Skip to content

KRITIS-Dachgesetz

KRITIS-Dachgesetz and NIS2: What Applies to Whom?

KRITIS-Dachgesetz and NIS2 apply in parallel: physical resilience falls under the BBK, cybersecurity under the BSI. Thresholds, deadlines, and fines at a glance.

By KaitoSec Team · Published 21 August 2026 · Updated 3 September 2026 · 13 min read

Germany's KRITIS-Dachgesetz, its KRITIS umbrella act, in effect since March 17, 2026, regulates the physical resilience of critical facilities; oversight and reporting fall under the BBK. The NIS2UmsuCG (in effect since December 6, 2025) regulates cybersecurity; the BSI is responsible. NIS2 covers roughly 29,500 entities, while the KRITIS-Dachgesetz, according to the law's explanatory memorandum, covers roughly 1,700 critical facilities. Both laws apply in parallel. Operators of critical facilities that fall under both face more obligations, not fewer.

What does the KRITIS-Dachgesetz regulate, and since when has it applied?

The KRITIS-Dachgesetz transposes the EU CER Directive 2022/2557 and took effect on March 17, 2026 (BGBl. 2026 I Nr. 66). For the first time, it obligates operators of critical facilities nationwide to ensure physical resilience: site protection, operational continuity, and personnel security. The responsible supervisory authority is the Federal Office of Civil Protection and Disaster Assistance (BBK).

The legislative timeline at a glance:

  • Bundestag vote on January 29, 2026 (BT-Drs. 21/2510)
  • Bundesrat approval on March 6, 2026 (1062nd session)
  • Promulgation in the Federal Law Gazette on March 16, 2026 (law of March 11, 2026, BGBl. 2026 I Nr. 66)
  • Entry into force on March 17, 2026

What's new is the cross-sector scope. Until now, the BSIG only regulated the IT security of critical infrastructure; physical protection was a matter for the federal states or scattered across sector-specific rules. The KRITIS-Dachgesetz responds with an independent, nationwide legal framework for the first time. The threshold logic, by contrast, is familiar: the term "operator of critical infrastructure" and the standard threshold of 500,000 people supplied come from the existing BSIG and BSI-KritisV regime; the KRITIS-Dachgesetz carries this logic over to the physical side.

What physical resilience means follows from the catalog of obligations in §§ 12 and 13:

  • Risk analyses for the operator's own critical facility
  • Resilience measures and a resilience plan: structural protection, access control, emergency and recovery preparedness, personnel security
  • Incident reports to the BBK under § 18

Germany is transposing the CER Directive considerably late; the EU transposition deadline had already expired on October 17, 2024. According to the BMI's assessment in the law's explanatory memorandum, around 1,700 critical facilities fall within the law's scope.

How do the KRITIS-Dachgesetz and NIS2 differ?

The KRITIS-Dachgesetz protects the physical side of critical facilities, NIS2 the digital side. The KRITIS-Dachgesetz requires site protection, operational continuity, and reports to the BBK; NIS2 requires cybersecurity risk management and reports to the BSI. Both laws apply in parallel, and an operator can fall under both at once.

The differences come down to four points:

  • Direction of protection: The KRITIS-Dachgesetz addresses the physical resilience of critical facilities: sabotage, natural hazards, loss of sites, supply chains, and personnel. NIS2 addresses the security of network and information systems; the catalog of measures is defined in § 30 BSIG.
  • Legal basis: The KRITIS-Dachgesetz transposes the EU CER Directive 2022/2557. NIS2 comes to Germany via the NIS2UmsuCG, which transposes the EU NIS2 Directive 2022/2555 and amends the BSIG to do so.
  • Oversight and reporting channel: The BBK is responsible for the KRITIS-Dachgesetz, with reports going through the joint reporting and registration platform run by the BBK and BSI. For NIS2, the BSI is the supervisory authority.
  • Terminology: The KRITIS-Dachgesetz speaks of operators of critical facilities, while NIS2 and the BSIG speak of especially important entities and important entities. Don't mix these terms up; they refer to different addressees with different obligations.

The two laws are also out of step timewise. The NIS2UmsuCG has been in force since December 6, 2025, and all its obligations have applied since then. We've broken down what that means for your organization in our article NIS2 in Germany. The KRITIS-Dachgesetz has applied since March 17, 2026; its obligations phase in based on registration.

The scale differs considerably: according to the BSI, NIS2 covers roughly 29,500 entities in Germany, while the KRITIS-Dachgesetz, per the law's explanatory memorandum, affects roughly 1,700 critical facilities.

Both laws complement each other; they don't replace each other. The legislator approaches the same facility from two directions: NIS2 asks whether your IT survives an attack, the KRITIS-Dachgesetz whether your facility survives a fire, a flood, or an act of sabotage. BSI President Claudia Plattner said of the Bundestag's vote on the NIS2UmsuCG: "With this law, Germany has reached an important milestone on the path to becoming a resilient cyber nation, because we are now protecting a critical part of our digital attack surface far better than before." (BSI press release of November 13, 2025)

Who falls under which law?

