KRITIS-Dachgesetz (KRITISDachG)

The KRITIS-Dachgesetz (KRITISDachG) transposes Directive (EU) 2022/2557 into German law and addresses the physical resilience of critical installations. It sits alongside the German BSI Act, which governs security in information technology, and gives the BBK, the Federal Office of Civil Protection and Disaster Assistance, a jurisdiction of its own. It has been in force since 17 March 2026.

NIS2Last reviewed:

Companies that discover this act usually discover it late, and in a specific way: a German site turns out to be a critical installation, and the compliance programme built around NIS2 turns out to answer only half of the German requirements.

The other half is a separate statute, with a separate authority, addressing a separate kind of failure. It applies to the same site.

Two acts, two protective aims

European law deals with the resilience of critical infrastructure through two parallel instruments. Directive (EU) 2022/2555 (NIS2) concerns the security of network and information systems; Directive (EU) 2022/2557 (CER) concerns the physical resilience of critical entities. Germany kept the split.

ActProtective aimAuthority
BSI-Gesetz (BSIG)security in information technologyBSI
KRITIS-Dachgesetz (KRITISDachG)physical resilience of critical installationsBBK

For operators of critical installations this means being covered twice, with two points of contact. An outage caused by a cyberattack and an outage caused by sabotage, a natural event or a power failure are addressed by different bodies of rules, while affecting the same installation.

Anyone who has already been through a CER transposition in another Member State will recognise the architecture. What is German is the allocation of authority to the BBK and the interlocking with the BSIG described below.

The current state of the law

The official short title is KRITISDachG. The second half of the name, Dachgesetz, is literally an "umbrella act", the term German drafting uses for a statute that frames a field rather than exhausting it.

The act of 11 March 2026 was promulgated in the Federal Law Gazette, BGBl. 2026 I no. 66, and has been in force since 17 March 2026 under Article 11(1); § 14(3) to (5) apply only from 1 January 2030. It was amended by Article 8 of the act of 21 July 2026 (BGBl. 2026 I no. 221). It runs to 26 sections, of which § 26 has lapsed.

The ten sectors of § 4

§ 4(1) KRITISDachG lists ten sectors: energy; transport and traffic; finance; social security services and basic income support for jobseekers; health; water; food; information technology and telecommunications; space; and municipal waste management.

The list is broader than the duty programme. § 4(2) exempts DORA financial entities and the information technology and telecommunications sector entirely from the core duties (risk analysis, resilience, reporting, management-body duties); for municipal waste management and social security, only § 12 remains. Anyone operating in one of those sectors should check § 4(2) first.

The duties, and when they start

DutyProvisionStarts
Registration with the BBK (joint facility with the BSI)§ 8(1)three months after an installation counts as a critical installation
Risk analysis and risk assessment§ 12(1)nine months after registration, then at least every four years
Resilience measures and resilience plan§ 13ten months after registration
Incident reporting§ 18ten months after registration
Management-body duties§ 20ten months after registration

The deadlines in the last four rows sit in § 8(7) and run from registration, not from the act's entry into force. An operator not yet established as running a critical installation has no clock running at all. The procedure itself is not yet set: under § 8(8) the BBK fixes it only within four weeks of the ordinance under § 4(3) and § 5(1) entering into force, and that ordinance has not yet been issued. The resilience plan under § 13(4) is more than a list of measures: it has to show the reasoning behind them.

Two reporting channels, two clocks

Operators of critical installations report under both acts, but on different clocks.

§ 18 KRITISDachG (incident)§ 32 BSIG (significant security incident)
First report24 hours from becoming aware24 hours from becoming aware
Second stagenone; the initial report is updated if the incident continuesreport within 72 hours of becoming aware
Detailed reportdetailed report one month after becoming aware of the incidentfinal report one month after the 72-hour report

Both reports go to the joint reporting office run by the BSI and the BBK, but the one-month deadline refers to a different event in each act.

How it interlocks with the BSIG

The two acts are bound together as a matter of drafting technique. § 2 no. 22 BSIG does not define the "kritische Anlage", the critical installation, itself: it refers on to § 2 no. 3 KRITISDachG. So who counts as an operator of a critical installation under the BSIG is determined by the KRITIS-Dachgesetz.

That is why a German scope assessment cannot be completed out of the BSIG alone, and why a diligence checklist built only around NIS2 will miss an entire category of German obligation.

The regimes also mesh operationally. Registration under § 33 BSIG runs through a registration facility that the BSI and the BBK have set up jointly, and reports under § 32 BSIG go to a reporting office run jointly by the two authorities. Running the other way, § 2 no. 2 KRITISDachG draws a line: software and IT services that do not directly control, monitor or support a physical process are governed exclusively by the BSI Act.

The single point of contact within the meaning of Article 9(2) of Directive (EU) 2022/2557 is, under § 3(1), the BBK, but it is not the sole supervisor. § 3(2) names further competent authorities depending on the critical service, among them the Bundesnetzagentur, BaFin and the BSI.

What the figure of 500,000 actually is

§ 5(2) sentence 2 KRITISDachG provides that the standard value is, in principle, 500,000 inhabitants to be supplied by an installation. That number is widely misread as a test that can be applied directly.

It is a reference value, from which the values that actually govern are derived. The BSI-Kritisverordnung, the critical infrastructure ordinance, describes it as a "Regelschwellenwert von 500 000 versorgten Personen" (a standard threshold of 500,000 persons supplied) and uses it exclusively in its calculation formulas. What has to be applied are the sector-specific thresholds, expressed for instance in megawatts, in cubic metres per year, or in case numbers per year.

And the test is carried out at installation level, not at company level. A large company can operate without a critical installation; a small one can operate a critical installation. For a group, that is the sentence to take away: the question is not how big you are, it is what a particular German site does.

What happens to the BSI-Kritisverordnung

The BSI-Kritisverordnung continues to apply. Its § 12 provides that it ceases to have effect only once the ordinance under § 4(3) and § 5(1) KRITISDachG is issued, and that has not yet happened. For determining which installations are critical, the BSI-Kritisverordnung therefore remains the source that matters for the time being.

What this means for an operator

Assess and document scope separately for each regime. The measures overlap less than people hope: access control, perimeter security, emergency power and personnel security are physical subjects, while §§ 30 and 31 BSIG are aimed at information technology systems.

Business continuity management is the bracket in which both perspectives meet, and it is where a combined treatment pays off most: one set of criticality ratings, one set of recovery objectives, two sets of controls hanging off them. Sanctions follow § 24; the top tier, up to €1 million under § 24(2), applies to defying an enforceable order issued under § 8(2) sentence 1.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework