Loading…
Loading…
The KRITIS-Dachgesetz (Dachgesetz zur Stärkung der physischen Resilienz kritischer Anlagen, "umbrella law for strengthening the physical resilience of critical facilities") is Germany's first cross-sector federal statute covering the physical protection of critical infrastructure, sitting alongside the long-standing BSI-Gesetz which governs IT security of critical infrastructure. It transposes EU Directive 2022/2557 (the CER Directive — Critical Entities Resilience), the physical-resilience counterpart to NIS2.
Core mechanics:
wastewater), food, information technology and telecommunications, financial services, health, and federal public administration. The Act empowers BMI to issue an implementing ordinance setting the operator threshold (typical CER-Directive threshold: services supplied to ≥500,000 persons or supra-regional importance).
must (a) register with the BBK (Federal Office for Civil Protection and Disaster Assistance), (b) carry out periodic risk assessments, (c) implement technical, security and organisational resilience measures appropriate to identified risks (perimeter security, business-continuity planning, redundancy, personnel-vetting, supply-chain controls), and (d) report significant incidents to the BBK without undue delay.
a national assessment of risks to critical services, identify "operators of particular European significance" (those supplying essential services to six or more EU Member States), and notify the Commission.
Directive, plus BMI supervisory powers and inspection rights.
The Act is the third leg of Germany's economic-security regulatory architecture, alongside the BSI-Gesetz / NIS2-Umsetzungsgesetz (cyber side) and the AWG/AWV foreign-trade regime (investment screening + dual- use export control). Together these statutes implement the EU's "toolbox" approach: NIS2 (cyber), CER (physical), FDI screening, dual- use export control, and the Foreign Subsidies Regulation.
resilience in Germany — replaces the previous patchwork of sector- specific regulations and voluntary BBK guidance.
TenneT, TransnetBW, E.ON, RWE), water utilities, hospitals, rail (DB Netz), airports (Fraport, Munich), ports (HHLA, Eurogate), and data-centre operators above the threshold.
cyber-physical resilience regime aligned with the EU baseline — closes the gap relative to peer Member States (France LPM/SNAC, Italy PSNC, NL Wbni) that already had comparable statutes.
require resilience-relevant suppliers (perimeter security, redundant power, secure logistics) to evidence compliance with the same regime.
facilities under KRITIS-Dachgesetz fall within the §55 AWV cross-sector investment-review trigger — strengthens FDI control over German critical infrastructure.
identifying critical operators per sector.
was the last large EU Member State to transpose NIS2; the cyber side trails the physical side).
vs the volume of newly-regulated operators.
(e.g., foreign-owned terminal operators, data centres) face heightened scrutiny under the combined KRITIS-Dachgesetz / §55 AWV regime.