NIS2 kicks in based on size criteria: from 50 employees or €10 million in annual revenue in one of the regulated sectors, with stricter rules from 250 employees. The KRITIS-Dachgesetz kicks in based on the degree of supply: the standard threshold is 500,000 people supplied per facility. Size alone doesn't make you an operator of a critical facility; conversely, KRITIS status automatically makes you an especially important entity under § 28 BSIG.

What thresholds apply under NIS2?

The size-cap rule under § 28 BSIG is decisive. Important entities are companies in the regulated sectors with 50 or more employees, or with annual revenue above €10 million and an annual balance sheet total above €10 million. Especially important entities are those with 250 or more employees, or with annual revenue above €50 million and an annual balance sheet total above €43 million. Covered regardless of size are operators of critical facilities (§ 28 para. 1 BSIG), as well as qualified trust service providers, DNS service providers, and TLD registries. The sectors are listed in Annexes 1 and 2 of the BSIG, 18 sectors in total at EU level. Our article Am I affected by NIS2? walks through the detailed assessment.

What thresholds apply under the KRITIS-Dachgesetz?

The standard threshold is 500,000 residents to be supplied per facility (§ 5 para. 2 KRITISDachG). A statutory ordinance from the Federal Ministry of the Interior sets the facility-specific thresholds. This KRITIS ordinance currently exists only as a draft bill; according to the BBK FAQ on the KRITIS-Dachgesetz, it is still being developed and coordinated. The draft retains the standard threshold and adds sector-specific values.

§ 4 para. 1 KRITISDachG groups operators into 10 sectors:

  • Energy
  • Transport and traffic
  • Finance
  • Social insurance benefits and basic income support for jobseekers
  • Health care
  • Water (drinking water and wastewater)
  • Food
  • Information technology and telecommunications
  • Space
  • Municipal waste management

The CER Directive lists 11 sectors and treats banking, financial market infrastructure, and public administration separately; the German law combines some of these and adds its own areas. § 4 para. 2 governs special roles: DORA financial undertakings are exempt from essential obligations because EU Regulation 2022/2554 takes precedence. The information technology and telecommunications sector remains partly under the BSIG regime. Municipal waste management and social insurance are subject only to reduced obligations, essentially the risk analysis under § 12.

What does this look like for a municipal utility?

A municipal utility employs 600 people and supplies a major city with electricity and drinking water. As an energy company, it falls under NIS2 through the size criteria, as an especially important entity. If one of its facilities supplies more than 500,000 people, it is also an operator of a critical facility under the KRITIS-Dachgesetz; this status alone would make it an especially important entity under § 28 BSIG even if it didn't meet the size criteria. The result: two registrations, two reporting channels, two catalogs of measures, one company.

What deadlines apply to KRITIS operators after registration?

Operators of critical facilities must register with the BBK no later than three months after their facility qualifies as critical. When that is the case depends on the still-pending KRITIS ordinance; registration only starts once it takes effect. After that, a staggered timeline applies: risk analysis after nine months, resilience measures, a resilience plan, and reporting procedures after ten months.

The registration requirement follows from § 8 para. 1 KRITISDachG: operators of critical facilities register with the BBK via the platform set up jointly with the BSI. The law no longer names a fixed start date. Originally, § 8 named July 17, 2026, matching the CER requirement to identify critical entities by that date. The legislator removed it with an amending act dated July 21, 2026 (BGBl. 2026 I Nr. 221), because the KRITIS ordinance is still missing. The BBK will now set out the details of the registration procedure within four weeks of the ordinance taking effect.

The practical snag: as long as the KRITIS ordinance isn't in force, many operators still don't know with legal certainty when their facility counts as critical and the three-month deadline starts running. Don't wait for the ordinance anyway; check now whether you're affected based on the standard threshold.

Once registered, the staggered deadlines under § 8 para. 7 apply:

  • 9 months after registration: risk analysis and risk assessment of the operator's own facility (§ 12), to be repeated at least every four years thereafter.
  • 10 months after registration: resilience measures and resilience plan (§ 13), incident reporting (§ 18), and evidence obligations (§ 20).

§ 18 sets its own deadlines for incidents:

  • Initial report: without delay, no later than 24 hours after becoming aware of the incident.
  • Detailed report: no later than one month after becoming aware.
  • Reporting channel: to the BBK via the joint platform.

NIS2 runs on a different clock: especially important and important entities report to the BSI in three stages, with 24 hours for the early warning, 72 hours for the initial report, and one month for the final report. You'll find the details in our article on NIS2 reporting obligations. Anyone who falls under both regimes needs a reporting process that serves both channels. Deadline discipline isn't automatic even on the NIS2 side: as of June 30, 2026, the BSI overview NIS-2 in Zahlen put registered companies at 17,729, against the BSI's overall estimate of around 29,500 affected entities.

