{"id":41818,"date":"2026-03-12T14:07:13","date_gmt":"2026-03-12T14:07:13","guid":{"rendered":"https:\/\/3-core.de\/?p=41818"},"modified":"2026-03-12T14:16:06","modified_gmt":"2026-03-12T14:16:06","slug":"kritis-umbrella-act-2026-requirements-obligations-and-audit-readiness","status":"publish","type":"post","link":"https:\/\/3-core.de\/en\/blog-englisch\/kritis-umbrella-act-2026-requirements-obligations-and-audit-readiness\/","title":{"rendered":"KRITIS Umbrella Act 2026: Requirements, Obligations, and Audit Readiness"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"41818\" class=\"elementor elementor-41818 elementor-41619\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-53f46539 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"56025\" data-id=\"53f46539\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-97fc82d\" data-eae-slider=\"8521\" data-id=\"97fc82d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-17b78b54 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"85080\" data-id=\"17b78b54\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-1c5197ab\" data-eae-slider=\"54106\" data-id=\"1c5197ab\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-517a061 elementor-widget elementor-widget-theme-post-featured-image elementor-widget-image\" data-id=\"517a061\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"theme-post-featured-image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"768\" height=\"524\" src=\"https:\/\/3-core.de\/wp-content\/uploads\/2026\/03\/Kritis-Dachgesetz-768x524.jpg\" class=\"attachment-medium_large size-medium_large wp-image-41782\" alt=\"A red neon SECURITY sign with an arrow points right, reflected on a marble wall. In the background, a smaller neon BAGGAGE DEPT sign is visible.\" srcset=\"https:\/\/3-core.de\/wp-content\/uploads\/2026\/03\/Kritis-Dachgesetz-768x524.jpg 768w, https:\/\/3-core.de\/wp-content\/uploads\/2026\/03\/Kritis-Dachgesetz-300x205.jpg 300w, https:\/\/3-core.de\/wp-content\/uploads\/2026\/03\/Kritis-Dachgesetz-1024x699.jpg 1024w, https:\/\/3-core.de\/wp-content\/uploads\/2026\/03\/Kritis-Dachgesetz-1536x1048.jpg 1536w, https:\/\/3-core.de\/wp-content\/uploads\/2026\/03\/Kritis-Dachgesetz-2048x1397.jpg 2048w\" sizes=\"(max-width: 768px) 100vw, 768px\" title=\"\">\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-138a58e2 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"30683\" data-id=\"138a58e2\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-683c27aa\" data-eae-slider=\"57815\" data-id=\"683c27aa\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-4fa27cfc elementor-widget elementor-widget-theme-post-title elementor-page-title elementor-widget-heading\" data-id=\"4fa27cfc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"theme-post-title.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">KRITIS Umbrella Act 2026: Requirements, Obligations, and Audit Readiness<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-535f087f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"30975\" data-id=\"535f087f\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7bbc09ec\" data-eae-slider=\"44104\" data-id=\"7bbc09ec\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-7fefd1dd elementor-widget elementor-widget-text-editor\" data-id=\"7fefd1dd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em>With the national transposition of the CER Directive, the protection of critical infrastructure in Germany will gain significantly greater importance in 2026. The current draft bill for the <strong>KRITIS Umbrella Act<\/strong> makes this clear: operators of critical infrastructure must prepare for<strong> stricter requirements, new reporting obligations, and robust evidence and documentation requirements.<\/strong><\/em><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-16eae6e9 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"49026\" data-id=\"16eae6e9\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-44c1a8dc\" data-eae-slider=\"96299\" data-id=\"44c1a8dc\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-80d5d60 elementor-widget elementor-widget-heading\" data-id=\"80d5d60\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">KRITIS Umbrella Act 2026: New Requirements for Critical Infrastructure Operators<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4ddb0116 elementor-widget elementor-widget-text-editor\" data-id=\"4ddb0116\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"0\" data-end=\"208\"><strong>For KRITIS companies,<\/strong> the issue is no longer just complying with legal requirements. What matters now is how quickly and systematically the new obligations can be translated into robust operational processes.<\/p><p data-start=\"210\" data-end=\"264\"><strong>Those who act early achieve more than mere compliance:<\/strong><\/p><ul data-start=\"266\" data-end=\"547\"><li data-section-id=\"1hp3kup\" data-start=\"266\" data-end=\"317\"><p data-start=\"268\" data-end=\"317\">greater organizational and technical resilience<\/p><\/li><li data-section-id=\"7jgci3\" data-start=\"318\" data-end=\"375\"><p data-start=\"320\" data-end=\"375\">improved auditability and ability to provide evidence<\/p><\/li><li data-section-id=\"1mlilza\" data-start=\"376\" data-end=\"410\"><p data-start=\"378\" data-end=\"410\">more stable critical processes<\/p><\/li><li data-section-id=\"1xhhaoj\" data-start=\"411\" data-end=\"478\"><p data-start=\"413\" data-end=\"478\">greater trust among customers, partners, and public authorities<\/p><\/li><li data-section-id=\"sos5o1\" data-start=\"479\" data-end=\"547\"><p data-start=\"481\" data-end=\"547\">a measurable competitive advantage through proactive preparation<\/p><\/li><\/ul><p data-start=\"549\" data-end=\"681\" data-is-last-node=\"\" data-is-only-node=\"\"><strong>A holistic KRITIS strategy ensures that risks are identified early, measures are prioritized, and incidents are managed effectively.<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-536a4d5 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"89503\" data-id=\"536a4d5\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-3bed566\" data-eae-slider=\"72129\" data-id=\"3bed566\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-dbf5590 elementor-cta--skin-classic elementor-animated-content elementor-bg-transform elementor-bg-transform-zoom-in elementor-widget elementor-widget-call-to-action\" data-id=\"dbf5590\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"call-to-action.