Germany Approves Critical Infrastructure Protection Law (Kritis Law)

0 comments

Germany Strengthens Critical Infrastructure Protection with Modern Law

Germany has enacted a new law designed to bolster the protection of its critical infrastructure, addressing vulnerabilities to both physical, and cyberattacks. The “Umbrella Act for Critical Infrastructure Protection” (KRITIS), passed by the Bundestag in January 2026 and subsequently approved by the Bundesrat, establishes nationwide minimum standards for essential sectors and implements an EU directive aimed at increasing resilience.

What Sectors are Covered?

The KRITIS law collectively addresses nine sectors previously regulated separately: energy, transport and traffic, finance and insurance, health, drinking water, wastewater, municipal waste disposal, information technology and telecommunications, food, space, and public administration.

Key Provisions of the KRITIS Law

  • Identification of Critical Systems: The law defines which companies and facilities are considered part of the critical infrastructure nationwide. A facility must be essential for overall supply in Germany and serve more than 500,000 people.
  • Minimum Security Standards: Nationwide, cross-sector minimum standards are established for the physical protection of critical infrastructure. This includes measures like emergency teams, enhanced property protection, and resilience strategies.
  • Risk Assessments and Reporting: Operators are required to conduct regular risk analyses and implement measures to minimize identified risks. They also have a duty to report security incidents.
  • Federal State Authority: The federal states are given the opportunity to identify additional critical facilities that fall solely under their responsibility.
  • Oversight and Penalties: The Federal Office for Civil Protection and Disaster Relief (BBK) will oversee implementation and can impose fines ranging from €100,000 to €1 million for violations.

Addressing Concerns and Implementation

Initial concerns centered on the threshold of 500,000 people a facility must serve to be considered critical infrastructure. Some federal states argued this was too high, particularly for sparsely populated regions. A protocol declaration was issued to address these concerns, allowing for greater flexibility in state-level identification of critical facilities.

Driving Forces Behind the Law

The strengthening of critical infrastructure protection is driven by both EU regulations, specifically the CER Directive on the resilience of critical entities, and a growing number of attacks targeting such infrastructure. Prior to this law, security measures were largely sector-specific and focused on IT security. The KRITIS law introduces cross-sector regulations and emphasizes physical protection.

Looking Ahead

The Federal Ministry of the Interior will evaluate the new law after two years to assess its effectiveness. This evaluation will be crucial in refining the framework and ensuring Germany’s critical infrastructure remains resilient against evolving threats.

Related Posts

Leave a Comment