Registration is the moment a KRITIS duty set starts running, and since 2026 it happens in two places. An operator registers twofold: as a besonders wichtige Einrichtung in the BSI portal under § 33 BSIG, and, once the Identifizierungsverordnung of the KRITIS-Dachgesetz enters into force, its critical plants with the BBK within three months (§ 8 KRITISDachG). Every three years it then demonstrates to the BSI that its risk-management and attack-detection measures are in place (§ 39 BSIG).
Is my plant critical? The self-assessment behind the Meldung
Whether any of this applies is decided by a threshold test, and the operator runs it. The BSI-Kritisverordnung sets a supply threshold per plant category, and every year, by 31 March, the operator must check whether a plant crossed that threshold during the previous year. Criticality then applies from 1 April of the following year. The lag matters: a plant that grows past its threshold in 2026 pulls the operating entity into the duty net from 1 April 2027, which is where unplanned registration emergencies usually begin.
The threshold applies per plant, not per company: size, revenue and headcount play no role, and only the gemeinsame Anlage construct bundles plants together. Document the result either way. A negative self-assessment on paper is the defensible baseline when a supervisor, insurer or major customer asks why no registration was filed, and the day a plant becomes critical starts the registration clock.
Registering with the BSI: § 33 BSIG, MIP and the second registration
Registration at the BSI is twofold. Operators of critical plants register under § 33 BSIG through the Melde- und Informationsportal (MIP), the filing channel at mip2.bsi.bund.de. In a second step, the operator registers as a besonders wichtige Einrichtung in the BSI-Portal, possible since 6 January 2026 and authenticated with a Mein Unternehmenskonto or an ELSTER organisational certificate.
The old law knew this duty as the Betriebsaufnahme-Meldung under § 8b Abs. 3 BSIG, filed at the latest on the first working day after becoming an operator. The new law carries it forward in § 33; the anchor date remains the day the plant became critical.
Two governance points follow. The organisational certificate binds the filing to the company rather than a private mailbox, so portal access belongs with the privileged accounts. And MIP stays the priority channel for incident notifications under § 32 BSIG until 31 July 2026: the account created at registration is the one a 24-hour incident clock runs through.
The second registration at the BBK: § 8 KRITIS-Dachgesetz
The Dachgesetz adds a parallel registration with a different regulator. The act has been in force since 17 March 2026, but the Identifizierungsverordnung that triggers the operator duties was still in preparation at the time of research, so BBK registration duties are not yet running. Once the ordinance enters into force, § 8 Abs. 1 requires registration within three months of a plant becoming critical.
The filing must contain eight data elements, including the sector, the Versorgungsgrad, public IP ranges, critical components and the contact point. The BBK confirms within four weeks and can register a plant ex officio where an operator does not act.
Two channels, two regulators, one plant: the BSI asks for cyber evidence, the BBK for physical and organisational resilience. Registering in only one channel is the most common structural gap in dual-regime situations. What follows a BBK registration, the risk analysis after nine months and the resilience duties after ten, is the subject of the article on KRITIS-Dachgesetz deadlines.
What must the Nachweisprüfung document?
The Nachweisprüfung is the periodic proof to the BSI that the mandated measures exist and work. Under § 39 Abs. 1 BSIG, the first evidence is due earliest three years after becoming an operator, and afterwards every three years. The rhythm is new: until December 2025 the cycle was two years under the old § 8a. The BSI has set the new dates individually, with a transition option for proof dates within twelve months of 6 December 2025.
The examination follows the BSI’s orientation guidance (GAiN 22) and lands in the Nachweisdokument P, structured into the sections PD, PE and PS. The scope documentation in Anlage PD.A must depict the critical service completely: processes, systems, third-party-operated parts and interfaces, captured in a Netzstrukturplan that also marks where attack-detection systems cover the network. Those systems have been mandatory since 1 May 2023 under § 31 BSIG. Results include a defect list (Mängelliste PE.A) with a remediation plan; the four-eyes principle applies to scope, certificates, risk approach, defect list and on-site checks; and the examination must end no more than twelve months before submission.
Who may examine is regulated too: the Prüfende Stelle must be unternehmensfremd and legally and economically independent. Internal audit qualifies only where quality assurance to IIA standard is no older than five years. Certificates help, but only as components: ISO 27001, C5 or IT-Grundschutz require a KRITIS-specific add-on examination under GAiN N.BG.01–06, with a certificate audit no more than twelve months old. Submission runs via MIP.
What weak evidence looks like in an audit
Weak evidence follows recognisable patterns, all avoidable before the auditor arrives. A scope that does not fully depict the critical service, because third-party-operated segments are missing, fails the GAiN criteria (N.DG.01/02) before any measure is discussed. A Netzstrukturplan without attack-detection markings documents a § 31 duty on paper only. In the follow-up cycle, the previous defect list must be handed over with the remediation status documented (GAiN D.AM.02/03); an operator arriving without it starts from zero.
The Dachgesetz adds a second audience. The zuständige Behörde audits resilience duties on a risk-based sample and can request parts of the § 39 evidence through the BBK and demand the Resilienzplan (§ 16 KRITISDachG). A gap filed in one procedure therefore does not stay there.
Who registers, who is the contact point, and who is vetted
Registration binds the operator as a legal entity: the ELSTER organisational certificate or Mein Unternehmenskonto belongs to the company, not to an individual. The filing names a Kontaktstelle, a role the BBK data elements carry forward. Portal administration and the Kontaktstelle are security-relevant positions.
The personnel anchor sits in the measure catalogues. § 30 Abs. 2 Nr. 9 BSIG makes concepts for personnel security and access control mandatory minimum measures, and the BSI’s RUN guidance grades them as personenbezogene Maßnahmen, which places them inside the § 39 evidence. The Dachgesetz requires appropriate security management for staff in § 13 Abs. 3 Nr. 5, expressly including external service-provider personnel, and training in Nr. 6. The EU layer points the same way: CER Article 13(5) lists security management for staff as a resilience measure, and the Commission’s 2026 guidelines call for reliability checks covering identity verification, criminal records and employment history.
Operationally this is the Zuverlässigkeitsprüfung: a documented reliability check before a person receives access to critical systems or sites, covering identity and registry data, sanctions and adverse-media signals, and employment history, closed by a human final review. Results feed the access-rights review, with revocation on role change or exit, and slot into the security-concept file the auditor examines. Structured, documented, reviewable verification of key personnel is the capability class Indicium provides here. How to build that file step by step is the subject of the implementation guide for KRITIS background checks; the boundary to state clearance is drawn in the comparison of state clearance and employer screening.
Frequently asked questions
Where do I file the KRITIS Meldung?
Operators of critical plants register via the Melde- und Informationsportal (MIP); the besonders wichtige Einrichtung registration runs through the BSI-Portal. The BBK registration follows once the Identifizierungsverordnung is in force.
How often must evidence be provided to the BSI?
Every three years under § 39 BSIG, the first proof earliest three years after becoming an operator. Until December 2025 the cycle was two years; the BSI has set the new dates individually.
Can ISO 27001 replace the KRITIS examination?
No. Certificates count as components and require a KRITIS-specific add-on examination (GAiN N.BG.01–06). The certificate audit must also be current, at most twelve months old.
Who may perform the Nachweisprüfung?
An independent Prüfende Stelle, unternehmensfremd and legally and economically independent. Internal audit is accepted only where quality assurance to IIA standard is no older than five years.
This article gives general information and does not constitute legal advice.