Connected critical infrastructure, IT and OT security, and resilience monitoring

BSIG / NIS2 / KRITIS Umbrella Act

KRITIS, NIS2 and the New BSI Act: What Companies Should Review Now

Germany has substantially developed its requirements for cybersecurity and operational resilience. The new BSI Act (BSIG) has applied since 6 December 2025 and implements key requirements of the European NIS2 Directive. The KRITIS Umbrella Act entered into force on 17 March 2026 and complements cybersecurity obligations with requirements for the physical resilience of critical facilities.

Important: Not every organisation covered by NIS2 or the BSIG is also an operator of a critical facility. The BSIG distinguishes in particular between essential entities, important entities and operators of critical facilities. The applicable category depends on the activity, type of entity, company size and, where relevant, facility-specific thresholds.

Are you in scope?

A robust scoping assessment should address at least the following questions:

  • Does your organisation fall within a type of entity listed in Annex 1 or Annex 2 of the BSIG?
  • Are the relevant size criteria met, or do special statutory inclusion rules apply?
  • Do you operate facilities that qualify as critical facilities because of their importance and the applicable thresholds?
  • Do overriding sector-specific regimes apply, such as DORA for certain financial entities or specific requirements for energy and telecommunications?

Core obligations under the BSIG

For essential and important entities, the BSIG includes requirements relating to risk management, registration, reporting of significant incidents, and management responsibility and training. Risk-management measures address areas such as risk analysis, incident handling, business continuity, supply-chain security, vulnerability management, effectiveness testing, cryptography, access control and multi-factor authentication.

Significant incidents are subject to staged reporting: generally an early warning within 24 hours, a more detailed incident notification within 72 hours and a final report no later than one month after the 72-hour notification. The statutory conditions and the reporting channel provided by the BSI must be observed.

Additional requirements apply to operators of critical facilities. Under section 39 BSIG, implementation of the relevant measures must generally be evidenced for the first time or again no later than after three years and subsequently every three years through security audits, inspections or certifications. Transitional and special provisions must be considered in each case.

Physical resilience under the KRITIS Umbrella Act

The KRITIS Umbrella Act also addresses risks that are not exclusively digital, including natural hazards, sabotage, unauthorised access, personnel dependencies and disruption of essential utilities. Operators in scope must coordinate their cybersecurity and resilience governance. The precise application of individual obligations may also depend on implementing regulations, official determinations and transitional provisions.

How we support you

Risk analysis and business continuity planning for interdependent critical infrastructure

Collegium Auditores provides risk-based and practical support with:

  • scope and classification assessments under the BSIG, NIS2, the KRITIS Umbrella Act and DORA;
  • gap analyses against statutory and regulatory requirements;
  • development of information-security, business-continuity and supply-chain processes;
  • preparation for and support during evidence reviews under section 39 BSIG;
  • assessment of control effectiveness and follow-up of identified deficiencies; and
  • training and awareness for management, specialist functions and internal auditors.

From scoping assessment to audit readiness

We combine experience in IT audit, internal audit, information security, data protection and governance. Depending on the engagement, we involve suitable specialists from our professional network. The objective is a traceable, proportionate and auditable implementation aligned with your organisation.

Contact: office(at)collegium-auditores.de

Legal status: 13 August 2026. The specific scope and any applicable transitional or sector-specific rules must be assessed on a case-by-case basis.