KRITIS stands for critical infrastructure: operators and plants in ten sectors, from energy and water through health and finance to space, whose failure would cause considerable supply shortfalls or dangers to public safety. Whether an individual plant belongs is decided by supply thresholds in the BSI-Kritisverordnung, not by company size. Two laws govern those operators: the BSIG for IT security, and the KRITIS-Dachgesetz for physical resilience.
What counts as a critical service and a critical Anlage
The current legal definition avoids the older umbrella term. Section 2 Nr. 24 of the new BSIG defines a critical service (kritische Dienstleistung) as a service supplying the general public in the named sectors whose failure would cause considerable supply shortfalls or dangers to public safety. A critical Anlage, under Section 2 Nr. 3 of the KRITIS-Dachgesetz, is a plant that is substantial for providing such a service. The new BSIG no longer treats Kritische Infrastrukturen as a legal category of their own; it addresses Betreiber kritischer Anlagen and counts them among the besonders wichtige Einrichtungen under Section 28 Abs. 2.
The historical anchor matters for readers of older guidance. The 2009 BSIG, in Section 2 Abs. 10, still defined KRITIS across eight sectors. Lists that add media and culture or state and administration circulate online, but they trace to other legal layers, not to the current catalogue. The practical consequence: criticality is assessed per plant and per service, so the analysis starts with what the Anlage supplies and to whom, not with legal form or headcount.
Which sectors belong to KRITIS?
The BSI-KritisV determines critical plants across nine sectors: energy, water, food, IT and telecommunications, health, finance and insurance, transport and traffic, municipal waste disposal, and social insurance plus basic income support for job seekers. The KRITIS-Dachgesetz adds space as the tenth sector in Section 4 Abs. 1. For the space economy this is new territory: a federal physical-resilience regime the sector did not previously face.
Public administration is not a sector in the current catalogue, though glossaries often list it; those older lists trace to other legal layers.
When does a plant become critical?
The BSI-KritisV answers this per plant category, using a supply threshold (Versorgungsgrad). The base value, the Regelschwellenwert, is 500,000 supplied persons, from which the BSI derives category-specific figures such as 104 megawatts for power generation or 0.869 tonnes of food per person and year. The base value is justified through emergency-capacity compensation limits: how much shortfall the overall system can still absorb in an emergency.
Three consequences follow. Thresholds apply strictly per plant, so companies, sites or corporate groups are not themselves KRITIS; only the gemeinsame Anlage construct can bundle plants. Operators must check annually, by 31 March, whether a plant crossed its threshold in the previous year. And because criticality applies from 1 April of the year after the threshold is first reached, growth past a threshold creates duties with a lag, which is where unplanned registration emergencies usually begin.
Two legal regimes: BSIG for IT security, the Dachgesetz for resilience
The first regime is the BSIG in the version in force since 6 December 2025, Germany’s NIS-2 transposition. It regulates the IT security of operators of critical Anlagen through registration, risk-management measures (Section 30), attack-detection systems (Section 31), incident reporting (Section 32) and periodic evidence (Section 39).
The second regime is the KRITIS-Dachgesetz, in force since 17 March 2026 (promulgated 11 March 2026 as BGBl. 2026 I Nr. 66, amended 21 July 2026). It transposes the EU CER Directive 2022/2557 and addresses the physical and organisational resilience of the plant itself. One status note: per the BBK’s FAQ, the Identifizierungsverordnung that triggers the operator duties was still in preparation at the time of research, so DachG registration, risk-analysis, resilience and reporting duties are not yet running. Once it is in force, registration is due within three months of a plant becoming critical, the risk analysis nine months after registration, resilience and reporting duties ten months after. The deadline cascade is laid out in the article on the KRITIS-Dachgesetz 2026.
Both regimes address the same plants but demand different evidence: cyber measures for the BSI, physical and organisational resilience for the Länder authorities and the BBK.
Who is an operator, and which duties follow?
Operator is whoever runs the plant providing the critical service. Because thresholds attach to plants, a company can run several plants of which only some are critical; one newly critical plant pulls the entity into the duty net. The BSIG cascade runs in five steps. First, register via the BSI’s Melde- und Informationsportal (MIP), including the second registration as a besonders wichtige Einrichtung; the workflow is covered in the companion piece on KRITIS registration and the BSI process. Second, implement risk-management measures under Section 30, including personnel security and access control. Third, run attack-detection systems under Section 31, mandatory since 1 May 2023. Fourth, report significant incidents under Section 32: initial notification within 24 hours, detailed notification within 72 hours, final report within one month, filed via MIP as the priority channel at least until 31 July 2026. Fifth, provide evidence under Section 39; the cycle changed from two years to three in December 2025, with the first proof due earliest three years after becoming an operator. Section 38 adds leadership approval, oversight and training duties.
Once applicable, the Dachgesetz layers its own cascade on top: BBK registration, risk analysis, resilience measures, and a 24-hour incident report to the joint BSI/BBK Meldestelle with a full report within one month (Section 18).
Personnel security: the duty that runs through both regimes
Both regimes treat people as a risk vector in their own right. Under the BSIG, Section 30 Abs. 2 Nr. 9 makes concepts for the security of personnel and for access control mandatory minimum measures, which places personnel security inside the Section 39 evidence; the BSI’s RUN guidance grades these points as personenbezogene Maßnahmen. Under the DachG, Section 13 Abs. 3 Nr. 5 requires appropriate security management for staff, explicitly including personnel of external service providers, and Nr. 6 adds training.
The EU layer explains why. CER Directive Article 13(5) lists security management for staff as a resilience measure, and the Commission’s 2026 guidelines call for a reliability-check system covering identity verification, criminal-record checks and employment history, plus need-to-know access rights and a register of keys and credentials with issuance and revocation dates.
Operationally this is the Zuverlässigkeitsprüfung: a documented check of employees before they get access to critical systems or sites, covering identity and registry data, sanctions and adverse-media signals, and employment history, closed by a human final review. The results feed the access-rights review, with revocation on role change or exit, and slot into the security-concept file auditors examine. A step-by-step build of that file is the subject of the implementation guide for KRITIS background checks; how employer-run verification differs from a state security clearance is covered in the comparison of state clearance and employer screening. Indicium sits in the middle of that capability class: structured, documented, reviewable verification of key personnel.
Frequently asked questions
Am I subject to KRITIS obligations?
The question resolves per plant, not per company. Check whether the Anlage operates in one of the ten sectors and crosses the category’s supply threshold in the BSI-KritisV. The annual check is due by 31 March; document the result, including a negative one.
What does the threshold of 500,000 supplied persons mean?
It is the Regelschwellenwert, the base value from which the BSI derives category-specific thresholds such as 104 megawatts for power generation. It models how much supply shortfall the system can still compensate, which is why it counts supplied persons rather than employees or revenue.
What is the difference between KRITIS and NIS2?
NIS2 is the EU directive; Germany implements it through the new BSIG, which distinguishes besonders wichtige and wichtige Einrichtungen. Operators of critical Anlagen are a subset of the besonders wichtige Einrichtungen (Section 28 Abs. 2 BSIG) with sector-specific duties, and the Dachgesetz adds physical resilience on top.
Do authorities and public administration count as KRITIS?
Not as a sector. The current catalogues of the BSI-KritisV and the Dachgesetz do not include state and administration; older lists trace to other legal layers. Public entities can be affected indirectly as clients or suppliers of critical plants.
This article gives general information and does not constitute legal advice.