Skip to main content
ISMS

KRITIS 2025: What Will Change Under the New KRITIS Framework Act

KRITIS 2025 explains how the new German KRITIS Framework Act will redefine physical resilience, risk management and reporting duties for critical infrastructure operators. Learn what changes, who is affected, and what organisations must prepare now.

Srdan Manasijevic

Srdan Manasijevic

CEO

KRITIS 2025: What Will Change Under the New KRITIS Framework Act

1. Title & Introduction

KRITIS 2025: What Will Change with the New KRITIS Framework Act

KRITIS in Transition Critical infrastructures are the backbone of modern societies. Without reliable energy supply, communication networks, healthcare or transport logistics, everyday life comes to a standstill – and with it political stability and economic performance.

With the new KRITIS Framework Act, the German government is setting the course for a more comprehensive and structured approach to protection. The aim is to strengthen the resilience of critical facilities against physical threats such as natural disasters, sabotage or system failures – in addition to existing IT security requirements.

This article provides an overview of what the new KRITIS Act is intended to change, who is affected, and what operators of critical facilities should know and start preparing for now.


2. Current State of KRITIS in Germany

Current State of KRITIS in Germany Up to now, the protection of critical infrastructures in Germany has been heavily focused on IT security. The IT Security Act, the BSI Act (BSIG), sector-specific rules in the Energy Industry Act and Telecommunications Act, as well as the first NIS Directive, have created important standards – primarily to protect digital systems against cyberattacks.

Physical risks – such as extreme weather events, sabotage or disruptions to supply chains – have often remained under-regulated. A cross-sector legal framework for physical resilience has been missing. At the same time, the threat landscape has shifted due to global crises, geopolitical tensions and coordinated attacks.

EU Directive 2022/2557, which entered into force in January 2023, calls for an all-hazards approach and obliges Member States to transpose it into national law by October 2024. This is the point of departure for the new KRITIS Framework Act.


3. Why a New KRITIS Framework Act?

Why a New KRITIS Framework Act? The KRITIS Framework Act is the German government’s response to the new European legal framework and the increasing need to protect critical infrastructures more comprehensively. While previous laws such as the BSIG have focused mainly on cyber risks, the new framework act introduces a cross-sector approach to physical protection.

It transposes EU Directive 2022/2557 into national law and defines harmonised minimum obligations for operators of critical entities: from prevention and response through to recovery after disruptions. At its core is a full resilience cycle.

The KRITIS Framework Act serves as an overarching legal framework and establishes common minimum standards – for example through mandatory risk assessments, resilience plans and incident reporting. Together with NIS2 (for digital security) and other regulations such as DORA, it creates a holistic approach combining physical and cyber resilience.


4. What Does the KRITIS Framework Act Regulate in Practice?

What Does the KRITIS Framework Act Regulate in Practice? The KRITIS Framework Act introduces, for the first time, a uniform cross-sector legal framework for the physical protection of critical facilities. It targets operators whose failure would have significant impacts on security of supply or public order.

Key elements include:

  • Risk Assessment & Resilience Planning (§ 12, § 13) Regular risk analyses (at least every four years) and resilience plans based on them, covering technical, structural, organisational and personnel measures.

  • Incident Reporting (§ 18) Significant disruptions must be reported within 24 hours to a central platform operated jointly by BBK and BSI, followed by a detailed follow-up report.

  • Definition & Registration of Critical Facilities (§ 8) Uniform national criteria (including degree of supply, e.g. > 500,000 people served) define which facilities are “critical”. These operators must register centrally.

  • Resilience Targets & Example Measures (§ 13 para. 3) The Act formulates objectives rather than rigid catalogues and provides non-binding examples such as structural protection, access control, backup power supply or crisis management.

  • Responsibilities & Oversight (§ 3) Supervision lies with different federal and state authorities depending on the sector, coordinated by the BBK.

In short, the KRITIS Framework Act regulates the “how” of resilience – procedures, minimum standards and responsibilities – while detailed requirements are developed via ordinances and recognised sector-specific standards (§ 14).


