The KRITIS-Dachgesetz (Germany’s umbrella act on critical infrastructure resilience) has been in force since March 2026 (Bundestag 29 January 2026, Bundesrat 6 March 2026, Federal Law Gazette — BGBl. 2026 I No. 66) and transposes the European CER Directive (EU) 2022/2557. For the first time, it obliges around 1,300 operators of critical facilities in ten sectors, uniformly across Germany, to ensure physical resilience — from registration through risk analysis to the resilience plan. The first deadline has already passed: registration with the BBK (Federal Office of Civil Protection) and BSI (Federal Office for Information Security) was due by 17 July 2026. Anyone who missed it should now register without delay and begin the risk analysis in parallel.
Who Is Affected
The Act addresses operators of critical facilities in ten sectors — including energy, water, health and transport. According to the estimates from the legislative process, around 1,300 operators fall under the new obligations. Unlike IT security law, the KRITIS-Dachgesetz targets physical and organisational resilience: it is about facilities, processes and — expressly — personnel, not IT systems alone. The cyber side is regulated in parallel by the BSIG (Act on the Federal Office for Information Security); on the distinction, see the article on personnel security under § 30 BSIG.
The Deadline Cascade: Registration, Risk Analysis, Resilience Plan
The programme of obligations is staggered over time:
- Registration with BBK/BSI by 17 July 2026 — this deadline has passed.
- Risk analysis: within nine months of registration, operators must systematically analyse the risks relevant to their facility.
- Resilience plan: within ten months, operators must set out the technical, organisational and personnel measures with which the identified risks will be addressed.
The cascade means: registration was not the goal, but the starting gun. From now on, the substantive deadlines are running — and the most demanding task, the resilience plan, follows immediately after the risk analysis. Anyone who exhausts the full nine months for the risk analysis has practically no buffer left for the resilience plan. It is therefore advisable to think of both work packages in parallel from the outset: the structure of the resilience plan — which measure categories it must cover, who is responsible internally, which evidence the supervisory authority will expect — can already be set up during the risk analysis.
Deadline Missed — What Now?
Operators who did not register by 17 July 2026 should not postpone registration but complete it without delay. Three reasons favour swift action:
- The registration obligation continues — it does not lapse with the deadline, and the omission grows with each passing day.
- The follow-on deadlines for the risk analysis and resilience plan hinge on registration; late registrants push their entire programme of obligations backward and end up having to explain themselves to the supervisory authority.
- A proactive late registration with a risk analysis already under way documents an intent to comply — waiting documents the opposite.
If in doubt, first cleanly examine whether your facility meets the operator criteria, and document that examination even if the result is negative. Precisely those operators who did not previously fall under IT security law frequently underestimate that the umbrella act sets its own independent criteria — the applicability assessment therefore belongs on record even when it is answered in the negative.
Personnel Security: A Distinct Set of Obligations, Not a Footnote
One aspect is underestimated in many implementation projects: the KRITIS-Dachgesetz — in particular § 13 KRITIS-DachG — and the underlying CER Directive treat the security of personnel as a distinct set of obligations alongside structural and technical measures. Background checks of employees in critical functions are expressly provided for under EU law. Anyone who narrows the resilience plan to fences, sensors and emergency plans leaves out a load-bearing pillar. How the personnel-screening duty can be implemented in concrete terms is shown in the implementation guide for background checks; the distinction from the state security clearance is explained in the article State Security Clearance vs. Employer Screening.
Recommended Course of Action
Clarify three things now, in this order: first, your registration status — if missed, register without delay. Second, the roadmap for the risk analysis, with clear responsibility and a realistic time buffer before the nine-month deadline. Third, personnel security as a dedicated work package in the resilience plan: which roles are critical, what screening depth is appropriate, how is it documented? For the last point, Indicium delivers audit-proof software reports with dated sources and human final review (Art. 22 GDPR) — from €79 per report. We are happy to show you what this looks like in your sector in a demo.
This article provides general information and does not constitute legal advice.