7 August 2026 Update - The transposition of the CER Directive in Germany
Germany completed the principal transposition of Directive (EU) 2022/2557 on the resilience of critical entities (CER Directive) through the KRITIS Dachgesetz (Critical Infrastructure Umbrella Act), which entered into force on 17 March 2026.
As of 7 August 2026, the emphasis has shifted from legislative transposition to identification and registration of critical entities, implementation of resilience risk assessments and resilience plans, operational compliance with the KRITIS Dachgesetz and its forthcoming implementing ordinance, supervisory coordination between the Federal Office of Civil Protection and Disaster Assistance (BBK) and the Federal Office for Information Security (BSI), and the integration of the physical resilience obligations established under the KRITIS Dachgesetz with the cybersecurity framework established under the NIS 2 Umsetzungs und Cybersicherheitsstärkungsgesetz and the BSI Act (BSIG).
7 August 2026 Update, more information about the Implementation of the Critical Entities Resilience (CER) Directive in Germany.
Germany has adopted one of the most comprehensive approaches within the European Union for the implementation of Directive (EU) 2022/2557 on the resilience of critical entities (CER Directive), as it incorporated CER into a broader restructuring of the national resilience architecture.
The implementation extends beyond the formal transposition of individual provisions of Union law, and reflects a deliberate legislative strategy aimed at integrating civil protection, critical infrastructure resilience, cybersecurity governance and continuity of essential services into a coordinated legal framework.
The CER Directive was transposed principally through the KRITIS-Dachgesetz. The Act entered into force on 17 March 2026. Earlier German legislation concentrated primarily on the protection of critical infrastructures from sector specific threats. The KRITIS Dachgesetz introduces a horizontal resilience framework applicable across numerous sectors providing essential services.
The legislation shifts the legal emphasis from protecting particular physical assets toward ensuring the continuity of essential societal and economic functions. This distinction is fundamental. The protected legal interest is the uninterrupted provision of essential services on which society depends.
The German implementation follows closely the architecture of the CER Directive, while adapting it to Germany's federal constitutional structure. The Act establishes procedures for the identification of critical entities, national risk assessment, resilience obligations, supervisory powers, inspections, enforcement mechanisms and cooperation between competent authorities. These provisions are intended to ensure that critical entities are capable not merely of preventing disruptions but also of resisting, responding to, recovering from and adapting to incidents affecting the continuity of their essential services.
One important characteristic of the German implementation is its close coordination with the NIS 2 implementation framework. The KRITIS Dachgesetz was enacted only a few months after the NIS 2 Umsetzungs und Cybersicherheitsstärkungsgesetz entered into force on 6 December 2025.
This coordinated legislative approach reflects an important conceptual development. The German legislature recognises that cybersecurity cannot be considered independently of the resilience of essential services. A cyber incident affecting an electricity transmission operator, for example, may rapidly develop into a disruption of energy supply, transportation, healthcare and telecommunications. Physical sabotage of a critical installation may generate significant cybersecurity consequences. The two legal frameworks regulate different aspects of the same operational environment.
The distinction between the two regimes remains legally important. The BSIG governs cybersecurity risk management, network and information system security, cyber incident reporting and cybersecurity supervision. The KRITIS Dachgesetz governs the resilience of critical entities against a broader spectrum of threats, including physical attacks, sabotage, terrorism, natural disasters, insider activity, supply chain disruption and other events capable of interrupting essential services. Compliance with one framework does not automatically establish compliance with the other, although many organizational measures may satisfy obligations arising under both statutes.
The implementation of the CER Directive also significantly alters the legal obligations of operators of essential services. Under the previous German critical infrastructure framework, emphasis frequently rested upon infrastructure protection and sector specific security requirements. The KRITIS Dachgesetz requires designated critical entities to undertake comprehensive resilience risk assessments addressing all relevant threats capable of impairing the provision of essential services. These assessments must not be confined to technical or physical security but should evaluate organizational, operational, geographical, supply-chain and interdependency risks.
This broader conception of resilience is particularly evident in the treatment of business continuity. The legislation does not assume that resilience can be achieved through protective measures. Organizations are expected to develop the capability to maintain essential functions during adverse events and to restore disrupted services within appropriate timeframes. Resilience planning becomes an integral legal obligation rather than a voluntary management practice.