5. Which Organisations Are Affected?

Which Organisations Are Affected? The KRITIS Framework Act applies to operators of so-called critical facilities. A facility is considered critical if its failure or impairment would have serious consequences for security of supply or public order.

Classification is based on criteria to be set out in a regulation. A key factor is the degree of supply – as a rule of thumb, facilities serving more than 500,000 people are considered critical. Dependencies with other sectors, available alternatives and geographic reach are also taken into account.

The Act initially covers ten sectors (§ 4 KRITIS-DachG):

  • Energy

  • Transport and traffic

  • Financial sector

  • Social security and basic welfare

  • Healthcare

  • Water

  • Food

  • Information technology and telecommunications

  • Space

  • Municipal waste management

Operators of critical facilities in these sectors are in scope – regardless of legal form or ownership structure. Companies with multiple sites or cross-border activities must assess each relevant facility individually.

Facilities of particular European significance – for example those providing essential services in or for at least six EU Member States – are subject to additional rules (§§ 9–10).

Key deadlines: Operators must register by July 2026 at the latest and then have nine to ten months to meet their obligations on resilience planning and implementation (§ 8 para. 7).


6. New Obligations for Operators of Critical Facilities

New Obligations for Operators of Critical Facilities The KRITIS Framework Act introduces binding obligations for physical protection for the first time. The focus is on structured resilience, documentation and continuous improvement:

  • Risk Analysis & Assessment (§ 12) Every four years – or more frequently if needed – operators must conduct systematic risk analyses, covering technical, natural, personnel and geopolitical risks as well as interdependencies with other sectors.

  • Resilience Plan (§ 13) Based on the risk analysis, a documented resilience plan must be prepared. It includes measures to prevent, limit and manage incidents (e.g. structural protection, access control, backup power, crisis response, alternative supply chains).

  • Training & Personnel Measures Staff and external service providers must be specifically trained, e.g. through information materials, exercises and scenario-based training.

  • Contact Point & Reporting Obligations (§§ 8, 18) Operators must appoint a central contact point and report significant incidents within 24 hours via a digital platform run by BBK and BSI, followed by detailed follow-up reports.

  • Evidence & Inspections (§ 16) Authorities can request documentation and audits. Any deficiencies must be remedied via binding action plans, following a risk-based supervisory approach.


7. How Does the KRITIS Act Interact with Existing IT Security Rules?

How Does the KRITIS Act Interact with Existing IT Security Rules? The KRITIS Framework Act complements, rather than replaces, existing IT security legislation such as the BSIG and the NIS2 implementation act (NIS2UmsuCG). While these focus on digital systems and cyberthreats, the KRITIS Act emphasises physical resilience and follows an all-hazards approach.

Interfaces between IT security and physical protection are intended to be harmonised – for instance through a joint reporting platform for incidents under both BSIG and the KRITIS Act (§ 18). Existing security measures can be credited towards the new obligations if they are equivalent in substance (§ 17).

Organisations already working on NIS2 readiness can build on their existing processes and structures – but need to assess whether physical protection is addressed in the same depth.


8. Sector Standards & Implementation Support (incl. Digital Tools)

Sector Standards & Implementation Support The KRITIS Framework Act is deliberately open to sector-specific solutions. Instead of prescribing rigid requirements for all sectors, it defines minimum standards which can be replaced by recognised industry standards (§ 14 para. 2). Industry associations and operators may develop their own resilience standards, subject to review and recognition by the BBK.

The BBK is also tasked with providing templates and guidance for risk analyses, resilience plans, training and reporting procedures, giving particularly small and medium-sized enterprises practical support.

Safety concepts already implemented under IT security or other legal regimes may be credited if they meet the requirements of the KRITIS Act (§ 17).

Digital Tools for Resilience To efficiently manage risk analyses, resilience planning, training and reporting, organisations should rely on integrated GRC, ISMS or BCM solutions. These tools help with structured workflows, central evidence management, reminders and consistent documentation – and make it easier to align NIS2 and KRITIS requirements.


