The question almost always arrives in the wrong form. "Are we KRITIS?" is asked about a company, and German law answers it about an installation.
That difference is not pedantry: it is why a large group can hold no critical installation at all while a small operator holds one, and why the assessment has to be repeated at every German site rather than settled once at group level.
Definition and delimitation
Critical infrastructures are organisations and facilities of essential importance to society: their failure or impairment would lead to sustained supply shortfalls, serious disruption to public safety, or other drastic consequences. Under BSI law, what is legally relevant is not the company as a whole but the individual critical installation.
The sectors
The KRITIS concept in BSI law covers, among others, the sectors of energy, water, food, information technology and telecommunications, health, finance and insurance, transport, and municipal waste disposal. What binds are the assignments made by the BSI-Kritisverordnung, the critical infrastructure ordinance, not general descriptions of a sector.
When an installation counts as critical
The BSI-Kritisverordnung sets out categories of installation and thresholds for each sector. Behind all of them sits one reference value, the Regelschwellenwert of 500,000 persons supplied, and this is where most readings go wrong. It is not a test you can apply to your own installation. What the ordinance actually sets, sector by sector, are quantitative thresholds derived from that reference value and expressed in installation-specific metrics: the quantity of energy generated, the volume of water delivered, the number of transactions. Your installation is measured against the figure for its own category, never against a headcount of people supplied.
Operators have to work this out for themselves. Whoever reaches the thresholds is an operator of a critical installation and has to notify the BSI accordingly.
The thresholds are reviewed periodically and adjusted by amendments to the ordinance. For operators that means the classification is not a one-off determination: it has to be reassessed on capacity changes, acquisitions and amendments to the ordinance. Even an operator sitting just below a threshold today should keep the calculation documented in a form somebody else can follow.
KRITIS and NIS2
Since the NIS-2-Umsetzungsgesetz, KRITIS has been embedded in a larger regulatory system.
| Feature | Operators of critical installations | Besonders wichtige and wichtige Einrichtungen |
|---|---|---|
| Trigger | threshold under the BSI-Kritisverordnung | sector under Annex 1 or 2 BSIG plus a size threshold |
| Size criterion | none | employees, turnover, balance sheet total |
| Scope of duties | NIS2 duties plus installation-specific requirements | registration, risk management, reporting |
| Evidence | recurring evidence to the BSI | documentation, evidence on request |
Operators of critical installations count at the same time among the besonders wichtige Einrichtungen. The reverse does not hold: most companies covered by NIS2 operate no critical installation. KRITIS is therefore now a subset of the NIS2 scope, carrying additional requirements. The NIS2 duties supplement the existing evidence processes rather than replacing them.
The practical reading for a group: the size test decides whether German NIS2 duties attach at all, and the installation test decides whether a heavier regime attaches on top. The two are answered from different sources and are easy to conflate.
Physical resilience: the KRITIS-Dachgesetz
While NIS2 addresses cybersecurity, Directive (EU) 2022/2557 is directed at the physical resilience of critical entities, from natural events through sabotage to loss of personnel. It is transposed in Germany by the KRITIS-Dachgesetz, which the Bundestag passed on 29 January 2026, to which the Bundesrat consented on 6 March 2026, and which was promulgated in the Federal Law Gazette. It establishes, among other things, resilience plans and duties to register and to report, and extends supervision to include the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe, the Federal Office of Civil Protection and Disaster Assistance.
For operators that means two interlocking bodies of rules covering the same installations: the BSIG for digital resilience, the KRITIS-Dachgesetz for physical resilience. A combined risk assessment is the more workable route, because protection objectives, criticality assessment and emergency planning overlap to a large extent.