CitadeltaCITADELTA

Germany's KRITIS Act says “Objektschutz” — physical site protection — in the statute itself

Germany's KRITIS Umbrella Act has been in force since 17 March 2026. It is applicable law — not a draft and not a proposal.

Its official title already says what it is about: the "Umbrella Act on Strengthening the Physical Resilience of Critical Installations" (KRITIS-Dachgesetz, KRITISDachG). It was executed on 11 March 2026 (Federal Law Gazette 2026 I no. 66) and entered into force on 17 March 2026 under Article 11(1) of the enacting statute; section 14(3) to (5) follow only on 1 January 2030. It has since been amended by Article 8 of the Act of 21 July 2026 (Federal Law Gazette 2026 I no. 221).

In consulting practice it is mostly handled by information security and law firms. That is understandable, because that is where the client relationships are — but it does not match what the statute says.

The half-sentence that matters

Section 13(3) no. 2 (a) KRITISDachG requires, in the statutory text:

"measures of structural and technical protection and organisational protection (Objektschutz) such as property demarcation and impeding façade elements"

A federal statute uses the term for physical site protection in its own text. The remaining categories in section 13(3) read accordingly: emergency preparedness, surveillance of the surrounding area, use of detection equipment, access controls, crisis management procedures and alarm-case processes, business continuity including emergency power supply and alternative supply chains, appropriate security management with regard to staff, and familiarising personnel through information material, training and exercises.

That is perimeter, access, detection, alarm organisation, personnel security and instruction. An information security management system covers none of it.

The scope is deliberately physical

Section 4(1) lists ten sectors: energy, transport, finance, social security and basic income support, health, water, food, information technology and telecommunications, space, and municipal waste disposal.

The decisive provision is section 4(2). Under it, sections 12 to 16, 18 and 20 do not apply to financial entities under the DORA Regulation, and not to operators in the information technology and telecommunications sector. For municipal waste disposal and social security, only section 12 remains.

What is left for the resilience plan under section 13 is, in practice: energy, transport, health, water, food and space. The legislature removed the IT-heavy sectors from precisely the part that demands physical measures.

What else the act requires

Registration. Section 8(1): at the latest three months after an installation qualifies as critical, with the Federal Office of Civil Protection (BBK), via a facility set up jointly by BSI and BBK.

Deadlines after registration. Section 8(7): duties under section 12 (the operator's own risk analysis and assessment) apply first nine months after registration; duties under sections 13, 18 and 20 first ten months after. The ten-month deadline therefore covers the resilience plan, incident reporting and the management obligation at the same time.

Traceability. Section 13(4) requires not only that the resilience plan sets out the measures, but that the underlying reasoning is apparent and that reference is made to the risk analysis. It must be updated as needed and after every risk analysis.

Management. Section 20 creates a separate implementation and supervision duty for company management.

Threshold. Section 5(2) sentence 2 gives a standard value of, in principle, 500,000 inhabitants supplied by an installation. Under section 5(3) the Federal Ministry of the Interior may designate installations below that value as significant; under section 5(7) the federal states may designate their own.

The act applies — the ordinance under it is still missing

To avoid the confusion that regularly arises here: the act is in force. What is still outstanding is the statutory instrument that fills it in — the "KRITIS Ordinance" (KritisV) under section 4(3) and section 5(1) KRITISDachG.

The Federal Ministry of the Interior published a draft of it on 26 May 2026; the consultation period ran until 16 June 2026. Under the draft, installations that already met the relevant thresholds in 2025 are to count as critical when the ordinance enters into force — and that date then also starts the clock for them. The draft is not yet applicable law, and changes in the further procedure are not excluded.

A simple chain follows. Without the ordinance there are no binding sector-specific thresholds. Without thresholds no installation qualifies as critical. Without that classification the three-month deadline in section 8(1) does not run — and without registration, neither do the nine- and ten-month deadlines in section 8(7).

Section 8(8) confirms the dependency expressly: the BBK will set out the details of the registration procedure only within four weeks of that ordinance entering into force. And section 13(5): the BBK will provide templates for resilience plans at the latest eight months after it enters into force.

Anyone advertising concrete due dates today will be corrected by any operator with a legal department. Talk about the duties, not about the dates: the duties are in the act and they apply; the dates depend on the ordinance.

On the fines, correctly attributed

Secondary sources circulate the claim that refusing access carries a penalty of up to one million euros. On the wording of section 24(2) that is not correct:

  • up to €1,000,000: contravening an order under section 8(2) sentence 1 (request for documents to determine criticality)
  • up to €500,000: failing to transmit an audit result under section 16(3) sentence 3, or transmitting it incorrectly
  • up to €200,000: contravening orders under section 16
  • up to €100,000: all remaining cases, including defective registration under section 8(1) and refusal of access under section 16(4) sentence 3

What operators can sensibly do now

Neither wait for the ordinance nor rush into activity. What makes sense is the groundwork that will be needed anyway and that presupposes no ordinance: demarcate properties and perimeters, document the physical protection already in place, put access rules and alarm procedures in writing, plan exercises. With that in hand, the resilience plan is later written from a basis rather than from nothing.


As at 8 August 2026. Entry into force, citation and amendment status of the act were checked against the official version on gesetze-im-internet.de. The status of the ordinance procedure rests on publicly available reporting on the draft and may change at short notice — please check the current position before making a decision. This article is a professional assessment, not legal advice.

Sources: KRITIS-Dachgesetz, full text · CMS: Legal update on the KRITIS Ordinance