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-cta\">\n\t\t\t\t\t<div class=\"elementor-cta__bg-wrapper\">\n\t\t\t\t<div class=\"elementor-cta__bg elementor-bg\" style=\"background-image: url(https:\/\/3-core.de\/wp-content\/uploads\/2026\/03\/Quick-Check-Kritis_3-core.eu_V2.jpeg);\" role=\"img\" aria-label=\"Top view of three people at a wooden table with tablets and notebooks. Text overlay reads: \u201cQuick Check: KRITIS Umbrella Act 2026. Our assessment of your company is just a few clicks away!\u201d.\"><\/div>\n\t\t\t\t<div class=\"elementor-cta__bg-overlay\"><\/div>\n\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-cta__content\">\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<h2 class=\"elementor-cta__title elementor-cta__content-item elementor-content-item\">\n\t\t\t\t\t\tQUICK CHECK\t\t\t\t\t<\/h2>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-cta__description elementor-cta__content-item elementor-content-item\">\n\t\t\t\t\t\tGet our assessment for your company in just a few clicks\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-cta__button-wrapper elementor-cta__content-item elementor-content-item \">\n\t\t\t\t\t<a class=\"elementor-cta__button elementor-button elementor-size-\" href=\"https:\/\/3-core.de\/quick-check-kritis-dachgesetz\/\">\n\t\t\t\t\t\tSTART NOW\t\t\t\t\t<\/a>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-1baeecf\" data-eae-slider=\"21223\" data-id=\"1baeecf\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f29e8a8 elementor-widget elementor-widget-heading\" data-id=\"f29e8a8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Operational Changes in 2026 Under the KRITIS Umbrella Act<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8421049 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"8421049\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"0\" data-end=\"158\"><strong>The KRITIS Umbrella Act<\/strong> will significantly increase the requirements for protecting critical infrastructure. Four operational areas are particularly relevant:<\/p><ul data-start=\"160\" data-end=\"343\"><li data-section-id=\"4rof8\" data-start=\"160\" data-end=\"198\"><p data-start=\"162\" data-end=\"198\"><strong>risk analysis and security concept<\/strong><\/p><\/li><li data-section-id=\"3vnwgr\" data-start=\"199\" data-end=\"251\"><p data-start=\"201\" data-end=\"251\"><strong>physical protection and protection zone concepts<\/strong><\/p><\/li><li data-section-id=\"1tsut9s\" data-start=\"252\" data-end=\"275\"><p data-start=\"254\" data-end=\"275\"><strong>resilience planning<\/strong><\/p><\/li><li data-section-id=\"1d6o0cp\" data-start=\"276\" data-end=\"343\"><p data-start=\"278\" data-end=\"343\"><strong>reporting and evidence obligations vis-\u00e0-vis public authorities<\/strong><\/p><\/li><\/ul><p data-start=\"345\" data-end=\"568\" data-is-last-node=\"\" data-is-only-node=\"\">In the future, companies will not only have to implement effective protective measures, but also document them in a structured manner and be able to provide robust proof of compliance in the event of an audit or inspection.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-23b24640 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"47396\" data-id=\"23b24640\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5a6cc765\" data-eae-slider=\"70274\" data-id=\"5a6cc765\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-6551bdc elementor-widget elementor-widget-spacer\" data-id=\"6551bdc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-20794c3a elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"25499\" data-id=\"20794c3a\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-787eeff8\" data-eae-slider=\"22938\" data-id=\"787eeff8\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-317bb5b4 elementor-widget elementor-widget-text-editor\" data-id=\"317bb5b4\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h2 data-start=\"0\" data-end=\"91\"><strong data-start=\"0\" data-end=\"91\">1. Risk Analysis under Section 12 KRITIS-DachG: The Foundation for Effective Protection<\/strong><\/h2><p data-start=\"93\" data-end=\"390\">The risk analysis within the security concept <strong>under Section 12 KRITIS-DachG<\/strong> is the central starting point for the effective protection of critical infrastructure. It forms the basis for a risk-based security strategy and identifies where the greatest threats and dependencies for your company lie.<\/p><p data-start=\"392\" data-end=\"626\" data-is-last-node=\"\" data-is-only-node=\"\">A structured <strong>all-hazards approach<\/strong> is particularly important here, as reflected, for example, in <strong>BSI Standard 200-3.<\/strong> This means that not only cyber risks are considered, but all relevant scenarios are systematically taken into account.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-6c78ae56 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"61517\" data-id=\"6c78ae56\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-15664626\" data-eae-slider=\"32442\" data-id=\"15664626\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3ad65828 elementor-view-stacked elementor-shape-square elementor-invisible elementor-widget elementor-widget-icon\" data-id=\"3ad65828\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeIn&quot;}\" data-widget_type=\"icon.