Analysis · Aug 19, 2026

The KRITIS Framework Act explained. What operators need to know.

A high-voltage substation with transmission pylons standing in morning fog above a field.

Water, power, food, public transport: supply is invisible in daily life as long as it works. The sites that carry it are called critical infrastructure — KRITIS in German.

On 17 March 2026 the KRITIS Framework Act (KRITIS-Dachgesetz) came into force. For the first time, a single German law requires operators of critical assets across every sector to protect their sites physically. It transposes the European CER Directive ((EU) 2022/2557), whose deadline expired in October 2024. The law applies. The regulation that puts it into practice does not exist yet.

NIS2 covers cyber, the Framework Act covers the physical

The two are often named in one breath, but they mean different things. The German NIS2 implementation act has applied since 6 December 2025 and governs IT security: networks, systems, attack detection. The KRITIS Framework Act governs physical resilience: buildings, fences, access, surveillance, emergency plans, recovery. Many operators fall under both and have to organize both. This article is about the Framework Act.

Who is covered

The law reaches well beyond power and water. § 4 (1) names ten sectors: energy, transport, finance, social insurance and basic income support, health, water, food, IT and telecommunications, space, and municipal waste management. Finance (covered by DORA), IT and telecommunications, and largely waste management and social insurance are exempted; there, essentially only the duty to run a risk analysis applies. Federal administration bodies are covered separately in § 7. The underlying EU directive counts eleven sectors, public administration among them; the German government told the Bundesrat it would develop a definition in the National KRITIS Resilience Strategy that also covers government and administration, media and culture, and social services.

An asset counts as critical if it supplies at least 500,000 inhabitants as a rule (§ 5 (2)). Which types of asset are meant, and where the threshold sits per sector, will be set by a regulation. A draft from May 2026 exists; the regulation is not in force.

Two things matter for operators below the threshold today. The federal states will be allowed to classify assets below the standard threshold as critical where a state authority is responsible for the service; the Federal Ministry of the Interior sets the criteria and procedure by regulation (§ 5 (7)). And when the Bundesrat approved the law on 6 March 2026, it criticized that the threshold had not been lowered to 150,000 inhabitants, arguing that otherwise numerous essential infrastructures, particularly in rural areas, would remain outside the law. The threshold debate is open.

What the law requires

The duties start with registration at the Federal Office of Civil Protection and Disaster Assistance (BBK). Deadlines then run from there: nine months for a risk analysis and assessment (§ 12), ten months to implement resilience measures and document a resilience plan (§ 13), ten months until incidents must be reported (§ 18). The risk analysis has to be repeated at least every four years.

§ 13 (1) names four goals: prevent incidents, give the assets adequate physical protection, respond to and repel incidents, and restore the critical service quickly. For physical protection, § 13 (3) lists structural and technical security measures and organizational site protection such as perimeter demarcation and resistant façade elements, instruments and procedures for monitoring the surroundings, the use of detection devices, and access controls. That is as specific as the law gets on technology, and it frames the list as examples rather than as a catalog of obligations. What a detection device has to achieve, who does the monitoring, and what happens once something is detected is not in there.

The reporting duty, by contrast, is precise. Under § 18, an operator must report an incident that significantly disrupts the critical service to the BBK within 24 hours of becoming aware of it. Within one month, a detailed report follows: type, cause and consequences of the incident, the number and share of people affected, the duration of the disruption, and the area affected. Delivering that within 24 hours takes alarm data that was already recorded in a structured way before the incident.

What “adequate physical protection” actually means

Since July 2026 the European Commission has been filling the gap. Its guidelines on the application of Article 13(5) of the CER Directive (C/2026/3712 of 13 July 2026) run to 94 numbered paragraphs in seven areas. They are explicitly non-binding, but for now they are the only official statement at EU level of what “adequate” can mean in practice, until the German minimum requirements under § 14 arrive. Area C, physical protection measures, is the one that matters for site security.

