AI Guide

KRITIS (Critical Infrastructure): Germany's designation for essential operators

KRITIS is Germany's regulatory designation, under the BSI-Gesetz and the KRITIS-Dachgesetz, for operators of critical infrastructure such as energy, water, health, finance, IT/telecom, transport, and food supply. KRITIS operators face heightened IT-security obligations, mandatory BSI incident reporting, and now physical resilience duties alongside the EU's NIS2 directive. Learn below what qualifies a company as a KRITIS operator, how it relates to NIS2 and BSI IT-Grundschutz, and what it means in practice for German Mittelstand companies.

Key Facts
  • KRITIS is the German legal designation for critical infrastructure operators under the BSI-Gesetz
  • The KRITIS-Dachgesetz has been in force since March 17, 2026, adding physical resilience duties
  • The BSI-KritisV sets a regular threshold of 500,000 supplied persons across ten sectors
  • As of mid-2026 the BSI had registered 1,231 KRITIS operators with 2,180 facilities
  • AI systems used as safety components in critical infrastructure are high-risk under the EU AI Act

Definition: KRITIS (Critical Infrastructure)

KRITIS is the German legal designation, defined in the BSI-Gesetz and specified by the BSI-KritisV regulation, for organizations operating infrastructure whose failure would cause sustained supply shortages or significant public safety disruption.

Core characteristics of KRITIS

A company becomes a KRITIS operator once it crosses a sector-specific supply threshold, not because of its industry label. Designation brings binding BSI obligations, not voluntary best practice.

  • Ten regulated sectors: energy, water, food, IT/telecom, health, finance, transport, media/culture, state/administration, waste
  • Regular threshold of 500,000 supplied persons
  • Mandatory registration with the BSI’s reporting portal
  • Continuous, state-of-the-art IT-security measures

KRITIS vs. NIS2

NIS2 is the EU-level cybersecurity directive every member state must transpose into national law. KRITIS is Germany’s own, older designation, now nested inside the broader NIS2 framework: a KRITIS operator automatically counts as an “especially important facility” under Germany’s transposition, layering governance duties on top of the older KRITIS rules.

Importance of KRITIS in enterprise AI

KRITIS status shapes how a company may deploy AI. Under the EU AI Act, AI systems used as safety components in energy, water, or gas supply are classified as high-risk AI systems, triggering conformity assessment and human oversight before deployment. Bitkom’s Wirtschaftsschutz 2025 study found companies attributing attacks to foreign intelligence services rose from 7% to 28% between 2023 and 2025, with energy suppliers a primary target.

Methods and procedures for KRITIS

Determining and maintaining KRITIS status follows a defined compliance sequence.

Threshold self-assessment

Every company in a regulated sector must periodically check supply volumes against the BSI-KritisV thresholds, before the BSI makes contact.

  • Calculate supplied persons or comparable metrics annually
  • Compare results against the applicable threshold
  • Document the assessment for audit purposes

BSI IT-Grundschutz implementation

Once designated, operators must run an information security management system aligned with BSI IT-Grundschutz, the control catalog KRITIS audits measure against.

Incident reporting under Section 32 BSIG

Section 32 BSIG obliges operators to report significant IT-security incidents to the BSI without undue delay, via an initial report, an update, and a final report through the Melde- und Informationsportal (MIP).

Important KPIs for KRITIS

Operators track compliance and resilience metrics to demonstrate ongoing readiness.

Operational compliance metrics

  • Incident report submitted within 24 hours: target 100%
  • Audit findings closed within agreed deadlines: target >95%
  • Systems covered by IT-Grundschutz baseline: target 100%
  • Business continuity plans tested annually: target 100%

Strategic resilience metrics

Beyond compliance checkboxes, operators are measured on resilience outcomes. The BSI reported 1,231 registered KRITIS operators with 2,180 facilities as of June 30, 2026, showing the scale now under active supervision since the KRITIS-Dachgesetz took effect.

Quality and audit metrics

Mature programs track evidence completeness for the two-year audit cycle and the time needed to close control gaps.

Risk factors and controls for KRITIS

KRITIS operators face risks beyond generic IT security.