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon-wrapper\">\n\t\t\t<a class=\"elementor-icon elementor-animation-bounce-in\" href=\"https:\/\/3-core.de\/umsetzung-nis2\/\">\n\t\t\t<i aria-hidden=\"true\" class=\"fas fa-exclamation-triangle\"><\/i>\t\t\t<\/a>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-49a76491\" data-eae-slider=\"76525\" data-id=\"49a76491\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-615a8f87 elementor-invisible elementor-widget elementor-widget-text-editor\" data-id=\"615a8f87\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInRight&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h3 data-start=\"0\" data-end=\"53\"><strong data-start=\"0\" data-end=\"53\">Typical Sources of Risk in the KRITIS Environment<\/strong><\/h3><p data-start=\"55\" data-end=\"83\"><strong>These include, among others:<\/strong><\/p><ul data-start=\"85\" data-end=\"408\" data-is-last-node=\"\" data-is-only-node=\"\"><li data-section-id=\"1e54cf6\" data-start=\"85\" data-end=\"129\"><p data-start=\"87\" data-end=\"129\">natural events and environmental hazards<\/p><\/li><li data-section-id=\"1u64nwv\" data-start=\"130\" data-end=\"178\"><p data-start=\"132\" data-end=\"178\">technical failures and infrastructure damage<\/p><\/li><li data-section-id=\"13vc5xi\" data-start=\"179\" data-end=\"225\"><p data-start=\"181\" data-end=\"225\">organizational errors and process failures<\/p><\/li><li data-section-id=\"kzf47d\" data-start=\"226\" data-end=\"273\"><p data-start=\"228\" data-end=\"273\">staff shortages or personnel unavailability<\/p><\/li><li data-section-id=\"3jvc6x\" data-start=\"274\" data-end=\"321\"><p data-start=\"276\" data-end=\"321\">disruptions in supply chains and interfaces<\/p><\/li><li data-section-id=\"vltgdy\" data-start=\"322\" data-end=\"369\"><p data-start=\"324\" data-end=\"369\">sabotage, vandalism, and deliberate attacks<\/p><\/li><li data-section-id=\"1sjnwcx\" data-start=\"370\" data-end=\"408\" data-is-last-node=\"\"><p data-start=\"372\" data-end=\"408\" data-is-last-node=\"\">hybrid threats and cascading effects<\/p><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-7df58196 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"74794\" data-id=\"7df58196\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-701e2fc7\" data-eae-slider=\"11329\" data-id=\"701e2fc7\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-4bfb752 elementor-view-stacked elementor-shape-square elementor-invisible elementor-widget elementor-widget-icon\" data-id=\"4bfb752\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeIn&quot;}\" data-widget_type=\"icon.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon-wrapper\">\n\t\t\t<a class=\"elementor-icon elementor-animation-bounce-in\" href=\"https:\/\/3-core.de\/umsetzung-kritis-dachg\/\">\n\t\t\t<i aria-hidden=\"true\" class=\"far fa-edit\"><\/i>\t\t\t<\/a>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-327a1860\" data-eae-slider=\"57877\" data-id=\"327a1860\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-6d2826eb elementor-invisible elementor-widget elementor-widget-text-editor\" data-id=\"6d2826eb\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInRight&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h3 data-start=\"0\" data-end=\"46\"><strong data-start=\"0\" data-end=\"46\">What a Robust Risk Analysis Should Deliver<\/strong><\/h3><p data-start=\"48\" data-end=\"79\">A sound risk analysis provides:<\/p><ul data-start=\"81\" data-end=\"335\"><li data-section-id=\"1cs4rus\" data-start=\"81\" data-end=\"125\"><p data-start=\"83\" data-end=\"125\">a realistic picture of threats and risks<\/p><\/li><li data-section-id=\"rkoqxv\" data-start=\"126\" data-end=\"171\"><p data-start=\"128\" data-end=\"171\">prioritization of the most critical risks<\/p><\/li><li data-section-id=\"1sspsoy\" data-start=\"172\" data-end=\"210\"><p data-start=\"174\" data-end=\"210\">the basis for targeted investments<\/p><\/li><li data-section-id=\"icd7mr\" data-start=\"211\" data-end=\"261\"><p data-start=\"213\" data-end=\"261\">better decision-making for protective measures<\/p><\/li><li data-section-id=\"933qed\" data-start=\"262\" data-end=\"335\"><p data-start=\"264\" data-end=\"335\">stronger ability to demonstrate compliance to supervisory authorities<\/p><\/li><\/ul><p data-start=\"337\" data-end=\"445\" data-is-last-node=\"\" data-is-only-node=\"\">In this way, a legal obligation becomes a strategic management tool for resilience and operational security.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-b7b3534 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"8127\" data-id=\"b7b3534\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4913a79\" data-eae-slider=\"73031\" data-id=\"4913a79\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f299749 elementor-widget elementor-widget-spacer\" data-id=\"f299749\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7f1aa7d elementor-widget elementor-widget-heading\" data-id=\"7f1aa7d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">2. Protection Zone Concept: Physical Protection of Critical Infrastructure<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-edd66a6 elementor-widget elementor-widget-text-editor\" data-id=\"edd66a6\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"0\" data-end=\"266\">In addition to organisational and technical measures, <strong>the physical protection of critical infrastructure<\/strong> plays a central role. A protection zone concept is designed to secure sensitive areas in graduated layers &#8211; from the outer perimeter to the innermost core zones.<\/p><p data-start=\"268\" data-end=\"439\" data-is-last-node=\"\" data-is-only-node=\"\">The principle follows <strong>an onion-layer model:<\/strong> multiple coordinated layers of protection make intrusion more difficult, delay attacks, and improve the detection of incidents.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-a4ddace elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"34564\" data-id=\"a4ddace\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-5ead88d\" data-eae-slider=\"17933\" data-id=\"5ead88d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-fe9b0e7 elementor-view-stacked elementor-shape-square elementor-invisible elementor-widget elementor-widget-icon\" data-id=\"fe9b0e7\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeIn&quot;}\" data-widget_type=\"icon.