Blog
NIS2 and the German KRITIS umbrella act: what companies in critical-infrastructure sectors need to implement now
Two central pieces of regulation for critical infrastructure have been in force in Germany since early 2026 - and apply in parallel for affected operators: the NIS2 Implementation Act and the KRITIS Umbrella Act (KRITIS-Dachgesetz). Here’s where things stand and what it means technically.
NIS2 Implementation Act: cybersecurity for more than 30,000 companies
The act was published in the Federal Law Gazette on 5 December 2025 and has been in force ever since; the BSI registration deadline for affected entities expired on 6 March 2026. It affects companies across 18 regulated sectors with at least 50 employees or more than €10 million in annual revenue - an estimated 30,000-plus companies in Germany.
KRITIS Umbrella Act: physical resilience as the second pillar
The Bundestag passed the KRITIS-Dachgesetz on 29 January 2026; it has been in force since 17 March 2026. Where NIS2 governs cybersecurity, the umbrella act implements the EU CER Directive and addresses physical resilience: protection against natural hazards, sabotage and hybrid threats. For KRITIS operators, both regimes apply side by side.
What this means technically
- Risk management: documented processes for identifying and assessing cyber and physical risks
- Reporting obligations: initial notification of significant security incidents to the BSI within 24 hours
- Redundancy and high availability: resilience for systems relevant to service delivery, typically through clustering and replication
- Access controls: identity and access management following least-privilege principles, multi-factor authentication
- Supply-chain security: assessment of suppliers and the hardware and software in use
Where Contensi comes in
Most of these requirements aren’t software you buy - they’re an architecture you build: highly available clusters instead of single points of failure, monitoring and incident management following clear processes, identity and access concepts that hold up under audit. That’s exactly what our Managed Services already cover with their "Security & Compliance" building block - NIS2 and the KRITIS-Dachgesetz now turn that into a legal obligation for affected companies rather than a nice to have.
Sources: OpenKRITIS (2026), German Bundestag – KRITIS-Dachgesetz documentation (2026), Kleeberg "NIS-2 und KRITIS-Dachgesetz" (2026).
Next step
Questions about this topic?
We’ll help you assess what’s relevant for your environment – no sales pitch.
Book an initial consultation