KRITIS Umbrella Act and NIS2 in Germany
The KRITIS Umbrella Act and NIS2 introduce different but closely connected requirements for security and resilience in Germany.
The KRITIS Umbrella Act, officially known as the German KRITIS-Dachgesetz, focuses on the physical and organisational resilience of critical facilities. NIS2 and the amended German BSI Act primarily address cybersecurity and the security of network and information systems.
Some organisations may fall within the scope of one framework, while others may have to comply with both. This overview explains the key differences, shared requirements and practical steps for companies operating in Germany.
KRITIS Umbrella Act and NIS2 at a glance
Both frameworks aim to strengthen the ability of essential organisations and services to withstand disruptions. However, they address different risks and groups of organisations.
| Area | KRITIS Umbrella Act | NIS2 and German BSI Act |
|---|---|---|
| Primary focus | Physical and organisational resilience | Cybersecurity and information security |
| Main subjects | Operators of critical facilities | Important and particularly important entities |
| Risk perspective | All-hazards approach | Risks to network and information systems |
| Core requirements | Risk assessment, resilience measures and resilience plan | Cybersecurity risk management, registration and incident reporting |
| Shared areas | BCM, crisis management, governance and exercises | BCM, crisis management, governance and exercises |
The obligations must be assessed separately. In practice, however, many organisational structures and processes can be developed together.
Quick Check: KRITIS Umbrella Act
What is the KRITIS Umbrella Act?
Germany’s Umbrella Act for Critical Infrastructure Protection, commonly referred to as the KRITIS Umbrella Act, establishes uniform cross-sector requirements for the physical resilience of critical facilities.
The Act came into force on 17 March 2026 and implements the European Critical Entities Resilience Directive, or CER Directive, in German law.
Its all-hazards approach considers risks such as:
- natural hazards and extreme weather;
- technical failures and supply interruptions;
- human error and organisational weaknesses;
- sabotage and unauthorised physical access;
- dependencies on suppliers and essential services.
Operators within the scope of the Act may be required to register critical facilities, conduct operator risk assessments, implement appropriate resilience measures and document them in a resilience plan. The Act also covers incident reporting and management responsibilities.
Do you require support with applicability assessment, risk analysis or resilience planning? Learn more about our KRITIS Umbrella Act consulting in Germany.
What is NIS2?
NIS2 is the European framework for strengthening cybersecurity across essential and important sectors.
In Germany, the requirements were implemented through the NIS2 Implementation Act and the amended BSI Act. The German legislation came into force on 6 December 2025.
The BSI Act distinguishes between important entities and particularly important entities. Depending on their classification, affected organisations must address requirements including:
- cybersecurity risk management;
- incident detection and response;
- business continuity and recovery;
- supply-chain security;
- registration with the BSI;
- reporting of significant security incidents;
- management oversight and training;
- documentation and evidence.
The principal requirements are set out in Sections 28 to 39 of the amended BSI Act.
Do you need to determine whether your organisation is affected or assess your current level of readiness? Learn more about our NIS2 consulting in Germany.
KRITIS Umbrella Act and NIS2: Key Differences
The KRITIS Umbrella Act focuses on the physical and organisational resilience of critical facilities. It addresses risks such as sabotage, natural hazards, technical failures and supply disruptions.
NIS2 primarily focuses on cybersecurity and the protection of network and information systems. It requires affected organisations to implement risk management measures, prepare incident reporting processes and establish management oversight.
The two frameworks complement each other. Companies may need both cyber and physical resilience measures, depending on their activities, facilities and legal classification.
Could Both Frameworks Apply?
An organisation may operate a critical facility while also qualifying as an important or particularly important entity under the German BSI Act.
Companies should therefore assess:
- relevant legal entities and locations;
- business activities and critical services;
- company size and applicable thresholds;
- existing ISMS, BCM and crisis management structures;
- registration, reporting and governance obligations.
A documented applicability assessment provides clarity on the relevant requirements and the next implementation steps.
What Companies Should Do Next
A structured approach usually includes six steps:
- Confirm whether the KRITIS Umbrella Act, NIS2 or both apply.
- Record existing security and resilience structures.
- Identify regulatory and operational gaps.
- Prioritise measures, responsibilities and deadlines.
- Establish governance and appropriate documentation.
- Test reporting, emergency and crisis processes.
This approach helps organisations avoid isolated solutions and build a coordinated security and resilience framework.
Integrated Security and Resilience
Several implementation areas can be combined:
Learn more about our Business Continuity Management consulting services.
You are currently viewing a placeholder content from YouTube. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationPractical Guidance and Consulting Support
Our free resources provide an initial orientation:
- KRITIS Umbrella Act Quick Check
- KRITIS Umbrella Act Guide
- Cybersecurity and NIS2 Guide
Strengthen Security and Resilience in Germany
Are you unsure whether the KRITIS Umbrella Act and NIS2 apply to your organisation?
3-core helps German and international companies identify the relevant requirements and develop a practical implementation approach.
Projects Related to the KRITIS Umbrella Act and NIS2
The practical implementation of the KRITIS Umbrella Act and NIS2 requires more than policies and formal documentation. Companies need effective structures, clearly defined responsibilities and measures that work during disruptions and security incidents.
Our selected projects show how organisations combine risk assessments, Business Continuity Management, crisis management and physical security to strengthen regulatory readiness and operational resilience.
Explore how 3-core supports companies in translating the requirements of the KRITIS Umbrella Act and NIS2 into practical and sustainable solutions.