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon-wrapper\">\n\t\t\t<a class=\"elementor-icon elementor-animation-bounce-in\" href=\"https:\/\/3-core.de\/umsetzung-nis2\/\">\n\t\t\t<i aria-hidden=\"true\" class=\"far fa-building\"><\/i>\t\t\t<\/a>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-69122c7\" data-eae-slider=\"15940\" data-id=\"69122c7\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-93eb762 elementor-invisible elementor-widget elementor-widget-text-editor\" data-id=\"93eb762\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInRight&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h3 data-start=\"0\" data-end=\"51\"><strong data-start=\"0\" data-end=\"51\">Typical Components of a Protection Zone Concept<\/strong><\/h3><p data-start=\"53\" data-end=\"99\">An effective protection zone concept includes:<\/p><ul data-start=\"101\" data-end=\"447\" data-is-last-node=\"\" data-is-only-node=\"\"><li data-section-id=\"lx3ers\" data-start=\"101\" data-end=\"174\"><p data-start=\"103\" data-end=\"174\">perimeter protection, e.g. fences, gates, barriers, and site security<\/p><\/li><li data-section-id=\"3wjbhd\" data-start=\"175\" data-end=\"225\"><p data-start=\"177\" data-end=\"225\">secured building envelopes, doors, and windows<\/p><\/li><li data-section-id=\"ujs8kd\" data-start=\"226\" data-end=\"252\"><p data-start=\"228\" data-end=\"252\">access control systems<\/p><\/li><li data-section-id=\"l452be\" data-start=\"253\" data-end=\"289\"><p data-start=\"255\" data-end=\"289\">video surveillance and detection<\/p><\/li><li data-section-id=\"vgepdh\" data-start=\"290\" data-end=\"329\"><p data-start=\"292\" data-end=\"329\">alerting and intervention processes<\/p><\/li><li data-section-id=\"15vw4jv\" data-start=\"330\" data-end=\"377\"><p data-start=\"332\" data-end=\"377\">clear responsibilities and escalation paths<\/p><\/li><li data-section-id=\"1st63o2\" data-start=\"378\" data-end=\"447\" data-is-last-node=\"\"><p data-start=\"380\" data-end=\"447\" data-is-last-node=\"\">organizational rules for visitors, service providers, and employees<\/p><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-3bc0544 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"45842\" data-id=\"3bc0544\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7021006\" data-eae-slider=\"17820\" data-id=\"7021006\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-8268b1d elementor-widget elementor-widget-text-editor\" data-id=\"8268b1d\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h3 data-start=\"0\" data-end=\"55\"><strong data-start=\"0\" data-end=\"55\">Why Protection Zones Are So Important Operationally<\/strong><\/h3><p data-start=\"57\" data-end=\"465\">A graduated protection zone concept is far more than a purely structural security measure. It creates the operational foundation for reducing risks at an early stage, effectively separating sensitive areas, and detecting unauthorized access more quickly. At the same time, it improves response capability in the event of an incident and helps ensure the long-term secure operation of critical infrastructure.<\/p><p data-start=\"467\" data-end=\"712\" data-is-last-node=\"\" data-is-only-node=\"\">However, such a concept only reaches its full effectiveness when structural, technical, and organisational measures are closely aligned and work together seamlessly in practice. Only then can a robust and effective level of security be achieved.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0df3eb8 elementor-widget elementor-widget-spacer\" data-id=\"0df3eb8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-19a79a1 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"63359\" data-id=\"19a79a1\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-bb6f95e\" data-eae-slider=\"79800\" data-id=\"bb6f95e\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-766761d elementor-widget elementor-widget-heading\" data-id=\"766761d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">3. Roadmap to Greater Resilience \u2013 What Does the Resilience Plan under Section 13 KRITIS-DachG Include?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2af1e51 elementor-widget elementor-widget-text-editor\" data-id=\"2af1e51\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"0\" data-end=\"294\"><strong>The resilience plan under Section 13 KRITIS-DachG<\/strong> is the structured roadmap that enables operators of critical infrastructure to systematically strengthen their resilience. Its purpose is to improve prevention, limit the impact of disruptions, and accelerate the recovery of critical processes.<\/p><p data-start=\"296\" data-end=\"404\" data-is-last-node=\"\" data-is-only-node=\"\">A resilience plan is not an isolated document, but an operational management tool for day-to-day operations.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-e308be7 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"31784\" data-id=\"e308be7\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-cd3a8d4\" data-eae-slider=\"42871\" data-id=\"cd3a8d4\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ef2f30c elementor-view-stacked elementor-shape-square elementor-invisible elementor-widget elementor-widget-icon\" data-id=\"ef2f30c\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeIn&quot;}\" data-widget_type=\"icon.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon-wrapper\">\n\t\t\t<a class=\"elementor-icon elementor-animation-bounce-in\" href=\"https:\/\/3-core.de\/umsetzung-nis2\/\">\n\t\t\t<i aria-hidden=\"true\" class=\"far fa-file-alt\"><\/i>\t\t\t<\/a>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-3a9c3c0\" data-eae-slider=\"82417\" data-id=\"3a9c3c0\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-8c67967 elementor-invisible elementor-widget elementor-widget-text-editor\" data-id=\"8c67967\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInRight&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"0\" data-end=\"37\"><strong data-start=\"0\" data-end=\"37\">What Belongs in a Resilience Plan<\/strong><\/p><p data-start=\"39\" data-end=\"126\">A practical resilience plan should include, among other things, the following elements:<\/p><ul data-start=\"128\" data-end=\"612\" data-is-last-node=\"\" data-is-only-node=\"\"><li data-section-id=\"wd6w0q\" data-start=\"128\" data-end=\"177\"><p data-start=\"130\" data-end=\"177\">an inventory of critical processes and assets<\/p><\/li><li data-section-id=\"aghwhp\" data-start=\"178\" data-end=\"210\"><p data-start=\"180\" data-end=\"210\">risk and dependency analysis<\/p><\/li><li data-section-id=\"cqkpg4\" data-start=\"211\" data-end=\"277\"><p data-start=\"213\" data-end=\"277\">assessment of supply chains, interfaces, and cascading effects<\/p><\/li><li data-section-id=\"sajcob\" data-start=\"278\" data-end=\"317\"><p data-start=\"280\" data-end=\"317\">definition of protection objectives<\/p><\/li><li data-section-id=\"80xwza\" data-start=\"318\" data-end=\"380\"><p data-start=\"320\" data-end=\"380\">measures for prevention, detection, response, and