What fines can result from violations?

The KRITIS-Dachgesetz provides for fines of up to €1 million (§ 24 KRITISDachG). NIS2 goes considerably further: up to €10 million or 2 percent of worldwide annual revenue for especially important entities (§ 65 BSIG). Anyone who violates both laws risks both fine frameworks at once.

For operators of critical facilities, § 24 KRITISDachG tiers the fines by type of violation:

  • Up to €1,000,000 for failing to comply with enforceable orders from the supervisory authority
  • Up to €500,000 for not submitting the results of security audits
  • Up to €100,000 for, among other things, missing or incorrect registration information

The fine framework was doubled during the parliamentary process, but it still stays well below NIS2 levels.

For especially important entities, § 65 BSIG provides for up to €10 million or 2 percent of worldwide annual revenue, and for important entities up to €7 million or 1.4 percent. On top of that comes the personal liability of management under § 38 BSIG. Our article on NIS2 fines and penalties explains the individual offenses and two practical scenarios in detail.

These are two separate laws with separate obligations, and the BBK and BSI can act in parallel. An operator of a critical facility that is also an especially important entity must meet both catalogs of obligations and can be held liable under both frameworks for violations.

How can operators implement both laws without duplicating work?

Both laws draw on the same foundations: a facility and asset inventory, a risk analysis methodology, an incident process with two reporting channels, and business continuity management. Anyone who builds these foundations properly once and maps the requirements of both regimes onto the same measures satisfies two laws with one program.

Four areas overlap in practice:

  • Risk analysis: § 12 KRITISDachG requires a risk analysis for the critical facility, § 30 BSIG a risk management process for the entity. A shared methodology serves both requirements.
  • Operational continuity: the resilience plan under the KRITIS-Dachgesetz and the BCM requirements under NIS2 both draw on the same business continuity management. ISO 22301-compliant BC plans also serve as continuity evidence for the KRITIS-Dachgesetz.
  • Incident management: one detection and assessment process, two reporting channels: to the BBK and to the BSI via the joint reporting platform.
  • Physical security: a core topic of the KRITIS-Dachgesetz, but it also appears in the NIS2 catalog of measures.

The overlap between roughly 29,500 NIS2 entities and operators of roughly 1,700 critical facilities has to serve both catalogs. Without cross-mapping, parallel programs and duplicate audit cycles emerge. With cross-mapping, an investment made for one law becomes evidence for the other. KaitoSec maps both regimes onto the same data model: ISMS and BCMS work in a shared workspace for continuous resilience on one inventory, so the same measure shows up as evidence in both catalogs.

Three steps you can start with now:

  1. Assess whether you're affected under both laws separately: as an operator of critical facilities and as an especially important or important entity.
  2. Prepare both registrations: the BSI portal for NIS2, the BBK platform for the KRITIS-Dachgesetz.
  3. Set up risk analysis and BCM so that both regimes can draw on them, instead of maintaining two separate sets of documents.

Frequently asked questions about the KRITIS-Dachgesetz and NIS2

Does the KRITIS-Dachgesetz replace NIS2?

No. The KRITIS-Dachgesetz regulates the physical resilience of critical facilities, with oversight resting with the BBK. The NIS2UmsuCG regulates cybersecurity, with oversight resting with the BSI. Both laws apply in parallel; operators of critical facilities generally have to satisfy both, which means more obligations than before, not fewer.

Do I have to register twice?

In many cases, yes, but through a shared platform. NIS2 entities register with the BSI. Operators of critical facilities also register with the BBK, via the joint registration platform run by the BBK and BSI under § 8 KRITISDachG, no later than three months after the facility qualifies as critical.

How do I know if my facility is critical?

The standard threshold is 500,000 residents to be supplied (§ 5 KRITISDachG). The facility-specific thresholds are set by the KRITIS ordinance, which as of August 2026 exists only as a draft. Don't wait for the final ordinance: check now, based on the standard threshold, whether your facilities could be affected.

What deadlines apply after KRITIS registration?

After registration, a nine-month deadline applies for the risk analysis (§ 12 KRITISDachG). Resilience measures, a resilience plan, and reporting procedures must be in place after ten months (§§ 13, 18, 20). For incidents: the initial report to the BBK is due within 24 hours, with a detailed report following within one month.

What applies to banks and insurers?

Financial undertakings within the scope of DORA (EU Regulation 2022/2554) are exempt from essential obligations under the KRITIS-Dachgesetz; DORA's requirements take precedence for them (§ 4 para. 2 KRITISDachG). DORA also applies as the specialized regime for cybersecurity relative to NIS2. Banks and insurers therefore address their resilience obligations primarily through DORA.

  • KRITIS-Dachgesetz
  • NIS2
  • CER-Richtlinie
  • BBK
  • Resilience
  • Compliance

Back to the blog