The Act further requires critical entities to adopt resilience measures proportionate to the risks identified in their assessments. Although the precise content of these measures necessarily varies according to the sector and operational environment, the legal obligation is functional rather than prescriptive. The legislation establishes the required outcome (the resilience of the essential service) while leaving regulated entities an appropriate degree of discretion regarding the technical and organizational means used to achieve that objective. This reflects the principle of proportionality embodied in both the CER Directive and German administrative law.
Responsibility for resilience is no longer an operational or technical matter. The statutory framework requires resilience to become an element of corporate governance and strategic oversight. Management bodies are expected to ensure that appropriate resilience measures are established, maintained and periodically reviewed. Although the CER legislation does not replicate every management liability provision contained in the BSIG, it nevertheless reinforces the expectation that resilience should be addressed at the highest levels of organizational decision making.
The German framework also places considerable emphasis on national risk assessment. Competent authorities are required to identify risks capable of affecting the provision of essential services, taking into account natural hazards, accidents, public health emergencies, malicious acts and hybrid threats. These assessments provide the basis for identifying critical entities and determining the resilience measures required within individual sectors. The process therefore operates as a continuous regulatory mechanism rather than a one-time legislative exercise.
The implementation reflects the broader evolution of European resilience law. Earlier regulatory approaches frequently treated cybersecurity, physical protection, emergency planning and business continuity as separate legal disciplines. The combined implementation of the CER Directive and the NIS 2 Directive demonstrates an emerging recognition that resilience must be assessed across the entire operational environment. Essential services increasingly depend upon interconnected technological, physical, organizational and societal systems. Resilience has become a multidisciplinary legal objective, not a purely technical compliance requirement.
12 March 2026 Update - The transposition of the CER Directive in Germany
Germany did not transpose the Directive on time. The European Commission initiated infringement procedures against Germany for failing to notify transposition measures by October 2024.
The delay occurred primarily because Germany decided to implement the Directive through a large cross sector framework law (KRITIS-Dachgesetz) instead of simple amendments. This required redefining critical infrastructure operators, coordinating with the NIS 2 Directive implementation, resolving federal Länder competence issues, and designing a new resilience governance structure. These are major developments, so the legislative process took significantly longer than the Directive’s timetable allowed.
The transposition of Directive (EU) 2022/2557 on the resilience of critical entities into German law must be understood as a structurally ambitious legislative process that, as of March 2026, had advanced to the final stage of national lawmaking.
The principal German implementing measure, the Gesetz zur Umsetzung der Richtlinie (EU) 2022/2557 und zur Stärkung der Resilienz kritischer Anlagen, commonly referred to as the KRITIS-Dachgesetz, was passed by the Bundestag on 29 January 2026. The Bundesrat approved it on 6 March 2026.
The German approach is notable for its decision to transpose the CER Directive through a new horizontal framework statute. The Government bill expressly presented the KRITIS-Dachgesetz as the instrument by which Directive (EU) 2022/2557 would be implemented in national law, and the Bundestag’s own legislative materials repeated that the bill was designed to transpose the CER Directive into German law. The explanatory memorandum describes the statute as the first federal cross sector framework laying down uniform minimum requirements for physical resilience measures for critical installations, while preserving coherence with the already existing and expanding body of cyber-regulation in the BSI-Gesetz and the NIS2 implementation process.
In the German transposition, there is a deliberate differentiation between physical or operational resilience, on the one hand, and cybersecurity, on the other. The explanatory memorandum to the draft law states in terms that the protection of IT security of critical infrastructure was already embedded in the BSI legal framework, where the KRITIS-Dachgesetz would stand alongside those rules and address resilience from an “all-hazards” perspective in relation to non-IT-based measures.
In doctrinal terms, this is highly relevant. It means that the German legislature conceived the CER Directive as requiring a separate normative layer dealing with physical protection, continuity capability, organizational preparedness, and crisis resilience. This design was intended for coherence with the NIS 2 regime by using shared concepts, coordinated identification mechanisms, and, as far as feasible, common registration and reporting structures.
The statute reveals a distinctly German technique of implementation, as it combines a framework law with significant delegated norm making. The bill provides for a national KRITIS resilience strategy, statutory rules on the identification of operators of critical installations, registration obligations, national risk analyses and risk assessments, incident reporting, and resilience duties. At the same time, it envisages a substantial role for secondary legislation and branch specific standards.