recovery<\/p><\/li><li data-section-id=\"xu5ubr\" data-start=\"381\" data-end=\"422\"><p data-start=\"383\" data-end=\"422\">emergency capacities and redundancies<\/p><\/li><li data-section-id=\"vko7c6\" data-start=\"423\" data-end=\"488\"><p data-start=\"425\" data-end=\"488\">crisis management organization and decision-making structures<\/p><\/li><li data-section-id=\"1tl6n31\" data-start=\"489\" data-end=\"529\"><p data-start=\"491\" data-end=\"529\">communication and reporting channels<\/p><\/li><li data-section-id=\"rhmguo\" data-start=\"530\" data-end=\"563\"><p data-start=\"532\" data-end=\"563\">exercise and testing concepts<\/p><\/li><li data-section-id=\"txfuc0\" data-start=\"564\" data-end=\"612\" data-is-last-node=\"\"><p data-start=\"566\" data-end=\"612\" data-is-last-node=\"\">monitoring, review, and continuous improvement<\/p><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-b287698 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"2548\" data-id=\"b287698\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-67fcc10\" data-eae-slider=\"92055\" data-id=\"67fcc10\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-d4558a4 elementor-widget elementor-widget-text-editor\" data-id=\"d4558a4\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"0\" data-end=\"42\"><strong data-start=\"0\" data-end=\"42\">Operational Value of a Resilience Plan<\/strong><\/p><p data-start=\"44\" data-end=\"489\">A robust resilience plan creates the conditions for identifying vulnerabilities at an early stage and addressing them in a targeted manner before they develop into critical disruptions. It helps to effectively limit the impact of outages, shorten recovery times, and clearly define responsibilities in the event of an incident. At the same time, it ensures that regulatory requirements can be met in a structured, transparent, and auditable way.<\/p><p data-start=\"491\" data-end=\"658\" data-is-last-node=\"\" data-is-only-node=\"\">This means resilience is no longer treated as a one-time project, but is embedded as a permanent and actively practiced operating standard throughout the organisation.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b66e1e9 elementor-widget elementor-widget-spacer\" data-id=\"b66e1e9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-7b86e33 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"22185\" data-id=\"7b86e33\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-aa8f137\" data-eae-slider=\"69021\" data-id=\"aa8f137\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-7e1c4ce elementor-widget elementor-widget-heading\" data-id=\"7e1c4ce\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">4. KRITIS Umbrella Act 2026: Reporting and Evidence Obligations \u2013 How to Become Audit-Ready<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e19035f elementor-widget elementor-widget-text-editor\" data-id=\"e19035f\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"0\" data-end=\"299\">A particularly important aspect of <strong>the KRITIS Umbrella Act<\/strong> is the new reporting and evidence obligations. In the future, companies will not only be required to report incidents within the prescribed deadlines, but also to demonstrate that their resilience measures have been implemented effectively.<\/p><p data-start=\"301\" data-end=\"359\"><strong data-start=\"301\" data-end=\"359\">Which reporting obligations KRITIS companies will face<\/strong><\/p><p data-start=\"361\" data-end=\"515\">The current draft provides in particular for incident reports to be submitted to <strong>the<\/strong> <strong>BBK<\/strong> via a joint digital reporting portal operated by <strong>the BBK and BSI.<\/strong><\/p><p data-start=\"517\" data-end=\"538\"><strong>Key elements include:<\/strong><\/p><ul data-start=\"540\" data-end=\"741\"><li data-section-id=\"9e3r6o\" data-start=\"540\" data-end=\"642\"><p data-start=\"542\" data-end=\"642\">an initial report without undue delay, no later than 24 hours after becoming aware of the incident<\/p><\/li><li data-section-id=\"uenssf\" data-start=\"643\" data-end=\"684\"><p data-start=\"645\" data-end=\"684\">updates in the case of ongoing events<\/p><\/li><li data-section-id=\"1eillbc\" data-start=\"685\" data-end=\"741\"><p data-start=\"687\" data-end=\"741\">a detailed report no later than one month afterwards<\/p><\/li><\/ul><p data-start=\"743\" data-end=\"880\" data-is-last-node=\"\" data-is-only-node=\"\">The exact design of the reporting procedure and the formal requirements will be further specified by the competent supervisory authority.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-19739a6c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"15476\" data-id=\"19739a6c\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-47ca13af\" data-eae-slider=\"67933\" data-id=\"47ca13af\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-91a3103 elementor-widget elementor-widget-image\" data-id=\"91a3103\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/3-core.de\/wp-content\/uploads\/2024\/10\/DSC04563-1024x683.jpeg\" class=\"attachment-large size-large wp-image-17906\" alt=\"A wooden desk with two open white binders filled with papers from recent risk analyses, a notebook, a pen, two small potted plants, a mug, and an empty black office chair in the background.\" srcset=\"https:\/\/3-core.de\/wp-content\/uploads\/2024\/10\/DSC04563-1024x683.jpeg 1024w, https:\/\/3-core.de\/wp-content\/uploads\/2024\/10\/DSC04563-300x200.jpeg 300w, https:\/\/3-core.de\/wp-content\/uploads\/2024\/10\/DSC04563-768x512.jpeg 768w, https:\/\/3-core.de\/wp-content\/uploads\/2024\/10\/DSC04563-1536x1024.jpeg 1536w, https:\/\/3-core.de\/wp-content\/uploads\/2024\/10\/DSC04563-2048x1365.jpeg 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" title=\"\">\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-828d24f\" data-eae-slider=\"33408\" data-id=\"828d24f\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-d17bb20 elementor-widget elementor-widget-heading\" data-id=\"d17bb20\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What Evidence Companies Must Provide<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6193f5c8 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"6193f5c8\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"0\" data-end=\"185\">For auditability and evidentiary robustness, it is essential that companies are able to document the implementation of their resilience requirements in a reliable and verifiable manner.