21.05.2026/

/ KRITIS requirements

What are the legal requirements for KRITIS operators?

Critical infrastructure (KRITIS) forms the backbone of our modern society. Energy supply, healthcare, water, information technology, and transportation: A failure or disruption of these systems can have far-reaching consequences for the economy, the government, and the public. The legal requirements for KRITIS operators are correspondingly stringent.

But what specific KRITIS requirements does the new KRITIS umbrella law entail? And what organizational, technical, and strategic KRITIS measures are actually necessary to ensure the long-term protection of critical infrastructure?

For operators of critical infrastructure, this is no longer just about IT security in the narrow sense. What is required is a holistic approach to resilience—ranging from risk analysis and appropriate technical and organizational measures to reporting requirements and regular verification. Protecting critical infrastructure is therefore a core business responsibility that must be strategically embedded.

The KRITIS Framework Act complements other regulatory requirements for cybersecurity—in particular the European NIS 2 Directive. While NIS 2 primarily sets requirements for the IT and cybersecurity of many companies and organizations, the KRITIS Framework Act focuses more on the physical and organizational resilience of critical infrastructure. We will examine the specific requirements under NIS 2 in a separate article.

Visitor Management & Yard Management (not just) for KRITIS companies.

Would you like to know if you are affected by KRITIS?

It is particularly important to note that responsibility does not lie solely with the IT department or plant security. Management is obligated to implement appropriate organizational measures to ensure the security and resilience of the company’s systems and processes. If management fails to adequately fulfill this obligation, the company faces not only substantial fines of up to 1 million euros. Under certain circumstances, personal liability of management may also be considered.

Furthermore, the financial damage caused by preventable security incidents—such as production downtime, reputational damage, or contractual penalties—can far exceed the statutory fines.

This makes it all the more important to analyze regulatory requirements in a structured manner at an early stage and translate them into robust, practical measures. In this article, you will learn which legal KRITIS requirements currently apply, which KRITIS measures must be implemented under the umbrella law, and how you can design the protection of critical infrastructure to be legally compliant and future-proof.

Registration of KRITIS companies

Under the KRITIS Framework Act, affected companies must self-register within three months. This process is overseen by a registration office jointly operated by the Federal Office for Civil Protection and Disaster Assistance (BBK) and the Federal Office for Information Security (BSI). Approximately two weeks after registration, the company will be notified of the competent supervisory authority.

This means that companies must first determine for themselves whether they qualify as KRITIS operators. This classification is based on defined thresholds for individual sectors and facilities.

Risk Analyses

One of the key KRITIS requirements is the preparation of structured risk analyses. In addition to the individual risks associated with their own operations, KRITIS companies must also take systemic dependencies into account.

These include, in particular:

  • Risks identified in national risk analyses
  • Risks arising from dependencies on other operators, including those in other sectors
  • Risks arising from other operators’ dependence on one’s own infrastructure

For example, a refinery operator may depend on the electricity supply or transportation capacity for crude oil. At the same time, the transportation sector or waste management sector may rely on the refinery’s products.

The initial risk analysis must be prepared no later than nine months after registration. It must then be updated at least every four years.

Resilience Measures, Implementation Plan, and Documentation

KRITIS companies are required to implement appropriate KRITIS measures within ten months of registration and to document these measures in an implementation plan.

The goal is to provide comprehensive and robust protection for critical infrastructure—from prevention and response to the restoration of operational capability.

Essentially, the legal requirements can be divided into several areas of action.

A key component of the KRITIS requirements is proactive emergency preparedness. Operators must identify and assess risks at an early stage and define appropriate countermeasures.

These include, among other things:

  • structured risk analyses and threat assessments
  • preventive emergency plans
  • clear responsibilities and escalation mechanisms

The goal is to prevent disruptions, attacks, or outages in advance, detect them early, or significantly reduce the likelihood of their occurrence.

The protection of critical infrastructure is not limited to cybersecurity. Adequate physical protection of buildings, production facilities, servers, warehouses, and technical equipment is equally essential.

This includes, in particular:

  • Structural, organizational, and technical security measures (e.g., perimeter protection, secured access points, facility protection, or yard management)
  • Clear demarcation of security-sensitive areas
  • Surveillance of the surrounding area
  • Use of detection and alarm systems
  • Controlled and documented access controls and visitor management

These KRITIS measures are designed to prevent unauthorized access, sabotage, or physical tampering. At the same time, KRITIS companies must also be designed to be as resilient as possible to natural disasters or accidents.

Despite preventive measures, incidents cannot be completely ruled out. For this reason, the KRITIS requirements mandate robust structures for rapid response and damage control.

Requirements include, among others:

  • an established risk management system
  • a formalized crisis management framework with clearly defined roles
  • documented crisis response plans and alert procedures
  • regular review and updating of protocols

The ability to act in a structured manner in an emergency is a key factor in determining the impact of an incident on supply security and the company’s reputation.

A key element in protecting critical infrastructure is ensuring operational continuity—even in the event of a disruption. Companies must take steps to restore their critical services as quickly as possible and minimize downtime.

These include:

  • Plans for maintaining operations (e.g., emergency power supply, redundancies, or backup systems)
  • Emergency and recovery plans
  • Identification and securing of alternative supply chains

Effective security management encompasses not only technology and processes, but also the human factor. Operators must ensure that both their own and external personnel are reliably integrated and vetted.

This includes, for example:

  • defined security requirements for service providers
  • contractual obligations regarding security standards
  • regulated authorization and access models

Especially for outsourced services, a structured governance model is essential to fully meet KRITIS requirements.

Regular training sessions and practical exercises are a mandatory component of KRITIS measures. Employees must be made aware of risks, threat scenarios, and rules of conduct.

These include:

  • Awareness programs
  • Emergency drills and crisis simulations
  • Training on security and reporting obligations

Effective protection of critical infrastructure can only be achieved when organizational, technical, and personnel measures work together.

Relationship to NIS2

The KRITIS Framework Act supplements the requirements of the NIS2 Directive but does not replace them. In the future, many companies may be subject to both regimes simultaneously.

While NIS2 primarily addresses cybersecurity, IT risk management, and reporting obligations for IT security incidents, the KRITIS Framework Act focuses more on the overall resilience of critical infrastructure—including physical security, organizational measures, and operational emergency preparedness.

The KRITIS Framework Act generally does not impose any documentation requirements that go beyond the requirements of NIS2. However, the competent supervisory authorities may request additional documentation.

We explain in detail which companies are affected by NIS2 and what specific security requirements result from it in our article on NIS2 requirements for companies.

Mandatory Reporting of Incidents

KRITIS companies are required to report any incident that significantly disrupts or could disrupt the provision of a critical service.

The report must be submitted to the Federal Office for Civil Protection and Disaster Assistance within 24 hours. A detailed report must also be submitted within one month at the latest.

Audit-proof documentation of security-related processes—such as access controls or visitor access—is often a key component in investigating such incidents.

As an ISO 27001-certified software provider, we are happy to assist companies with their initiatives, particularly when it comes to KRITIS-compliant access control and KRITIS-compliant yard management.

Would you like to discuss your situation with us?

Please contact us for advice and to receive a no-obligation quote.

Would you like us to call you back? Please enter your telephone number and the desired time period.
Indicates required field