Analysis · Sep 11, 2026

The law is waiting for its regulation. The attackers are not.

Central Berlin at dusk, the television tower above lit streets and buildings.

On Tuesday, 1 September 2026, emergency services found improvised projectiles aimed at extra-high-voltage lines at the Turnow-Preilack substation near Jänschwalde in Brandenburg. The same evening, a short circuit at the substation in Bergheim in the Rhineland took five units of two lignite power plants off the grid. In a cornfield next to it lay six launching devices capable of firing pyrotechnics across power lines. Herbert Reul, interior minister of North Rhine-Westphalia, said the next day that much pointed to this being no coincidence. A week later, police arrested a suspect; the Federal Prosecutor General is investigating anti-constitutional sabotage and disruption of public utilities.

Four incidents, this year alone

The double incident in September is the most recent in a series of attacks on critical infrastructure in Germany that have hit or threatened supply this year.

In January 2026, an arson attack on a cable bridge cut the high-voltage lines in the southwest of Berlin. Around 45,000 households, roughly 100,000 people, and 2,200 shops and businesses were without power for days, hospitals and care homes among them.

On 8 June 2026 the Reutlingen-West substation burned; up to 40,000 households were temporarily without power. Investigators assume deliberate arson.

During the night of 5 August 2026, a drone carrying explosives and a detonator was found at Leipzig/Halle Airport. A cargo aircraft is presumed to have collided with a second drone. Saxony’s interior minister, Armin Schuster, later described a threat that had to be named clearly as state terrorism.

On 1 September, Jänschwalde and Bergheim followed.

All of these attacks were aimed at the physical site, not at IT. In Brandenburg and North Rhine-Westphalia the authorities initially investigated state-sponsored sabotage as well, until suspicion settled on a single individual who claimed the attack in a letter protesting fossil energy. The European Commission named this threat picture explicitly in its July 2026 guidelines on the CER Directive: operators should account for state actors intent on sabotage and espionage alongside terrorism and insiders (paragraph 25).

Where the law stands

The KRITIS Framework Act (KRITIS-Dachgesetz) has been in force since 17 March 2026. It requires operators of critical assets to run risk analyses, implement physical protection and report incidents within 24 hours. We have summarized what is in it in a separate article: the KRITIS Framework Act explained.

At the same time, operators are left in the dark, because the regulation that gives the law its detail is missing. The Federal Office of Civil Protection and Disaster Assistance (BBK) writes in its FAQ that there is currently no duty to register under the Framework Act, because the regulation identifying critical assets is still being drafted and coordinated. A lower bound for registration — no earlier than 17 July 2026 — was originally in the law and was removed at the end of July 2026.

Just below the threshold is not outside

An asset counts as critical if it supplies at least 500,000 inhabitants as a rule. Anyone below that should not feel safe. When the federal states approved the law in the Bundesrat on 6 March 2026, they called for the threshold to be lowered to 150,000, arguing that otherwise numerous essential infrastructures, particularly in rural areas, would remain outside the law. The law also allows the states to classify assets below the standard threshold as critical where a state authority is responsible for the service (§ 5 (7)). And two years after it came into force the law is evaluated, the threshold explicitly included.

The substation in Bergheim supplies no households directly; it connects power plants to the extra-high-voltage grid. Whether it will count as a critical asset is still open. It was hit anyway.

The responsibility already sits with the operator

How the legislator will shape the duties in detail is open. To an attacker it makes no difference. Berlin in January, Reutlingen in June, Leipzig/Halle in August, Jänschwalde and Bergheim in September: none of these attacks waited for a regulation, and no operator hit by them could point to a deadline that had not started yet.

Responsibility for protecting a site already sits with its operator, towards the people it supplies. And it sits with its own management, which answers personally for implementation under § 20. A cut-off date changes none of that; it only makes the duty auditable. Concepts for perimeter protection, alerting and documentation can be developed and put in place today.

What is coming is already visible. The European Commission’s July 2026 guidelines describe in 94 paragraphs what the CER Directive means by physical protection: monitored and regularly tested perimeter detection (paragraph 29), video in real time and recorded (paragraph 30), alerting with clear chains of command (paragraph 65), an incident database (paragraph 20), drone detection and countermeasures (paragraphs 46 to 50). The guidelines are not binding, but the German regulation and the minimum requirements under § 14 transpose the same directive. Working to them today is the closest preview of the German requirements anyone has.

What we can take on today

None of what follows waits for the regulation. With it, these points are likely to become the part of your resilience plan you have to evidence.

Perimeter detection is only as good as the response that follows it. The guidelines ask for systems that are monitored and tested regularly. Connect your sites to us (Aufschaltung) and your signals arrive in one place, assessed around the clock, including at three in the morning.

Who is alerted for which event, who decides on an intervention, and which authority is informed when: we set that out with you in an alarm plan. That is what the guidelines describe as alerting systems with clear chains of command and formalized cooperation with police and emergency services — and it is a document you can put on the table in an audit.

We document every alarm with a timestamp, its cause, the measure taken and the outcome. That is the basis for a report under § 18: you pull the incident out of running documentation instead of reconstructing it afterwards.

We do not sell compliance; the duty stays with the operator. Ask us what connecting a site looks like in practice, and which part of the daily work we take on.

Safety is made, not given.