<\/p><p data-start=\"187\" data-end=\"249\"><strong>In particular, authorities may request the following evidence:<\/strong><\/p><ul data-start=\"251\" data-end=\"532\" data-is-last-node=\"\" data-is-only-node=\"\"><li data-section-id=\"eevl8e\" data-start=\"251\" data-end=\"270\"><p data-start=\"253\" data-end=\"270\">resilience plan<\/p><\/li><li data-section-id=\"kfqx32\" data-start=\"271\" data-end=\"291\"><p data-start=\"273\" data-end=\"291\">security concept<\/p><\/li><li data-section-id=\"15sbb7m\" data-start=\"292\" data-end=\"334\"><p data-start=\"294\" data-end=\"334\">results of internal or external audits<\/p><\/li><li data-section-id=\"oipy2d\" data-start=\"335\" data-end=\"390\"><p data-start=\"337\" data-end=\"390\">documentation of measures and implementation status<\/p><\/li><li data-section-id=\"1ea03eh\" data-start=\"391\" data-end=\"426\"><p data-start=\"393\" data-end=\"426\">evidence of exercises and tests<\/p><\/li><li data-section-id=\"nj6u7u\" data-start=\"427\" data-end=\"476\"><p data-start=\"429\" data-end=\"476\">remediation plans for identified deficiencies<\/p><\/li><li data-section-id=\"1cku3bg\" data-start=\"477\" data-end=\"532\" data-is-last-node=\"\"><p data-start=\"479\" data-end=\"532\" data-is-last-node=\"\">proof of implementation following on-site inspections<\/p><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-67a57f2a elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"93781\" data-id=\"67a57f2a\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-55ec9e41\" data-eae-slider=\"72820\" data-id=\"55ec9e41\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e3edf92 elementor-widget elementor-widget-spacer\" data-id=\"e3edf92\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ea10a26 elementor-widget elementor-widget-heading\" data-id=\"ea10a26\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">We get you ready. Trust 3-core as your consulting partner of choice.<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-228b0bb elementor-widget elementor-widget-text-editor\" data-id=\"228b0bb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"0\" data-end=\"517\"><strong>3-core<\/strong> helps you translate the requirements of the <strong>KRITIS-DachG<\/strong> into day-to-day operations in a pragmatic and audit-ready manner from designing reporting and alerting processes, to developing the resilience plan, to preparing for audits, certifications, and on-site inspections by supervisory authorities. In addition, we provide practical tools that can be integrated into your existing landscape in a system-agnostic way &#8211; both through our risk analysis template and through a practical resilience plan framework.<\/p><p data-start=\"519\" data-end=\"909\" data-is-last-node=\"\" data-is-only-node=\"\">And we do not leave you to handle it alone: our interdisciplinary experts support the implementation process, adapt approaches and templates to companies across all <strong>KRITIS sectors<\/strong> and industries, and assist with execution so that tools become effective processes. In this way, legal requirements are turned into <strong>clear procedures, robust evidence, and real resilience in everyday operations.<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9d1eef8 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"9d1eef8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ffde3fb elementor-widget elementor-widget-heading\" data-id=\"ffde3fb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">FAQ on the KRITIS Umbrella Act 2026<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-65bfee8a elementor-widget elementor-widget-accordion\" data-id=\"65bfee8a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h2 id=\"elementor-tab-title-1701\" class=\"elementor-tab-title\" data-tab=\"1\" role=\"button\" aria-controls=\"elementor-tab-content-1701\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What is the KRITIS Umbrella Act?<\/a>\n\t\t\t\t\t<\/h2>\n\t\t\t\t\t<div id=\"elementor-tab-content-1701\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"1\" role=\"region\" aria-labelledby=\"elementor-tab-title-1701\"><p><strong>The KRITIS Umbrella Act<\/strong> is Germany\u2019s national implementation of the <strong>CER Directive.<\/strong> It sets out requirements for the resilience and protection of critical infrastructure.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h2 id=\"elementor-tab-title-1702\" class=\"elementor-tab-title\" data-tab=\"2\" role=\"button\" aria-controls=\"elementor-tab-content-1702\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What will change for KRITIS companies in 2026?<\/a>\n\t\t\t\t\t<\/h2>\n\t\t\t\t\t<div id=\"elementor-tab-content-1702\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"2\" role=\"region\" aria-labelledby=\"elementor-tab-title-1702\"><p>KRITIS companies must prepare for stricter requirements in risk analysis, resilience planning, physical protection, as well as reporting and evidence obligations.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h2 id=\"elementor-tab-title-1703\" class=\"elementor-tab-title\" data-tab=\"3\" role=\"button\" aria-controls=\"elementor-tab-content-1703\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What is a risk analysis under Section 12 KRITIS-DachG?<\/a>\n\t\t\t\t\t<\/h2>\n\t\t\t\t\t<div id=\"elementor-tab-content-1703\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"3\" role=\"region\" aria-labelledby=\"elementor-tab-title-1703\"><p>It is part of the security concept and serves to systematically identify threats, dependencies, and vulnerabilities, and to derive appropriate protective measures.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h2 id=\"elementor-tab-title-1704\" class=\"elementor-tab-title\" data-tab=\"4\" role=\"button\" aria-controls=\"elementor-tab-content-1704\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What should be included in a resilience plan under Section 13 KRITIS-DachG?