What the KRITIS umbrella law actually changes
The new Act significantly broadens the previous scope of KRITIS regulation. Whilst existing requirements – such as those set out in the IT Security Act and NIS2 – primarily address cyber risks, the KRITIS umbrella Act takes a more comprehensive approach to the physical protection of critical infrastructure.
The most important changes relate primarily to resilience measures, registration and reporting obligations, and government oversight.
1. Holistic risk analyses become mandatory
A key change is the mandatory systematic risk analysis for operators of critical infrastructure.
In future, KRITIS operators must regularly carry out more comprehensive analyses of the threats to which their critical facilities and services are exposed.
Factors to be taken into account include, amongst others:
- natural disasters and extreme weather
- Sabotage and physical attacks
- Technical failures
- cross-sectoral risks
- Geopolitical and hybrid threats
- Supply chain dependencies
These risk analyses form the basis for all further measures to ensure the resilience of critical infrastructure.
2. New requirements for resilience and protective measures
Based on the risk analysis, KRITIS operators must implement appropriate technical and organisational measures to ensure the operational capability of critical services.
Key requirements under the KRITIS Framework Act include, amongst others:
- Protection of critical facilities against physical access (resilience plan)
- Security concepts for critical sites (physical protection)
- Redundancies for central systems (risk management)
- Emergency and crisis management (business continuity management)
- Raising awareness amongst staff and service providers
The aim is to maintain critical services as far as possible, or to restore them swiftly, even in the event of disruptions or crisis situations.
3. Extended registration and reporting obligations
The KRITIS Framework Act also introduces new registration and reporting obligations for operators of critical infrastructure.
Organisations covered by the legislation must in future register centrally via a platform provided by the BBK and the BSI. The three-month registration period begins upon the entry into force of the KRITIS Regulation, which specifically defines the group of operators concerned. Once registration is complete, operators have nine months to carry out the risk analysis. The implementation of the necessary resilience measures and the first reporting obligation must be fulfilled within ten months of registration. Violations may result in fines of up to one million euros. In addition, organisations are obliged to set up a central point of contact for the authorities. In cases of doubt, the BBK may also register organisations on its own initiative.
Furthermore, operators must report significant security-related incidents to the relevant authorities via a central reporting point, for example:
- major failures of critical systems (initial report to be submitted within 24 hours at the latest)
- attempts at sabotage or security breaches
- serious disruptions to critical processes
In the case of ongoing or evolving incidents, reports must also be continuously updated so that authorities receive the most up-to-date picture of the situation. A detailed final report or status report must also be submitted to the relevant authorities within one month at the latest.
These registration and reporting obligations are intended to provide a better overview of risks and threats to critical infrastructure.
4. Greater oversight of KRITIS operators
Another important aspect of the KRITIS framework law is increased state supervision of critical infrastructure operators.
In future, the authorities will be able, amongst other things, to:
- Request evidence of security and resilience measures
- carry out inspections
- impose sanctions in the event of breaches
For operators, this means that resilience measures must be documented in a transparent manner and be subject to audit.
What KRITIS operators should do specifically now
For many organisations, the most important next step is to review their existing security and risk management structures in light of the new KRITIS requirements.
The focus here is particularly on the following questions:
- Have all critical facilities and services been identified?
- Is there a comprehensive risk analysis for relevant threat scenarios?
- Are emergency and crisis management processes sufficiently established?
- Are there clear responsibilities for KRITIS compliance?
- Have registration and reporting processes been defined?
A structured self-assessment helps to identify potential gaps at an early stage.
KRITIS Framework Act Checklist: Are you prepared for the new KRITIS requirements?
The following checklist helps organisations and public authorities to review their preparedness for the KRITIS Framework Act.
Scope of application and regulatory analysis
- Does your organisation belong to a sector covered by the KRITIS Framework Act?
- Have critical infrastructure and critical services been identified?
- Have the regulatory requirements under the KRITIS Framework Act, NIS2 and the IT Security Act been analysed?
- Have preparations been made for timely registration via the central platform?
- Has a central point of contact for regulatory authorities been designated?
Risk analysis
- Is there a structured risk analysis in place for critical infrastructure and services?
- Are natural, technical or human risks taken into account?
- Have scenarios such as natural disasters, sabotage or system failures been analysed?
Resilience measures
- Are there security measures in place to protect critical facilities?
- Are there redundancies in place for critical systems and processes?
- Are protective measures reviewed regularly?
Business Continuity and Crisis Management
- Is there a business continuity management (BCM) system in place?
- Are there emergency and crisis plans in place for critical scenarios?
- Are crisis drills carried out regularly?
Governance and reporting processes
- Have responsibilities for KRITIS compliance been defined?
- Are there processes in place for reporting security-related incidents?
- Have processes been established for ongoing updates and final reports?
- Are security measures documented and audit-ready?
How Materna can support KRITIS operators
Implementing the new KRITIS requirements often necessitates changes to organisation, technology and governance. Materna supports KRITIS operators in the structured implementation of the KRITIS framework legislation, including through:
- KRITIS readiness assessments to evaluate the current level of maturity
- Conducting risk and resilience analyses
- Establishing business continuity management
- Developing modern security architectures
- Support with compliance and audits
This enables companies and public authorities not only to meet regulatory requirements, but also to strengthen their resilience to crises and disruptions in the long term.
Further information
Critical infrastructure