KRITIS Ordinance 2026: What obligations operators really have to meet
With the KRITIS umbrella law and the adapted BSI-KritisV, the threshold values, obligations to provide evidence and the amount of fines will change for operators of critical infrastructures in 2026. This article explains which obligations remain specific, which ones are new, and how an information security officer operationally establishes audit capability.
With the entry into force of the NIS 2 directive and the parallel adaptation of the BSI-KritisV, the list of obligations for operators of critical infrastructures in Germany will become significantly more complex in 2026. The federal government has presented the KRITIS umbrella law and the NIS2UmsuCG, which together eliminate the previous separation between IT security and physical resilience and create a uniform framework of obligations for around 29,500 affected companies in Germany. The thresholds of the BSI-KritisV remain calibrated at 500,000 people served in most sectors, but the scope of application is expanding to include new sectors such as public administration, food supply and digital infrastructure, and the threat of sanctions increases to up to 10 million euros or two percent of group sales for essential facilities.
This article explains in detail what obligations operators will specifically have to meet in 2026, how the BSI-KritisV differs from the The KRITIS umbrella law and the NIS 2 implementation define which thresholds apply to which sector, how the provision of evidence according to Section 8a Paragraph 3 BSIG works, which reporting obligations exist within 24 and 72 hours and which sanctions are threatened. It focuses on the operational view of an information security officer, not the regulatory theory, and ultimately shows how CIVAC, as a compliance platform and officer-as-a-service, makes the duties manageable in two working days, instead of two to six weeks as in the classic consulting market.
Key Takeaways
- The BSI-KritisV defines sectoral thresholds; The operational burden of duties results from the interaction with the NIS2UmsuCG, the KRITIS umbrella law and the BSIG. A single paragraph is not enough for compliance.
- Evidence in accordance with Section 8a Paragraph 3 BSIG must be submitted every two years. Anyone who fails to provide proof risks fines of up to ten million euros and an order to rectify the defects within a short period of time.
- The 24-hour early warning and 72-hour follow-up report to the BSI are due as soon as the incident becomes known, not as soon as the internal escalation occurs. A documented reporting path with representation regulations is mandatory.
What the KRITIS Ordinance 2026 really regulates
The BSI-KritisV is a legal regulation of the Federal Ministry of the Interior and Homeland based on Section 10 BSIG. It specifies which facilities, systems and facilities are considered critical infrastructure within the meaning of Section 2 Paragraph 10 BSIG and defines sector-specific thresholds for this. It does not replace the BSIG itself, but supplements it with the quantitative criteria from which a company is considered a KRITIS operator. The obligations themselves continue to be in the BSIG, supplemented by the new regulations from the NIS2UmsuCG and the KRITIS umbrella law, which will come into force from 2026 and adapt German law to the NIS 2 Directive and the EU CER Directive.
The regulation is divided into nine sectors: energy, water, nutrition, information technology and telecommunications, health, finance and insurance, transport and traffic, municipal waste disposal and state administration. For each sector, the annexes to the regulation define threshold values above which the obligations apply. In the energy sector, the threshold for electricity supply is 3,700 GWh annually, in the water sector it is 22 million cubic metres, and in the health sector it is 30,000 fully inpatient treatment cases per year. The threshold values are based on the standard case of 500,000 people served, but are differentiated depending on the sector. The annual self-assessment based on the BSI-KritisV appendices is the first step for the operational assessment of your own impact. Anyone who exceeds the threshold is obliged to register with the BSI as an operator and to appoint an information security officer, to name the contact point for information security to the BSI and to ensure operational availability even outside normal business hours. The BSI also provides a more in-depth overview of the sectors and threshold values on its topic pages and in the annually updated management reports on IT security in Germany.
Scope 2026: Who is newly affected and who falls out of the grid
With the implementation of the NIS 2 Directive via the NIS2UmsuCG, the scope of application of the KRITIS Regulation 2026 is expanding significantly, without the BSI-KritisV itself covering all new addressees. The NIS-2 directive recognises two categories: essential facilities and critical facilities, each divided into high and very high criticality sectors. Essential facilities are largely the classic KRITIS sectors plus providers of digital services above certain size criteria. Key entities include the medium and medium-sized enterprises in the NIS 2 sectors that remain below the KRITIS thresholds but are still subject to the NIS 2 burden. In total, the federal government expects around 29,500 companies in Germany to be affected.
