Companies that discover this act usually discover it late, and in a specific way: a German site turns out to be a critical installation, and the compliance programme built around NIS2 turns out to answer only half of the German requirements.
The other half is a separate statute, with a separate authority, addressing a separate kind of failure. It applies to the same site.
Two acts, two protective aims
European law deals with the resilience of critical infrastructure through two parallel instruments. Directive (EU) 2022/2555 (NIS2) concerns the security of network and information systems; Directive (EU) 2022/2557 (CER) concerns the physical resilience of critical entities. Germany kept the split.
| Act | Protective aim | Authority |
|---|---|---|
| BSI-Gesetz (BSIG) | security in information technology | BSI |
| KRITIS-Dachgesetz (KRITISDachG) | physical resilience of critical installations | BBK |
For operators of critical installations this means being covered twice, with two points of contact. An outage caused by a cyberattack and an outage caused by sabotage, a natural event or a power failure are addressed by different bodies of rules, while affecting the same installation.
Anyone who has already been through a CER transposition in another Member State will recognise the architecture. What is German is the allocation of authority to the BBK and the interlocking with the BSIG described below.
The current state of the law
The official short title is KRITISDachG. The second half of the name, Dachgesetz, is literally an "umbrella act", the term German drafting uses for a statute that frames a field rather than exhausting it.
The act of 11 March 2026 was promulgated in the Federal Law Gazette, BGBl. 2026 I no. 66, and has been in force since 17 March 2026 under Article 11(1); § 14(3) to (5) apply only from 1 January 2030. It was amended by Article 8 of the act of 21 July 2026 (BGBl. 2026 I no. 221). It runs to 26 sections, of which § 26 has lapsed.
The ten sectors of § 4
§ 4(1) KRITISDachG lists ten sectors: energy; transport and traffic; finance; social security services and basic income support for jobseekers; health; water; food; information technology and telecommunications; space; and municipal waste management.
The list is broader than the duty programme. § 4(2) exempts DORA financial entities and the information technology and telecommunications sector entirely from the core duties (risk analysis, resilience, reporting, management-body duties); for municipal waste management and social security, only § 12 remains. Anyone operating in one of those sectors should check § 4(2) first.
The duties, and when they start
| Duty | Provision | Starts |
|---|---|---|
| Registration with the BBK (joint facility with the BSI) | § 8(1) | three months after an installation counts as a critical installation |
| Risk analysis and risk assessment | § 12(1) | nine months after registration, then at least every four years |
| Resilience measures and resilience plan | § 13 | ten months after registration |
| Incident reporting | § 18 | ten months after registration |
| Management-body duties | § 20 | ten months after registration |
The deadlines in the last four rows sit in § 8(7) and run from registration, not from the act's entry into force. An operator not yet established as running a critical installation has no clock running at all. The procedure itself is not yet set: under § 8(8) the BBK fixes it only within four weeks of the ordinance under § 4(3) and § 5(1) entering into force, and that ordinance has not yet been issued. The resilience plan under § 13(4) is more than a list of measures: it has to show the reasoning behind them.
Two reporting channels, two clocks
Operators of critical installations report under both acts, but on different clocks.
| § 18 KRITISDachG (incident) | § 32 BSIG (significant security incident) | |
|---|---|---|
| First report | 24 hours from becoming aware | 24 hours from becoming aware |
| Second stage | none; the initial report is updated if the incident continues | report within 72 hours of becoming aware |
| Detailed report | detailed report one month after becoming aware of the incident | final report one month after the 72-hour report |
Both reports go to the joint reporting office run by the BSI and the BBK, but the one-month deadline refers to a different event in each act.
How it interlocks with the BSIG
The two acts are bound together as a matter of drafting technique. § 2 no. 22 BSIG does not define the "kritische Anlage", the critical installation, itself: it refers on to § 2 no. 3 KRITISDachG. So who counts as an operator of a critical installation under the BSIG is determined by the KRITIS-Dachgesetz.
That is why a German scope assessment cannot be completed out of the BSIG alone, and why a diligence checklist built only around NIS2 will miss an entire category of German obligation.
The regimes also mesh operationally. Registration under § 33 BSIG runs through a registration facility that the BSI and the BBK have set up jointly, and reports under § 32 BSIG go to a reporting office run jointly by the two authorities. Running the other way, § 2 no. 2 KRITISDachG draws a line: software and IT services that do not directly control, monitor or support a physical process are governed exclusively by the BSI Act.
The single point of contact within the meaning of Article 9(2) of Directive (EU) 2022/2557 is, under § 3(1), the BBK, but it is not the sole supervisor. § 3(2) names further competent authorities depending on the critical service, among them the Bundesnetzagentur, BaFin and the BSI.
What the figure of 500,000 actually is
§ 5(2) sentence 2 KRITISDachG provides that the standard value is, in principle, 500,000 inhabitants to be supplied by an installation. That number is widely misread as a test that can be applied directly.
It is a reference value, from which the values that actually govern are derived. The BSI-Kritisverordnung, the critical infrastructure ordinance, describes it as a "Regelschwellenwert von 500 000 versorgten Personen" (a standard threshold of 500,000 persons supplied) and uses it exclusively in its calculation formulas. What has to be applied are the sector-specific thresholds, expressed for instance in megawatts, in cubic metres per year, or in case numbers per year.
And the test is carried out at installation level, not at company level. A large company can operate without a critical installation; a small one can operate a critical installation. For a group, that is the sentence to take away: the question is not how big you are, it is what a particular German site does.
What happens to the BSI-Kritisverordnung
The BSI-Kritisverordnung continues to apply. Its § 12 provides that it ceases to have effect only once the ordinance under § 4(3) and § 5(1) KRITISDachG is issued, and that has not yet happened. For determining which installations are critical, the BSI-Kritisverordnung therefore remains the source that matters for the time being.
What this means for an operator
Assess and document scope separately for each regime. The measures overlap less than people hope: access control, perimeter security, emergency power and personnel security are physical subjects, while §§ 30 and 31 BSIG are aimed at information technology systems.
Business continuity management is the bracket in which both perspectives meet, and it is where a combined treatment pays off most: one set of criticality ratings, one set of recovery objectives, two sets of controls hanging off them. Sanctions follow § 24; the top tier, up to €1 million under § 24(2), applies to defying an enforceable order issued under § 8(2) sentence 1.