<\/a>\n\t\t\t\t\t<\/h2>\n\t\t\t\t\t<div id=\"elementor-tab-content-1704\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"4\" role=\"region\" aria-labelledby=\"elementor-tab-title-1704\"><div class=\"flex flex-col text-sm pb-25\"><article class=\"text-token-text-primary w-full focus:outline-none [--shadow-height:45px] has-data-writing-block:pointer-events-none has-data-writing-block:-mt-(--shadow-height) has-data-writing-block:pt-(--shadow-height) [&amp;:has([data-writing-block])&gt;*]:pointer-events-auto scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]\" dir=\"auto\" tabindex=\"-1\" data-turn-id=\"request-WEB:846d1c23-5848-4521-8188-3181e03f1c27-40\" data-testid=\"conversation-turn-70\" data-scroll-anchor=\"true\" data-turn=\"assistant\"><div class=\"text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm\/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg\/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)\"><div class=\"[--thread-content-max-width:40rem] @w-lg\/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group\/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn\" tabindex=\"-1\"><div class=\"flex max-w-full flex-col gap-4 grow\"><div class=\"min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal [.text-message+&amp;]:mt-1\" dir=\"auto\" data-message-author-role=\"assistant\" data-message-id=\"45e2feab-f3d0-441d-9570-b23e4ad09019\" data-message-model-slug=\"gpt-5-4-thinking\"><div class=\"flex w-full flex-col gap-1 empty:hidden\"><div class=\"markdown prose dark:prose-invert w-full wrap-break-word light markdown-new-styling\"><p data-start=\"0\" data-end=\"198\" data-is-last-node=\"\" data-is-only-node=\"\">A resilience plan includes, among other things, risk and dependency analyses, protection objectives, measures for prevention and response, emergency organisation, exercises, and supporting evidence.<\/p><\/div><\/div><\/div><\/div><\/div><\/div><\/article><\/div><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h2 id=\"elementor-tab-title-1705\" class=\"elementor-tab-title\" data-tab=\"5\" role=\"button\" aria-controls=\"elementor-tab-content-1705\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What does audit-ready mean in the KRITIS context?<\/a>\n\t\t\t\t\t<\/h2>\n\t\t\t\t\t<div id=\"elementor-tab-content-1705\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"5\" role=\"region\" aria-labelledby=\"elementor-tab-title-1705\"><p>Audit-ready means that a company has structured its measures, processes, and supporting evidence in such a way that it can demonstrate compliance with the requirements of authorities or auditors in a robust and well-organised manner.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t<script type=\"application\/ld+json\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is the KRITIS Umbrella Act?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p><strong>The KRITIS Umbrella Act<\\\/strong> is Germany\\u2019s national implementation of the <strong>CER Directive.<\\\/strong> It sets out requirements for the resilience and protection of critical infrastructure.<\\\/p>\"}},{\"@type\":\"Question\",\"name\":\"What will change for KRITIS companies in 2026?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>KRITIS companies must prepare for stricter requirements in risk analysis, resilience planning, physical protection, as well as reporting and evidence obligations.<\\\/p>\"}},{\"@type\":\"Question\",\"name\":\"What is a risk analysis under Section 12 KRITIS-DachG?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>It is part of the security concept and serves to systematically identify threats, dependencies, and vulnerabilities, and to derive appropriate protective measures.<\\\/p>\"}},{\"@type\":\"Question\",\"name\":\"What should be included in a resilience plan under Section 13 KRITIS-DachG?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<div class=\\\"flex flex-col text-sm pb-25\\\"><article class=\\\"text-token-text-primary w-full focus:outline-none [--shadow-height:45px] has-data-writing-block:pointer-events-none has-data-writing-block:-mt-(--shadow-height) has-data-writing-block:pt-(--shadow-height) [&amp;:has([data-writing-block])&gt;*]:pointer-events-auto scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]\\\" dir=\\\"auto\\\" tabindex=\\\"-1\\\" data-turn-id=\\\"request-WEB:846d1c23-5848-4521-8188-3181e03f1c27-40\\\" data-testid=\\\"conversation-turn-70\\\" data-scroll-anchor=\\\"true\\\" data-turn=\\\"assistant\\\"><div class=\\\"text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm\\\/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg\\\/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)\\\"><div class=\\\"[--thread-content-max-width:40rem] @w-lg\\\/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group\\\/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn\\\" tabindex=\\\"-1\\\"><div class=\\\"flex max-w-full flex-col gap-4 grow\\\"><div class=\\\"min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal [.text-message+&amp;]:mt-1\\\" dir=\\\"auto\\\" data-message-author-role=\\\"assistant\\\" data-message-id=\\\"45e2feab-f3d0-441d-9570-b23e4ad09019\\\" data-message-model-slug=\\\"gpt-5-4-thinking\\\"><div class=\\\"flex w-full flex-col gap-1 empty:hidden\\\"><div class=\\\"markdown prose dark:prose-invert w-full wrap-break-word light markdown-new-styling\\\"><p data-start=\\\"0\\\" data-end=\\\"198\\\" data-is-last-node=\\\"\\\" data-is-only-node=\\\"\\\">A resilience plan includes, among other things, risk and dependency analyses, protection objectives, measures for prevention and response, emergency organisation, exercises, and supporting evidence.<\\\/p><\\\/div><\\\/div><\\\/div><\\\/div><\\\/div><\\\/div><\\\/article><\\\/div>\"}},{\"@type\":\"Question\",\"name\":\"What does audit-ready mean in the KRITIS context?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>Audit-ready means that a company has structured its measures, processes, and supporting evidence in such a way that it can demonstrate compliance with the requirements of authorities or auditors in a robust and well-organised manner.