Critical Infrastructure (KRITIS)

Critical infrastructures — KRITIS in German usage — are organisations and facilities of essential importance to society whose failure would cause serious supply shortfalls or endanger public safety. In German law the concept is given shape by the BSI Act and the BSI-Kritisverordnung; what decides it is the sector and the threshold.

NIS2Last reviewed:

The question almost always arrives in the wrong form. "Are we KRITIS?" is asked about a company, and German law answers it about an installation.

That difference is not pedantry: it is why a large group can hold no critical installation at all while a small operator holds one, and why the assessment has to be repeated at every German site rather than settled once at group level.

Definition and delimitation

Critical infrastructures are organisations and facilities of essential importance to society: their failure or impairment would lead to sustained supply shortfalls, serious disruption to public safety, or other drastic consequences. Under BSI law, what is legally relevant is not the company as a whole but the individual critical installation.

The sectors

The KRITIS concept in BSI law covers, among others, the sectors of energy, water, food, information technology and telecommunications, health, finance and insurance, transport, and municipal waste disposal. What binds are the assignments made by the BSI-Kritisverordnung, the critical infrastructure ordinance, not general descriptions of a sector.

When an installation counts as critical

The BSI-Kritisverordnung sets out categories of installation and thresholds for each sector. Behind all of them sits one reference value, the Regelschwellenwert of 500,000 persons supplied, and this is where most readings go wrong. It is not a test you can apply to your own installation. What the ordinance actually sets, sector by sector, are quantitative thresholds derived from that reference value and expressed in installation-specific metrics: the quantity of energy generated, the volume of water delivered, the number of transactions. Your installation is measured against the figure for its own category, never against a headcount of people supplied.

Operators have to work this out for themselves. Whoever reaches the thresholds is an operator of a critical installation and has to notify the BSI accordingly.

The thresholds are reviewed periodically and adjusted by amendments to the ordinance. For operators that means the classification is not a one-off determination: it has to be reassessed on capacity changes, acquisitions and amendments to the ordinance. Even an operator sitting just below a threshold today should keep the calculation documented in a form somebody else can follow.

KRITIS and NIS2

Since the NIS-2-Umsetzungsgesetz, KRITIS has been embedded in a larger regulatory system.

FeatureOperators of critical installationsBesonders wichtige and wichtige Einrichtungen
Triggerthreshold under the BSI-Kritisverordnungsector under Annex 1 or 2 BSIG plus a size threshold
Size criterionnoneemployees, turnover, balance sheet total
Scope of dutiesNIS2 duties plus installation-specific requirementsregistration, risk management, reporting
Evidencerecurring evidence to the BSIdocumentation, evidence on request

Operators of critical installations count at the same time among the besonders wichtige Einrichtungen. The reverse does not hold: most companies covered by NIS2 operate no critical installation. KRITIS is therefore now a subset of the NIS2 scope, carrying additional requirements. The NIS2 duties supplement the existing evidence processes rather than replacing them.

The practical reading for a group: the size test decides whether German NIS2 duties attach at all, and the installation test decides whether a heavier regime attaches on top. The two are answered from different sources and are easy to conflate.

Physical resilience: the KRITIS-Dachgesetz

While NIS2 addresses cybersecurity, Directive (EU) 2022/2557 is directed at the physical resilience of critical entities, from natural events through sabotage to loss of personnel. It is transposed in Germany by the KRITIS-Dachgesetz, which the Bundestag passed on 29 January 2026, to which the Bundesrat consented on 6 March 2026, and which was promulgated in the Federal Law Gazette. It establishes, among other things, resilience plans and duties to register and to report, and extends supervision to include the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe, the Federal Office of Civil Protection and Disaster Assistance.

For operators that means two interlocking bodies of rules covering the same installations: the BSIG for digital resilience, the KRITIS-Dachgesetz for physical resilience. A combined risk assessment is the more workable route, because protection objectives, criticality assessment and emergency planning overlap to a large extent.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyEU-hostedMulti-framework