One incident, two clocks
Since March an operator of critical installations has two supervisory files: one for cybersecurity with the BSI and one for physical protection with the BBK. Both demand reports within 24 hours. After that they count differently, and whoever runs both off one calendar entry misses one.
Say NIS2 and you mean cybersecurity: the reporting regime of Section 32 BSIG, registration with the BSI, evidence under Section 39. Since 16 March 2026 there has been the second act. The German KRITIS umbrella act transposes the CER Directive and requires operators of critical installations to address physical protection: against fire, flooding, sabotage, loss of supply. The competent authority is not the BSI but the Federal Office of Civil Protection and Disaster Assistance, the BBK.
Whoever falls under both keeps two files. And the place where that goes wrong is not the registration. It is the incident.
What the umbrella act requires
The obligations hang not on a national cut-off but on your own registration; an entry on that has been in the compliance calendar since 10 September. Registration is due at the latest three months after an installation qualifies as critical (Section 8(1)). The risk analysis under Section 12 is first due nine months after registration, the resilience plan and reporting under Sections 13 and 18 ten months after (Section 8(7)).
The risk analysis follows the all-hazards approach, ten hazard categories under Section 11(2). The resilience plan has six categories of measures under Section 13(3). "Not applicable" is permissible under subsection 2, but with a justification: an empty category is not a decision but a gap.
The incident that triggers both chains
A fire in a utility's equipment room. The control room goes down, and so does the remote control technology. That is a disruption of the critical service, reportable under Section 18 of the umbrella act to the joint reporting office of the BBK and the BSI. It is at the same time a significant security incident under Section 32 BSIG, reportable to the BSI. Two chains, two addressees, one event.
Both begin the same way: a first report within 24 hours of becoming aware. After that they part, at a point that is easy to read past.
From awareness, from notification
Section 32 BSIG requires, after the early warning, a notification within 72 hours and a final report "no later than one month after transmission of the notification under number 2". The one-month period therefore runs from the 72-hour notification.
Section 18(1) of the umbrella act requires the initial report no later than 24 hours after becoming aware and the detailed report "no later than one month after becoming aware of the incident". The one-month period runs from awareness.
For an incident that becomes known on day one, the KRITIS report is therefore due up to three days earlier than the NIS2 final report. Whoever derives both deadlines from one calendar entry gets one of them wrong. And because DORA counts at the same point as NIS2, from the notification, the umbrella act's rule is the exception you have to know.
In our module the one-month period therefore hangs on the anchor "awareness", and a test pins that down, so nobody aligns the anchor with DORA at the next rebuild.
What does not have to be kept twice
A second file does not mean second work. Section 17 of the umbrella act expressly allows parts of the evidence under Section 39 BSIG to be used towards the BBK as well. An emergency plan from BCM, a fire safety inspection, an access rule, a training course: those are pieces of evidence that belong in both files and should exist only once.
The module therefore links the six categories to what already exists in BCM, fire protection, physical access, occupational safety and training, and shows which category may be covered by it. The view decides nothing. It shows where you do not have to start from scratch.
Two questions to ask
Which of your installations does the umbrella act cover, and has registration with the BBK been done? Three months from determination have, since March, already passed for many.
And: who in your organisation knows that a fire triggers a 24-hour report, not only a ransomware incident? The reporting chain for the cyber branch usually has a name. The one for the physical branch usually does not yet.
More on the critical infrastructure resilience module page. The cyber branch with its three stages is described on the NIS2 reporting page.
Sources
German KRITIS umbrella act, Sections 8, 11, 12, 13, 17 and 18, at Gesetze im Internet. Section 32 BSIG (reporting obligations), also there. CER Directive (EU) 2022/2557, Articles 13 and 14. Quotations translated from the German.
Questions about this update?
Talk to us – we are happy to show you this feature in a demo.