The new scope of application includes medium-sized providers of data centre services, providers of publicly accessible electronic communications services, providers of cloud services, ICT service providers, selected providers of postal services, medium-sized water suppliers, food manufacturers with critical quantities, selected chemical manufacturers and public administration companies. Practically no existing KRITIS operators are left out of the grid, as the threshold values of the BSI-KritisV are essentially retained. For companies that are unsure whether they are affected, a structured threshold check with documentation per sector and asset type is recommended. The self-assessment is only legally valid if it is in writing, dated and provided with calculation bases. The auditor calls, the evidence is ready. CIVAC provides a template for the threshold test as part of the thirty-seven audit templates, including the sector definitions from the BSI-KritisV in the current version, the parallel classification according to NIS 2 criteria and a documented annual repetition of the test with a clear deadline and version status. This means that the self-assessment can be reproduced at any time during the audit and provides the BSI with a reliable basis for argumentation upon request.
The central obligations of operators at a glance
The central duties of the KRITIS operators in 2026 will be divided into six main blocks, which must be fulfilled operationally side by side. Firstly, registration with the BSI as an operator of critical infrastructure in accordance with Section 8b BSIG, stating the contact point and how to reach it. Secondly, the appointment of an information security officer or a contact point for information security in accordance with Section 38 BSIG-new, with a documented reporting line to the management and representation regulations. Thirdly, the implementation of appropriate technical and organisational measures according to the state of the art in accordance with Section 8a Paragraph 1 BSIG, including cryptography, access controls, vulnerability management, supply chain security and business continuity management.
Fourth, the reporting of significant security incidents in accordance with Section 8b BSIG with the new NIS 2 deadlines: 24h early warning, 72h follow-up report and final report within a month. Deadline begins as soon as we become aware of it. Fifthly, the provision of evidence of the implementation of the security measures every two years in accordance with Section 8a Paragraph 3 BSIG, regularly by an authorised inspection body, with a list of defects and a remedial plan. Sixth, the information of the management and the obligation of the top management to approve and monitor the measures, with personal liability of the management according to Section 38 NIS2UmsuCG if duties of care are breached. These six blocks are not an optional catalogue of measures, but rather form the core of the obligations. CIVAC maps all six blocks in one workspace and provides the thirty-seven audit templates, the ISO/IEC 27001:2022 controls and the 24h/72h reporting path centrally, including the report templates for management and the training modules for the board of directors and supervisory board. The appointment certificate, signed, filed, verifiable. The chain of obligations is therefore documented in a single work environment, instead of being distributed across emails, tables and PDFs on different drives, which regularly leads to weak evidence in audits.
Specifically, threshold values: When is your company an operator?
The threshold values of the BSI-KritisV are regulated sector-specifically in Annexes 1 to 8 of the regulation and will be partially updated in 2026. In the energy sector, a facility is considered CRITICAL if it generates, transmits or distributes electricity amounting to at least 3,700 GWh per year, processes gas amounting to at least 5,190 GWh per year or handles mineral oil amounting to at least 420,000 tonnes per year. In the water sector, the threshold is 22 million cubic metres of drinking water per year or the connection of 500,000 population equivalents to wastewater disposal. In the health sector, hospitals are affected by 30,000 or more inpatient treatment cases per year, and manufacturers of prescription medicines by 4.65 million packs per year.
In the information technology and telecommunications sector, staggered thresholds apply for Internet nodes, DNS resolvers, trust service providers, data centres and cloud providers. For example, a data centre is affected with a contractually guaranteed output of 3.5 MW or more. In the financial sector, the threshold for payment transaction processing is 5.9 billion euros per year. In the transport sector, airports with more than 20 million passengers, seaports with more than 5.4 million tonnes handled and rail transport operators with defined passenger kilometers are affected. If you are unsure, you must carry out the threshold calculation in a documented manner, with data basis and reference date. A missing threshold value documentation is viewed as an independent deficiency in the audit. Audit-proof, documented, § 10 BSIG-proof. The CIVAC template for the threshold value check contains the current sector values and guides you through the calculation in a structured manner, including the asset definitions, the parallel NIS-2 classification and a template for the annual repeat check with the deadline, data source and signature of the responsible officer. A FAQ about this can be found at civac.de/faq.
Obligation to provide proof according to Section 8a Paragraph 3 BSIG: What you have to deliver every two years
The obligation to provide evidence according to Section 8a Paragraph 3 BSIG is the most operationally complex obligation in the KRITIS regime. Operators must prove to the BSI every two years that the technical and organisational measures required under Section 8a Paragraph 1 BSIG have actually been implemented. Proof can be provided through security audits, tests or certifications. In practice, most operators choose to test against an industry-specific security standard such as B3S in combination with ISO/IEC 27001 certification. The test report must be drawn up by an authorised testing body that is recognised by the BSI in accordance with Section 8a Paragraph 3 Sentence 2 BSIG.