The guidelines recommend alarm and intrusion detection systems with indoor and outdoor sensors that are monitored and tested regularly (paragraph 29). Video systems should cover the relevant areas in real time and in recordings, with regular review of the footage (paragraph 30). Keys and electronic access media should sit in a single, binding register with issue and return records (paragraph 38). For incident response, the guidelines name alerting systems across several channels, clear chains of command and exercised procedures (paragraph 65), plus formalized cooperation with police, emergency services and authorities (paragraph 61). And they call for an incident database with systematic recording (paragraph 20).

Drones do not appear in the Framework Act at all. The guidelines give them five paragraphs: detection and tracking of unmanned systems via radar, cameras and sensors, visual screening of sensitive areas, physical countermeasures such as nets and canopies, geographical zones and eventually geofencing, and partnerships with police and defense (paragraphs 46 to 50). After the drone incident at Leipzig/Halle Airport in August 2026, that topic is unlikely to stay non-binding in Germany for long.

What this means for a single site is easiest to see at a substation. The law asks for monitoring of the surroundings and detection devices. The guidelines get specific: outdoor sensors on the fence, video with recording, someone who sees the alarms and verifies them, an alarm plan with a chain of command, and a database in which every alarm carries its time, cause and response. For a waterworks or a hospital with many entrances, access management with a key register comes on top.

What happens if duties are missed

The law uses three levers. First, fines under § 24: up to 100,000 euros for missing or faulty registration and for refusing to cooperate with an audit, up to 200,000 euros where evidence or a remediation plan is not submitted, up to 500,000 euros for audit results that are not transmitted, and up to one million euros where an operator withholds the documents the BBK needs to judge whether an asset is critical at all. Compared with NIS2 those are low figures, and it was already argued during the legislative process that the penalty would in many cases be cheaper than the protective measure; the interior committee then doubled the fines.

Second, the management. Under § 20, managing directors and board members have to implement the resilience measures and ensure implementation through suitable organization. Where they breach that duty culpably, they are liable to their own company. That moves the topic out of the specialist department and into the boardroom.

Third, supervision. The competent authority can review implementation, enter business premises and inspect documents, and order a remediation plan with deadlines (§ 16). The BBK can register operators itself if they fail to do so (§ 8 (3)). One exception applies to electricity, natural gas and hydrogen supply: there, evidence runs through the Energy Industry Act and the Federal Network Agency rather than through the Framework Act.

Where implementation stands today

The law applies, but the duties have not started. The BBK writes in its FAQ that there is currently no duty to register under the Framework Act, because the regulation identifying critical assets is still being drafted and coordinated. A lower bound for registration — no earlier than 17 July 2026 — was originally in the law and was removed at the end of July 2026.

Once the regulation is in force, the BBK publishes the registration procedure within four weeks. Operators then have three months from the determination of their criticality to register, and the nine- and ten-month deadlines start from there. The law is also evaluated two years after it came into force (§ 25), the threshold explicitly included.

Who does the protecting

The debate around the Framework Act is about thresholds, responsibilities and deadlines. Who protects the sites rarely comes up. Sensors on the fence and cameras at the gate are hardware. What the Commission’s guidelines require is that those systems are monitored and tested, that someone verifies alarms, triggers interventions and talks to the authorities — around the clock.

We answer the signals ourselves. Critical sites are connected to us (Aufschaltung): intrusion, perimeter, video and fault signals arrive in one place, are checked around the clock, and in an alarm a chain of intervention agreed in advance takes over. Paragraphs 29, 30 and 65 of the guidelines describe exactly that part of the work, and every step of it is documented.

Trident, our operating system for alarm receiving centers, is recognized under VdS 3534. Because we build it ourselves, we adapt alarm procedures to an operator’s processes instead of adapting the operator to the software. Every alarm is documented with timestamp, cause and response. That data is the basis for the 24-hour report under § 18 and for the incident database in paragraph 20. For new sensors — drone detection, robotics — the question to ask any center today is how it connects them without setting up its procedures again from scratch.

We do not sell compliance; the duty stays with the operator. What we take on is the part that has to happen every night. Talk to us about what connecting a site looks like in practice.

Safety is made, not given.