KRITIS Framework Act: Why operators of critical infrastructure must now reassess their physical resilience

July 28, 2026

The requirements placed on operators of critical infrastructure are undergoing fundamental change. Alongside cyber security, the physical protection of plants, facilities and supply structures is increasingly becoming a focus for legislators. The KRITIS Framework Act, which came into force in March 2026, aims to sustainably strengthen the resilience of critical infrastructure against natural hazards, sabotage, terrorism and other physical threats. The following article is based on a specialist presentation by Daniel Rekowski, risk manager and managing director of Perito GmbH, which he delivered at KRIFA Münster – the specialist conference and exhibition on security and crisis preparedness – on 15 and 16 July 2026. In it, Rekowski explained the current status of legislative implementation, the practical implications of the KRITIS Framework Act, and the challenges that operators of critical infrastructure face in implementing the new requirements.

The security landscape in Europe has changed fundamentally in recent years. Acts of sabotage, hybrid threats, cyber-attacks and targeted disruptions to critical supply systems demonstrate that the risks facing operators of critical infrastructure are no longer confined exclusively to the digital realm. With the entry into force of the KRITIS umbrella law, the physical protection of critical facilities is therefore, for the first time, also being provided with a binding legal framework.

For many companies, this represents a paradigm shift. Whilst information security has been enshrined in regulations for years, the focus is now shifting to the resilience of the entire organisation – from perimeter security and organisational processes to structural protective measures and regular risk analyses.

“For a long time, physical security was somewhat neglected compared to cyber security. Now both areas are being considered together – and that is precisely where the real strength of the KRITIS umbrella law lies,” explains Daniel Rekowski.

Two laws – two different objectives

A key reason for the current uncertainty felt by many operators lies in the frequent conflation of two different sets of regulations: the European NIS2 Directive and the CER (Critical Entities Resilience) Directive, which has been implemented in Germany through the KRITIS umbrella law.

Although both pursue the common goal of strengthening the resilience of critical infrastructure, they have different priorities. Whilst NIS2 primarily defines requirements for information and cyber security and is overseen by the Federal Office for Information Security (BSI), the KRITIS umbrella law focuses on the physical protection of critical facilities. The Federal Office for Civil Protection and Disaster Assistance (BBK) is responsible for this.

In public debate, the two sets of regulations are often confused with one another. In fact, however, they complement each other. It is only the interplay of digital and physical security that creates a holistic level of security.

“Many operators have been working intensively on cybersecurity for years. The task now is to apply the same level of professionalism to the physical protection of their facilities,” explains Rekowski.

A long road to the law

The path to the KRITIS umbrella law was a long one, marked by intense political debate. Work on an initial draft bill began as early as 2022. This was followed by numerous submissions from associations, industry organisations, chambers of commerce and local authority umbrella organisations. The main criticism was that the law was formulated too abstractly in many respects and lacked concrete guidelines for action.

Following the change of government, the process was further delayed. It was not until March 2026 that the KRITIS umbrella law finally came into force. For operators, however, this does not automatically mean clarity. Numerous practical questions are only to be answered by a new KRITIS regulation, which is currently being drafted. Among other things, it will specify which companies are actually affected and what requirements apply to registration, risk analyses and resilience measures.

Registration will only begin once the new KRITIS Regulation is in place

Although the KRITIS Framework Act is already in force, many operators are still waiting for the actual implementation to begin. The reason for this is the KRITIS Regulation, which is currently being revised and is intended to set out numerous detailed provisions.

“The previous KRITIS Regulation has expired. It is now being rewritten. Only once this new regulation has been published will the actual implementation period begin,” explains Rekowski.

Once the new regulation is published, a binding timetable will come into effect for affected operators. They must register their facilities within three months. They will then have nine months to carry out the first risk analysis. The first verifiable resilience measures must be implemented no later than ten months after the completion of this analysis. These may be structural, technical or organisational measures suitable for sustainably increasing the facility’s resilience.

The obligation does not end there. Risk analyses must be updated at least every four years. Furthermore, operators are obliged to document reportable security incidents via the central reporting portal and to incorporate the insights gained from these into the next risk analysis.

Critical infrastructure now covers significantly more sectors

The concept of critical infrastructure now extends far beyond the electricity supply or waterworks.

In addition to energy, transport, telecommunications and healthcare, relevant sectors now also include, amongst others, large logistics centres, parts of the food industry, social security institutions, municipal waste disposal and the space sector.

This development takes account of the fact that modern societies depend on numerous interconnected supply systems. Even prolonged outages in individual sectors can have significant economic and social consequences.

The decisive factor here is not merely the size of a company, but its systemic importance for the provision of essential services to the population. The KRITIS framework law is fundamentally based on whether services for around 500,000 people depend directly or indirectly on a particular facility.

Risk analysis becomes a key management task

Systematic risk analysis lies at the heart of the new law. In future, organisations must identify and assess all relevant threats and derive appropriate protective measures. This explicitly covers not only cyber-attacks, but also physical risks such as sabotage, burglary, vandalism or targeted disruption of critical operational processes.

“Many operators already have very good IT security strategies. When it comes to physical security, however, they are often still in the early stages,” observes Rekowski based on his consultancy experience.

The aim is not to consider individual security measures in isolation. Rather, the entire facility must be understood as an integrated security system – from the property boundary through access controls to organisational emergency procedures. Similarly, industry associations are called upon to provide their member companies with specific recommendations and minimum standards for physical security.

Even minor security incidents are becoming relevant

The KRITIS umbrella law is also changing the way physical security incidents are handled.