The evidence includes at least four components. Firstly, a complete list of the implemented measures with reference to the ISO/IEC 27001:2022 controls and the industry-specific security standard. Secondly, a punch list with risk assessment and a binding remediation plan with responsibilities and deadlines. Thirdly, the test report from the body authorised to test with date, signature and scope. Fourth, the written statement from management on the list of defects and the remedial plan with a note of approval. Anyone who does not submit the proof or submits it too late risks a fine according to Section 14 BSIG and an order to correct defects within a short period of time, which, in the worst case, restricts operations. The CIVAC platform maintains the register of measures with reference to all 93 ISO/IEC 27001:2022 controls, documents the list of defects and the remedial plan in an audit-proof manner and provides the template for the management statement. The auditor calls, the evidence is ready., with a complete chain of evidence and dating of each individual measure over the full two-year period of the audit cycle, without subsequent reconstruction from email archives or distributed SharePoint folders. An overview of the platform services can be found at civac.de/facts.
Reporting requirements: 24 hours, 72 hours, one month
With the implementation of the NIS 2 directive, the reporting obligations for KRITIS operators will change fundamentally in 2026. Previously, there was a one-stage reporting requirement for significant security incidents in accordance with Section 8b BSIG without a fixed deadline. In the future, three staggered reports with clear deadlines will apply. Firstly, early warning within 24 hours of becoming aware of the incident. It includes an initial description, a preliminary risk assessment and, if necessary, the suspicion of a cross-border impact. Secondly, the incident report within 72 hours of knowledge, with an updated risk assessment, description of the indicators of compromise and the measures taken to date. Thirdly, the final report within one month of knowledge, with a detailed analysis of the incident, determination of the cause and measures taken.
The deadlines start from the time the incident is known, not from the internal escalation or confirmation by IT forensics. In practical terms, this means that the reporting path must be set up redundantly, with substitution arrangements and availability outside of business hours. Anyone who exceeds the 24-hour early warning by even two hours is documenting a breach of duty, which will be reflected in the audit and, in repeated cases, subject to sanctions. Deadline begins as soon as we become aware of it. The CIVAC platform provides the 24h/72h reporting path with its own timer, escalating notification to the information security officer and the board, ready-made reporting texts in German and a direct interface to the BSI reporting portal. The path is stored in the workspace with substitution regulations and is practiced at least once a year through a tabletop scenario, including honest measurement of the response times actually achieved on weekends and public holidays. Others run compliance like a filing cabinet. We run it like software. The role of the information security officer is the decisive one in this chain of duties, and its operational anchoring in day-to-day business is the only guarantee of passing the first serious BSI examination.
Personal liability of management
With the NIS2UmsuCG, the German legislator is for the first time drawing management's due diligence obligations in information security as narrowly as in financial accounting. Management must approve the security measures required under Section 8a BSIG, monitor their implementation and take part in regular training. If she violates these obligations and the company suffers damage as a result, she is personally liable to the company in accordance with the principles of the Business Judgment Rule and Section 43 GmbHG or Section 93 AktG. This is not a new basis for liability under civil law, but the reversal of the burden of proof and the express anchoring in the NIS2UmsuCG make lawsuits after incidents more likely.
In practical terms, this means that management must provide evidence of written approval of the catalogue of security measures, must regularly participate in training at least annually and must be listed as the addressee of the information in the incident reports. A mere delegation to the information security officer is not sufficient, as the supervisory responsibility remains with the board. The information security officer advises, the management decides. A documented reporting line with quarterly written reports to management and an archived approval of the catalogue of measures are the most effective protection against personal liability. The appointment certificate, signed, filed, verifiable. The CIVAC platform delivers the reporting templates, the training modules and the management approval workflow as standard, including the audit trail that enables proof of due diligence in the event of a dispute. This reduces management's personal liability risk to a reasonable level without slowing down operational security decisions. In addition, the platform provides templates for D&O insurance and reporting to the supervisory board in the depth expected under stock corporation and GmbH law, so that the governance side also remains documented and comprehensible to shareholders.
Sanctions and fine framework 2026
The sanction framework for KRITIS breaches of duty will increase significantly in 2026. Previously, Section 14 BSIG imposed fines of up to 100,000 euros, and in some cases up to 2 million euros for particularly serious violations. With the NIS2UmsuCG, the maximum rates for essential facilities increase to up to 10 million euros or two percent of global group sales, whichever is higher. For important institutions, the maximum rate is up to 7 million euros or one point four percent of global group sales. The fines can be imposed cumulatively for different breaches of duty, for example late reporting plus inadequate measures plus failed proof.
