and the Federal Office for Information Security (BSI). Approximately two weeks after registration, the company will be notified of the competent supervisory authority.
This means that companies must first determine for themselves whether they qualify as KRITIS operators. This classification is based on defined thresholds for individual sectors and facilities.
Risk Analyses
One of the key KRITIS requirements is the preparation of structured risk analyses. In addition to the individual risks associated with their own operations, KRITIS companies must also take systemic dependencies into account.
These include, in particular:
- Risks identified in national risk analyses
- Risks arising from dependencies on other operators, including those in other sectors
- Risks arising from other operators’ dependence on one’s own infrastructure
For example, a refinery operator may depend on the electricity supply or transportation capacity for crude oil. At the same time, the transportation sector or waste management sector may rely on the refinery’s products.
The initial risk analysis must be prepared no later than nine months after registration. It must then be updated at least every four years.
Resilience Measures, Implementation Plan, and Documentation
KRITIS companies are required to implement appropriate KRITIS measures within ten months of registration and to document these measures in an implementation plan.
The goal is to provide comprehensive and robust protection for critical infrastructure—from prevention and response to the restoration of operational capability.
Essentially, the legal requirements can be divided into several areas of action.
Relationship to NIS2
The KRITIS Framework Act supplements the requirements of the NIS2 Directive but does not replace them. In the future, many companies may be subject to both regimes simultaneously.
While NIS2 primarily addresses cybersecurity, IT risk management, and reporting obligations for IT security incidents, the KRITIS Framework Act focuses more on the overall resilience of critical infrastructure—including physical security, organizational measures, and operational emergency preparedness.
The KRITIS Framework Act generally does not impose any documentation requirements that go beyond the requirements of NIS2. However, the competent supervisory authorities may request additional documentation.
We explain in detail which companies are affected by NIS2 and what specific security requirements result from it in our article on NIS2 requirements for companies.
Mandatory Reporting of Incidents
KRITIS companies are required to report any incident that significantly disrupts or could disrupt the provision of a critical service.
The report must be submitted to the Federal Office for Civil Protection and Disaster Assistance within 24 hours. A detailed report must also be submitted within one month at the latest.
Audit-proof documentation of security-related processes—such as access controls or visitor access—is often a key component in investigating such incidents.
As an ISO 27001-certified software provider, we are happy to assist companies with their initiatives, particularly when it comes to KRITIS-compliant access control and KRITIS-compliant yard management.
Would you like to discuss your situation with us?
Please contact us for advice and to receive a no-obligation quote.