9. Opportunities & Challenges for Organisations

Opportunities & Challenges for Organisations

Challenges

  • Organisational Effort: New processes and responsibilities must be established, including risk analyses and resilience plans.

  • Unclear Responsibilities: Many companies must first define who is responsible for physical resilience (e.g. management, facilities, BCM).

  • Legal Uncertainty: Many details will only be clarified through secondary legislation. Organisations must prepare early and remain adaptable.

  • Costs: Legislators expect significant one-off and recurring costs – resilience requires investment in structures, technology and people.

Opportunities

  • Increased Availability: Better preparation limits damage and stabilises entire supply networks.

  • Reputational Benefits: Demonstrable resilience management becomes a strong trust indicator for customers, partners and regulators.

  • Competitive Edge: Early movers can position themselves as leaders and perform better in tenders and audits.

  • Stronger Internal Processes: Scenario-based thinking, cross-functional teams and better documentation enhance overall crisis readiness.


10. Conclusion: What Organisations Should Do Now

Conclusion: What Organisations Should Do Now Even though many details of the KRITIS Framework Act will only be specified in secondary legislation, the direction is clear: critical infrastructures must become significantly more resilient. Organisations likely to be in scope should act now:

  1. Assess Exposure

    • Does the organisation operate in one of the ten covered sectors?

    • Does it serve more than 500,000 people or perform system-critical functions?

    • Does it provide essential services in or for multiple EU Member States?

  2. Clarify Responsibilities

    • Who is responsible for physical resilience, risk analysis and reporting?

    • How are IT security and physical protection integrated organisationally?

    • Should a cross-functional resilience or BCM team be established?

  3. Start Preparations

    • Prepare an initial risk assessment using existing information

    • Identify and document existing measures and concepts

    • Design internal incident and reporting workflows

    • Monitor guidance from BBK, BSI and industry associations

Resilience is not a one-off project but an ongoing journey. The KRITIS Framework Act provides the legal framework – real crisis readiness is decided in day-to-day implementation.


11. Q&A / FAQ (English)

Question 1

What is the KRITIS Framework Act?

The KRITIS Framework Act is a new nationwide legal framework designed to strengthen the physical resilience of critical infrastructures in Germany. It obliges operators of critical facilities to conduct regular risk assessments, establish resilience plans and report significant disruptions.


Question 2

Who is affected by the KRITIS Act?

The Act applies to operators of critical facilities in ten defined KRITIS sectors, such as energy, healthcare, transport or IT and telecommunications. A key factor is whether a facility serves more than 500,000 people or performs a system-critical function.


Question 3

What obligations arise under the KRITIS Act?

Operators must regularly assess risks, draw up a resilience plan, train staff and report significant incidents within 24 hours to a central reporting platform. They must also appoint a contact point and be able to provide documentation and evidence to supervisory authorities.


Question 4

When does the new KRITIS Act apply?

EU requirements must be transposed into national law by October 2024 at the latest. For affected organisations, the first obligations will apply by July 2026, by which time registration and implementation of the resilience requirements must be completed.


Question 5

What is the difference between the KRITIS Act and NIS2?

NIS2 focuses primarily on the security of network and information systems and addresses mainly cyber risks. The KRITIS Framework Act centres on the physical resilience of critical facilities and follows an all-hazards approach. Both regimes are designed to work together: NIS2 strengthens digital security, while the KRITIS Act complements it with structural, organisational and personnel measures.

Srdan Manasijevic

Srdan Manasijevic

CEO

Expert in information security, data protection and risk management with extensive experience advising enterprises and public-sector organizations. Specialized in ISO 27001, BSI and advanced risk methodologies.

From reading to doing: your ISMS with fuentis

ISO 27001, BSI IT-Grundschutz, TISAX and NIS2 in one platform – the free/Basic plan is €0 for 12 months.