<\\\/p>\"}}]}<\/script>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6d39a991 elementor-widget elementor-widget-spacer\" data-id=\"6d39a991\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-12317c08 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"94312\" data-id=\"12317c08\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-20163922\" data-eae-slider=\"75992\" data-id=\"20163922\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ae00a3b elementor-widget elementor-widget-text-editor\" data-id=\"ae00a3b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h2>Discover More: Projects &amp; Articles<\/h2>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-71eb6316 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"94699\" data-id=\"71eb6316\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-71a93bec\" data-eae-slider=\"95093\" data-id=\"71a93bec\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-3613c784 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"72555\" data-id=\"3613c784\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6bc1e801\" data-eae-slider=\"78486\" data-id=\"6bc1e801\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-b4e26c6 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"35317\" data-id=\"b4e26c6\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4b2d1b9\" data-eae-slider=\"13583\" data-id=\"4b2d1b9\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-24186 elementor-widget elementor-widget-global elementor-global-24186 elementor-widget-html\" data-id=\"24186\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div style=\"text-align: center;\">\n<a href=\"https:\/\/zeeg.me\/info6655\/30min-termin\" class=\"zeeg-popup-link\" target=\"_blank\" rel=\"noopener\">Book your Free Kickoff Call<\/a>\n<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>With the national transposition of the CER Directive, the protection of critical infrastructure in Germany will gain significantly greater importance in 2026. The current draft bill for the KRITIS Umbrella Act makes this clear: operators of critical infrastructure must prepare for stricter requirements, new reporting obligations, and robust evidence and documentation requirements. KRITIS Umbrella Act [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":41782,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"elementor_header_footer","format":"standard","meta":{"ocean_post_layout":"","ocean_both_sidebars_style":"","ocean_both_sidebars_content_width":0,"ocean_both_sidebars_sidebars_width":0,"ocean_sidebar":"0","ocean_second_sidebar":"0","ocean_disable_margins":"enable","ocean_add_body_class":"","ocean_shortcode_before_top_bar":"","ocean_shortcode_after_top_bar":"","ocean_shortcode_before_header":"","ocean_shortcode_after_header":"","ocean_has_shortcode":"","ocean_shortcode_after_title":"","ocean_shortcode_before_footer_widgets":"","ocean_shortcode_after_footer_widgets":"","ocean_shortcode_before_footer_bottom":"","ocean_shortcode_after_footer_bottom":"","ocean_display_top_bar":"default","ocean_display_header":"default","ocean_header_style":"","ocean_center_header_left_menu":"0","ocean_custom_header_template":"0","ocean_custom_logo":0,"ocean_custom_retina_logo":0,"ocean_custom_logo_max_width":0,"ocean_custom_logo_tablet_max_width":0,"ocean_custom_logo_mobile_max_width":0,"ocean_custom_logo_max_height":0,"ocean_custom_logo_tablet_max_height":0,"ocean_custom_logo_mobile_max_height":0,"ocean_header_custom_menu":"0","ocean_menu_typo_font_family":"0","ocean_menu_typo_font_subset":"","ocean_menu_typo_font_size":0,"ocean_menu_typo_font_size_tablet":0,"ocean_menu_typo_font_size_mobile":0,"ocean_menu_typo_font_size_unit":"px","ocean_menu_typo_font_weight":"","ocean_menu_typo_font_weight_tablet":"","ocean_menu_typo_font_weight_mobile":"","ocean_menu_typo_transform":"","ocean_menu_typo_transform_tablet":"","ocean_menu_typo_transform_mobile":"","ocean_menu_typo_line_height":0,"ocean_menu_typo_line_height_tablet":0,"ocean_menu_typo_line_height_mobile":0,"ocean_menu_typo_line_height_unit":"","ocean_menu_typo_spacing":0,"ocean_menu_typo_spacing_tablet":0,"ocean_menu_typo_spacing_mobile":0,"ocean_menu_typo_spacing_unit":"","ocean_menu_link_color":"","ocean_menu_link_color_hover":"","ocean_menu_link_color_active":"","ocean_menu_link_background":"","ocean_menu_link_hover_background":"","ocean_menu_link_active_background":"","ocean_menu_social_links_bg":"","ocean_menu_social_hover_links_bg":"","ocean_menu_social_links_color":"","ocean_menu_social_hover_links_color":"","ocean_disable_title":"default","ocean_disable_heading":"default","ocean_post_title":"","ocean_post_subheading":"","ocean_post_title_style":"","ocean_post_title_background_color":"","ocean_post_title_background":0,"ocean_post_title_bg_image_position":"","ocean_post_title_bg_image_attachment":"","ocean_post_title_bg_image_repeat":"","ocean_post_title_bg_image_size":"","ocean_post_title_height":0,"ocean_post_title_bg_overlay":0.5,"ocean_post_title_bg_overlay_color":"","ocean_disable_breadcrumbs":"default","ocean_breadcrumbs_color":"","ocean_breadcrumbs_separator_color":"","ocean_breadcrumbs_links_color":"","ocean_breadcrumbs_links_hover_color":"","ocean_display_footer_widgets":"default","ocean_display_footer_bottom":"default","ocean_custom_footer_template":"0","ocean_post_oembed":"","ocean_post_self_hosted_media":"","ocean_post_video_embed":"","ocean_link_format":"","ocean_link_format_target":"self","ocean_quote_format":"","ocean_quote_format_link":"post","ocean_gallery_link_images":"on","ocean_gallery_id":[],"footnotes":""},"categories":[174],"tags":[],"class_list":["post-41818","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-englisch","entry","has-media"],"_links":{"self":[{"href":"https:\/\/3-core.de\/en\/wp-json\/wp\/v2\/posts\/41818","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/3-core.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/3-core.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/3-core.de\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/3-core.de\/en\/wp-json\/wp\/v2\/comments?post=41818"}],"version-history":[{"count":15,"href":"https:\/\/3-core.de\/en\/wp-json\/wp\/v2\/posts\/41818\/revisions"}],"predecessor-version":[{"id":41844,"href":"https:\/\/3-core.de\/en\/wp-json\/wp\/v2\/posts\/41818\/revisions\/41844"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/3-core.de\/en\/wp-json\/wp\/v2\/media\/41782"}],"wp:attachment":[{"href":"https:\/\/3-core.de\/en\/wp-json\/wp\/v2\/media?parent=41818"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/3-core.de\/en\/wp-json\/wp\/v2\/categories?post=41818"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/3-core.de\/en\/wp-json\/wp\/v2\/tags?post=41818"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}