BSI-KritisV

BSI Criticality Regulation

BSI-Kritisverordnung

The BSI Criticality Regulation (BSI-KritisV) specifies which facilities in Germany count as critical infrastructure (KRITIS). For this it defines, per sector, facility categories and thresholds — the regular benchmark being the supply of around 500,000 people. Whoever exceeds a threshold is subject to special duties towards the BSI.

History & facts. The BSI-KritisV (originally from 2016, on the basis of the BSI Act) determines KRITIS by sectors, critical services, facility categories and specific thresholds. Operators must identify themselves: a check is made annually as of 31 March; if a threshold was exceeded in the previous year, the facility counts as critical from 1 April and must be registered with the BSI. With the NIS2 implementation (amended BSI Act, in force since 6 December 2025) the regulation was adjusted; the KRITIS sectors are now defined in Section 2 of the BSI Act and detailed per sector in the regulation. Outlook & recommendation. The regulatory structure is in transition: the KRITIS umbrella act (implementation of the EU CER directive, physical resilience) came into force in 2026, and a draft of a new KRITIS regulation was open for comment in spring 2026 — upon its entry into force the existing BSI-KritisV is to be replaced. For operators this means: the threshold logic remains at its core, but the exact categories and responsibilities (BSI for IT security, BBK for physical protection) are in flux. A careful, documented self-assessment — ideally accompanied — is strongly recommended. This is not legal advice; what is authoritative is the respective regulation in force.
BSI-KritisV — BSI Criticality Regulation