In future, even the unauthorised entry of a person onto premises may be subject to a reporting obligation. Such events must be documented via the central reporting portal and will be factored into the further assessment of the security situation.

Furthermore, the Federal Office for Civil Protection and Disaster Assistance (BBK) may require operators to carry out a fresh risk analysis even outside the regular four-year cycle.

“If incidents become frequent or security vulnerabilities occur repeatedly, the BBK may demand an ad hoc risk analysis. In such cases, it is not sufficient to wait for the next regular review cycle,” explains Rekowski.

Breaches can prove costly

Compliance with legal requirements is not a voluntary matter. The KRITIS Framework Act provides for fines of up to 500,000 euros – for instance, for missed deadlines, false information or failure to report security-related incidents.

From his consultancy experience, Rekowski is already familiar with such problem cases.

“I currently advise several data centres. Two of them have presented themselves to the authorities as smaller than they actually are in order to avoid reporting obligations,” he reports. In the long term, however, such a strategy carries considerable risks, as the authorities are continually refining their audit mechanisms.

There’s a world of difference between new-build and existing properties

The varying starting points for operators are particularly evident in the case of data centres.

Whilst newly built data centres can be planned from the outset on the basis of modern security concepts, many operators work in rented existing properties.

“A newly built data centre on a greenfield site can be planned from the outset in line with the results of a risk analysis. The situation is quite different when operators have merely leased space in existing buildings. There, public areas often border directly on security-critical facilities,” explains Rekowski.

In such cases, traditional security measures such as security fences or vehicle barriers often cannot be retrofitted. Instead, security zones must be created within the building – for example, through multi-stage access control systems, additional access controls or specially protected technical areas. Rekowski points to data centres in inner-city rented premises where cooling systems are directly adjacent to areas accessible to the public. In such cases, the key is to systematically relocate the actual high-security areas deeper into the building and to shield them from one another using multiple layers of protection.

Existing facilities present operators with particular challenges

Whilst new data centres or industrial facilities can be designed to meet modern security requirements right from the planning stage, the situation is considerably more difficult for existing facilities. Many critical infrastructure facilities were built decades ago under completely different conditions – at a time when aspects such as protection against sabotage or multi-tiered security zones were hardly a consideration.

Power stations are a case in point. Rekowski reports on a risk analysis of a former coal-fired power station, whose infrastructure was originally designed solely to ensure the most efficient possible operation.

“In the past, the focus was on logistics. The coal trains and lorries were meant to reach the generating units as quickly as possible. The result today is, in some cases, a potential target area stretching several hundred metres, with straight access routes and only a simple barrier system,” he explains.

The challenge, therefore, is not to completely rebuild existing facilities, but to gradually adapt existing structures to today’s threat landscape. This includes, for example, measures to reduce vehicle speeds, additional access controls, spatially staggered security zones, or the targeted expansion of perimeter protection and access controls.

Risk analyses create transparency rather than uncertainty

In his day-to-day consultancy work, Rekowski frequently encounters a certain degree of scepticism towards the risk analyses required by law. Many operators fear that these analyses will reveal significant investment shortfalls or necessitate extensive immediate measures.

However, he considers this concern to be unfounded.

“Of course, some operators are initially wary of a risk analysis. After all, it highlights areas where investment has been neglected for many years. But that is not the point. Nobody expects shortfalls that have built up over decades to be rectified within a year. “

Rather, the risk analysis should be seen as a strategic tool. It transparently highlights where the greatest risks lie and which measures should be prioritised. This creates a robust basis for investment decisions and provides a clear plan for regulatory authorities.

Particularly in the case of older facilities, implementation can often only be carried out in stages. What is crucial, therefore, is not so much immediate perfection as a clear strategy for the continuous improvement of resilience.

Industry associations play a key role

Alongside the operators themselves, Rekowski sees industry associations in particular as bearing responsibility. They could offer their member companies practical guidance and help to translate the legal requirements – some of which are still rather abstract – into concrete technical recommendations.

“It is now up to the associations to provide their member companies with recommendations – for example, on the physical protection of premises or on minimum standards for risk analyses.”

Uniform recommendations could not only facilitate implementation but also help to establish comparable security standards within individual sectors.

Physical and digital security are converging

The KRITIS umbrella law makes it clear that resilience must be approached holistically in future. Physical security and cyber security can no longer be separated from one another.

Effective protection of critical infrastructure can only be achieved through the interplay of various measures – ranging from organisational processes and structural security measures to modern information and communication technologies.

At the same time, the regular review of the effectiveness of these measures is becoming increasingly important. Risk analyses will no longer be one-off projects, but rather an integral part of a continuous improvement process. New threats, technical developments or security-related incidents must be continuously assessed and integrated into existing security concepts.

Laying the foundations for greater resilience now

With the KRITIS umbrella law, a new phase of security management is beginning for operators of critical infrastructure. For the first time, physical resilience, organisational preparedness and cyber security are being brought together within a comprehensive regulatory framework.

Even though numerous detailed regulations will only be finalised with the new KRITIS Regulation, companies should use the time remaining to critically review their security structures. Those who start conducting risk analyses at an early stage, identify existing vulnerabilities and prioritise appropriate measures will not only better meet the legal requirements but also sustainably strengthen their resilience to future threats.

For Rekowski, one thing is paramount: “The important thing is simply to get started. That is precisely what has not yet happened in many areas.”

This pragmatic approach sums up the objective of the KRITIS umbrella law. It is not a question of creating a perfect security architecture within the shortest possible time. Rather, the key is to set a systematic process in motion, assess risks transparently, continuously develop protective measures and permanently embed resilience as an integral part of corporate strategy. [DCM]

Related Articles

Share This