Regulatory and liability exposure

Missing a registration deadline or an incident report carries direct regulatory consequences and personal management liability risk.

  • Fines for non-compliance with registration or reporting duties
  • Personal liability for managing directors under Section 38 BSIG
  • Reputational damage from public disclosure

Supply chain and third-party risk

Operators depend on vendors, cloud providers, and AI integrators who are not themselves regulated but whose failures propagate into the supply chain. Contractual requirements and vendor audits are now standard controls.

Physical resilience gaps

The KRITIS-Dachgesetz added binding duties for physical protection, crisis management, and personnel security that many operators previously treated as informal practice.

Practical example

A 260-employee regional water utility in Lower Saxony found during a routine review that its supply volume had crossed the BSI-KritisV threshold, making KRITIS registration mandatory. It had already automated meter-reading anomaly detection with an AI system but never assessed it against EU AI Act high-risk criteria. With an external compliance partner, it registered with the BSI, mapped the AI system as a safety-relevant component, and built a reporting workflow into its operations software.

  • Automated evidence collection for the biennial IT-Grundschutz audit
  • A structured 24/72-hour incident escalation workflow with clear ownership
  • A registered AI system inventory covering the anomaly detection model
  • Quarterly management reporting on KRITIS and NIS2 obligations

Current developments and effects

Germany’s KRITIS regime has expanded significantly since early 2026.

Sector expansion and physical resilience

The KRITIS-Dachgesetz, in force since March 17, 2026, added waste management as a tenth sector and made physical resilience a binding operator duty.

  • New requirement for documented crisis management plans
  • Personnel security screening for critical roles
  • Coordination duties with regional civil protection authorities

Convergence with the Cyber Resilience Act

Hardware and software sold into KRITIS environments increasingly need to satisfy the EU Cyber Resilience Act’s security-by-design requirements before operators can procure them. Finance-sector KRITIS operators additionally face DORA, which sets parallel ICT resilience duties for banks and insurers.

Rising attack pressure

Gartner forecasts worldwide information security spending will reach $244.2 billion in 2026, a 13.3% increase, with critical infrastructure among the sectors driving the fastest growth as geopolitical targeting intensifies.

Conclusion

KRITIS designation turns critical infrastructure operation into a continuously audited legal obligation, not a reputational label. As the KRITIS-Dachgesetz and NIS2 stack duties on the original BSI-Gesetz framework, the compliance burden for qualifying Mittelstand companies keeps growing. Understanding whether a company crosses the relevant thresholds is now a prerequisite for any AI deployment touching supply-critical processes. Companies that build compliance into their operating rhythm early avoid scrambling at the next audit cycle.

Frequently Asked Questions

What makes a company a KRITIS operator?

A company qualifies once its supply volume in a regulated sector, such as energy, water, or health, exceeds the BSI-KritisV threshold, most commonly 500,000 supplied persons. Designation rests on measurable supply data, not company size.

How does KRITIS relate to NIS2?

NIS2 sets a cybersecurity baseline across the EU, while KRITIS is Germany’s stricter, pre-existing designation for the highest-criticality operators. Under Germany’s transposition, KRITIS operators count as especially important facilities, so both obligations apply together.

Does KRITIS status apply to smaller Mittelstand companies?

Yes, if supply volumes cross the threshold. A regional water utility or hospital group with a few hundred employees can qualify just as easily as a national provider, since thresholds rest on people supplied, not headcount.

What does KRITIS mean for AI systems we deploy?

An AI system used as a safety component in energy or water supply is classified as high-risk under the EU AI Act, requiring conformity assessment and documented human oversight before go-live.

Do we need our own IT security team to become KRITIS-compliant?

Not necessarily. Many Mittelstand operators work with external partners to implement BSI IT-Grundschutz and manage the audit cycle, while keeping internal ownership of risk assessment and reporting.

What happens if a KRITIS operator misses an incident report deadline?

Missing the Section 32 BSIG deadlines can trigger fines and, under the newer rules, personal liability for managing directors. Operators typically automate monitoring and escalation to avoid missing the initial notification window.

Building better software Contact us together