The physical counterpart to the cyber branch of NIS2 and B3S
The German KRITIS umbrella act, transposing CER Directive (EU) 2022/2557, has applied since 16 March 2026. For the first time it requires operators of critical installations to address physical protection across all sectors: registration with the Federal Office of Civil Protection, a risk analysis under the all-hazards approach, a resilience plan with six statutory categories of measures, personnel security in sensitive positions and incident reports within 24 hours. The deadlines hang on your own registration, not on a national cut-off. The module keeps the file the way the act structures it, and is deliberately built as the counterpart to the cyber branch: the same installation can carry a NIS2 reporting chain and a KRITIS reporting chain, with different clocks.
The ten hazard categories under Section 11(2) are created in full as "still to be assessed" when the risk analysis is opened. Approval with open categories is refused. Whatever was not considered is visibly missing rather than silently absent.
2
A gap is not a decision
The six categories of measures under Section 13(3) are created in full per installation. A category without an entry is a gap. "Not applicable" with a justification is permissible, because Section 13(2) allows it, but it is a documented decision and not an empty field.
3
Two clocks, one incident
The initial report under Section 18 is due 24 hours after becoming aware, the detailed report one month after becoming aware, not one month after the initial report. That differs from DORA and NIS2, and a test pins it down. An incident can carry a NIS2 chain alongside.
4
Only the fact, never the certificate
For reliability checks in sensitive positions the module stores the occasion, scope, consent, result and validity. The content of a criminal record certificate is never stored, with Article 10 GDPR in view. Separate permissions keep personnel security apart from the rest of the module.
Capabilities
All capabilities at a glance
Register of critical installations with sector, critical service and level of supply
Supervisory file with the BBK: registration, file reference, contacts, versions and correspondence
The act’s seven obligations on two anchors: determination and registration
Registration three months after determination (Section 8(1)), change notification within two weeks
All-hazards risk analysis under Section 12: first nine months after registration, then every 48 months
Ten hazard categories under Section 11(2) and Article 13 CER, assessed in the risk register
Resilience measures in the six categories of Section 13(3), each with implementation evidence
Evidence linked from BCM, fire protection, physical access, occupational safety, training and the measures register
Resilience plan versioned and approved, resilience evidence as report and PDF
Sensitive positions with justification, type of access and check cycle (Section 13(3) no. 5, Article 14 CER)
Reliability checks with occasion, scope, consent, result and validity
Incident report under Section 18 to the joint BBK/BSI reporting office, with content per subsection 2
Equivalence under Section 17: which categories may be covered by evidence from other modules
Implementation status of the linked B3S scope in the evidence view
Read-only AI tools for installations and obligations
Result
A file that answers the BBK’s questions in the order the act asks them, without duplicating anything already held in the cyber branch.
Experience Critical infrastructure resilience live
Schedule a no-obligation demo – we will show you the module with your own use cases.