ISMS & Risk

Critical infrastructure resilience

The physical counterpart to the cyber branch of NIS2 and B3S

The German KRITIS umbrella act, transposing CER Directive (EU) 2022/2557, has applied since 16 March 2026. For the first time it requires operators of critical installations to address physical protection across all sectors: registration with the Federal Office of Civil Protection, a risk analysis under the all-hazards approach, a resilience plan with six statutory categories of measures, personnel security in sensitive positions and incident reports within 24 hours. The deadlines hang on your own registration, not on a national cut-off. The module keeps the file the way the act structures it, and is deliberately built as the counterpart to the cyber branch: the same installation can carry a NIS2 reporting chain and a KRITIS reporting chain, with different clocks.

KRITIS-DachgesetzCER-Richtlinie (EU) 2022/2557BSIGB3S
Features

Your benefits

1

The all-hazards approach is demonstrably complete

The ten hazard categories under Section 11(2) are created in full as "still to be assessed" when the risk analysis is opened. Approval with open categories is refused. Whatever was not considered is visibly missing rather than silently absent.

2

A gap is not a decision

The six categories of measures under Section 13(3) are created in full per installation. A category without an entry is a gap. "Not applicable" with a justification is permissible, because Section 13(2) allows it, but it is a documented decision and not an empty field.

3

Two clocks, one incident

The initial report under Section 18 is due 24 hours after becoming aware, the detailed report one month after becoming aware, not one month after the initial report. That differs from DORA and NIS2, and a test pins it down. An incident can carry a NIS2 chain alongside.

4

Only the fact, never the certificate

For reliability checks in sensitive positions the module stores the occasion, scope, consent, result and validity. The content of a criminal record certificate is never stored, with Article 10 GDPR in view. Separate permissions keep personnel security apart from the rest of the module.

Capabilities

All capabilities at a glance

  • Register of critical installations with sector, critical service and level of supply
  • Supervisory file with the BBK: registration, file reference, contacts, versions and correspondence
  • The act’s seven obligations on two anchors: determination and registration
  • Registration three months after determination (Section 8(1)), change notification within two weeks
  • All-hazards risk analysis under Section 12: first nine months after registration, then every 48 months
  • Ten hazard categories under Section 11(2) and Article 13 CER, assessed in the risk register
  • Resilience measures in the six categories of Section 13(3), each with implementation evidence
  • Evidence linked from BCM, fire protection, physical access, occupational safety, training and the measures register
  • Resilience plan versioned and approved, resilience evidence as report and PDF
  • Sensitive positions with justification, type of access and check cycle (Section 13(3) no. 5, Article 14 CER)
  • Reliability checks with occasion, scope, consent, result and validity
  • Incident report under Section 18 to the joint BBK/BSI reporting office, with content per subsection 2
  • Equivalence under Section 17: which categories may be covered by evidence from other modules
  • Implementation status of the linked B3S scope in the evidence view
  • Read-only AI tools for installations and obligations
Result

A file that answers the BBK’s questions in the order the act asks them, without duplicating anything already held in the cyber branch.

Experience Critical infrastructure resilience live

Schedule a no-obligation demo – we will show you the module with your own use cases.