In addition to the fine, the BSI can issue orders to rectify defects within a short period of time in accordance with Section 8b BSIG; in extreme cases, the operation of a system can be ordered to be stopped or restricted if there is a significant risk to the security of supply. In the event of a disruption in supply that becomes public, reputational damage and civil claims for damages from affected customers can also occur. In most cases, the overall economic impact of a material breach of duty significantly exceeds the amount of the fine. Anyone who takes their obligations seriously protects the company, the management and the security of supply at the same time. CIVAC not only provides the tools for fulfilling obligations, but also the chain of evidence that can be verified at any time, which enables fines to be reduced or proceedings to be discontinued in the sanction process, for example if the operator can prove that a single breach of obligation was isolated and the other duties of care were fulfilled. The auditor calls, the evidence is ready. A more in-depth overview of sanctions can be found at civac.de/faq.
From reading to order: ISB order and workspace in two working days
CIVAC is a compliance platform and officer-as-a-service. For KRITIS operators, this means specifically: The platform provides the tools for fulfilling all six mandatory blocks, including the threshold documentation, the register of measures in accordance with Section 8a BSIG, the preparation of evidence in accordance with Section 8a Paragraph 3 BSIG, the 24h/72h reporting path in accordance with Section 8b BSIG and the report templates for management. The platform is ISO/IEC 27001:2022 certified, hosts exclusively in the European Union and includes thirty-seven ready-to-use audit templates. Officer orders are placed within two working days, compared to the traditional market which takes two to six weeks. The appointment certificate, signed, filed, verifiable.
The dual model gives you the choice. Licence the workspace for your internal representatives, or have our representatives order it. If you already have a qualified internal information security officer, he or she will take over the platform as an operational work environment with a register of measures, templates, reporting paths and reports. If you require an external order, our information security officers will take over the role within two working days, sign the appointment certificate with the management, register the company with the BSI as a contact point and immediately begin with the threshold documentation, the measure assessment and the first tabletop test of the reporting path. The majority of KRITIS operators in our portfolio combine both: internal security responsibility for ongoing operations, external officer function for regulatory reporting and proof requirements. Turn reading into an assignment. Write a short briefing email to info@civac.de or use the contact form on civac.de. You will receive a binding offer with named representative, licence scope, start date and implementation schedule for the four-week standard rollout within one working day.
FAQ
Does the BSI-KritisV 2026 also apply to parent companies without their own operations?
No. The BSI-KritisV addresses the operator of the system, i.e. the legal entity that actually operates the critical infrastructure. Group parent companies without their own operations are only affected if they themselves operate a system within the meaning of the BSI-KritisV. For corporations, the distribution of responsibilities must still be documented in a compliance matrix so that reporting obligations do not fail at group boundaries.
Is an ISO/IEC 27001 certification sufficient as proof according to Section 8a Paragraph 3 BSIG?
As a rule, ISO/IEC 27001 certification alone is not enough, as the BSI-KritisV has industry-specific security requirements that are regulated in the B3S. A combined test according to ISO/IEC 27001:2022 and the respective B3S of the industry is common. The body authorised to examine must be recognised by the BSI. CIVAC supports the preparation of the combined audit with the audit templates.
When does the 24-hour period for early warning to the BSI begin?
The 24-hour period begins when the operator's responsible body, usually the Security Operations Centre or the information security officer, becomes aware of the significant security incident. Deadline begins as soon as we become aware of it. It does not begin with internal escalation to management or confirmation through a forensic investigation. A documented initial reporting time is part of every incident documentation.
What role does management have in the KRITIS regime from 2026?
The management approves the security measures in accordance with Section 8a BSIG, monitors their implementation and regularly takes part in training courses. She is personally liable according to the principles of the business judgment rule if she violates these obligations and the company suffers damage as a result. Documented approval and regular training participation significantly reduce the personal liability risk and can be verified in the workspace.
How does KRITIS obligation differ from NIS 2 obligation?
KRITIS obligations apply to operators of critical infrastructures above the threshold values of the BSI-KritisV. NIS 2 obligations additionally apply to essential and important facilities below these thresholds, provided they belong to the NIS 2 sectors. Many KRITIS operators are also essential facilities under NIS-2 and must comply with both regimes in parallel. The lists of obligations overlap, but are not identical.
How quickly can CIVAC appoint an external information security officer for a KRITIS operator?
Two business days from signed briefing to active order. The CIVAC SLA of two working days also applies to KRITIS mandates. The appointment certificate, BSI registration and workspace setup run in parallel, so that the threshold documentation and the first measure assessment can begin in the same calendar week. Classic providers usually need two to six weeks to place a comparable order on the market.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.