The explanatory memorandum states that the law would establish statutory resilience objectives and provide examples of measures that operators may adopt, while a subsequent Rechtsverordnung would concretize the circle of addressees and the applicable criteria. It also contemplates the development and recognition of branchenspezifische Resilienzstandards. This shows that Germany opted for a layered model in which Parliament establishes the core legal framework and the executive later specifies identification criteria and certain substantive details.
A central legal feature of the German framework is the identification of “Betreiber kritischer Anlagen” (instead of a literal reproduction of the Union term “critical entities.”) This choice should not be misunderstood as a departure from the Directive’s substance. It reflects Germany’s attempt to put the CER framework onto its existing KRITIS vocabulary and administrative practice.
The Bundestag materials state that the law lays down rules for identifying operators of critical installations and “critical entities of particular European significance,” and it also provides for registration obligations for operators of critical installations. The Government’s public explanation after Bundesrat approval adds that the law defines nationwide which companies and institutions are part of critical infrastructure, using a threshold criterion according to which the installation must be essential for overall supply in Germany and serve more than 500,000 persons.
The threshold structure of the German law is important. According to the Government’s official account after Bundesrat approval, an installation falls within the federal framework if it is essential for the overall supply of Germany and serves more than 500,000 persons. That criterion was controversial in the legislative process. The Bundestag materials record that the Bundesrat criticized the threshold as too high and advocated a lower threshold of 150,000 persons, arguing that many operators supplying a majority of the population would otherwise remain below the statutory cut-off. The final parliamentary compromise preserved the possibility for the Länder to identify additional critical installations in sectors falling solely within their competence, with the criteria and procedure to be specified by regulation subject to Bundesrat consent. Legally, this solution is noteworthy because it combines federal standardization with a subsidiary space for Länder specific expansion. It seeks to reconcile the Directive’s demand for a coherent national framework with Germany’s federal structure.
The substantive obligations imposed on operators under the German model are broad and unmistakably reflect the Directive’s resilience logic. The Bundestag and Government materials state that the KRITIS-Dachgesetz establishes national risk analyses and risk assessments for critical services, codifies essential national requirements for resilience measures, and introduces a reporting system for incidents.
The explanatory memorandum further indicates that operators must designate a contact point and report significant disturbances via a digital platform jointly operated by the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe and the Bundesamt für Sicherheit in der Informationstechnik. It emphasizes that the law follows an all hazards, risk based approach and aims to impose concrete obligations for maintaining, strengthening, or restoring the operational capability and resilience of operators.
In doctrinal terms, this is the decisive transition from a predominantly protective model to a resilience model. Operators are not merely expected to cooperate with state security authorities. They are placed under a statutory duty to organize their own resilience through risk analysis, resilience planning, and incident governance.
The German legislative materials further show that the law is designed to operate within an interlocking administrative system involving both civil protection and cyber authorities. The explanatory memorandum stresses coordinated interfaces between the BBK and the BSI and seeks to reduce administrative burdens on operators by pursuing common technical solutions for registration and incident reporting.
This is legally significant because the CER Directive does not exist in isolation. In the German context, its implementation is being structurally aligned with the parallel development of NIS 2 related cybersecurity law.
According to the Government’s official summary after Bundesrat approval, the statute brings together sectors including energy, transport and traffic, finance and insurance, health, drinking water, wastewater, municipal waste disposal, information technology and telecommunications, food, space, and public administration. That breadth is important because it demonstrates that Germany is implementing the expanded multi sector approach required by the CER Directive and embedding it in a domestic KRITIS system that is intended to capture a much wider range of essential services and their interdependencies.
As of 14 March 2026, Germany’s implementation of the CER Directive is delayed but systemically serious transposition centered on the KRITIS-Dachgesetz. The German legislature has chosen to create a sector overarching statutory framework for physical and organizational resilience, closely coordinated with cyber regulation, federal in structure yet open to Länder supplementation, and dependent on subsequent regulations and recognized sectoral standards. The central legal question for Germany after March 2026 is how quickly the final formal steps, the subordinate legislation, and the administrative designation and supervisory machinery will mature into a fully operational resilience regime that gives complete and effective domestic effect to Directive (EU) 2022/2557.