The EU Critical Infrastructure Directive extends the protection of critical infrastructure to include physical and organisational resilience across 11 sectors. Germany is implementing it through the KRITIS Framework Act (in force since 17 March 2026) – operators must be designated by 17 July 2026 and should act promptly in view of the tight deadlines and the need to align with NIS2.
Global crises, acts of sabotage and natural disasters highlight just how vulnerable Europe’s supply infrastructure is. Whilst NIS-2 places a strong emphasis on cyber security, the European Union has also taken steps to address physical and operational resilience.
The European Directive on the Resilience of Critical Entities ((EU) 2022/2557) came into force on 16 January 2023. This ‘CER Directive’ significantly broadens the legal scope: In addition to IT protection, the physical, organisational and personnel resilience of operators of essential services takes centre stage. Whilst the formal deadline for transposition into national law expired on 17 October 2024, the process of identifying critical entities has been extended until mid-2026. However, implementation in the Member States also presents its own challenges.
The CER Directive came into force on 16 January 2023 and replaces the previous European ECI Directive from 2008. Whilst the previous regulation covered only the energy and transport sectors, the new directive drastically expands its scope to 11 critical sectors:
1. Energy
2. Transport
3. Banking
4. Financial market infrastructures
5. Health
6. Drinking water
7. Wastewater
8. Digital infrastructure
9. Public administration
10. Space
11. Food (production, processing, distribution)
The EU CER Directive covers 11 sectors, as it newly incorporates areas such as space and public administration, and lists drinking water and wastewater as two separate sectors, whereas the previous German KRITIS regulation was based on 10 traditionally defined sectors
The CER Directive adopts an ‘all-hazards’ approach. This means that operators must analyse risks of all kinds – from natural disasters, sabotage and terrorism to insider threats or pandemics – and take precautionary measures.
In this respect, the CER Directive forms the physical counterpart to the cyber-focused NIS2 Directive:
NIS2 regulates IT and information security.
CER governs physical, organisational and personnel resilience.
An important knock-on effect is that once a company has been classified by Member States as a ‘critical facility’ under CER, it is automatically regarded as an ‘essential facility’ under NIS2.
Although the European deadline for Member States to transpose the legislation expired on 17 October 2024, the pace of national implementation has been extremely uneven. The European Commission has already launched infringement proceedings against defaulting Member States due to late notification of transposition measures.
Germany as a pioneer: The KRITIS umbrella law
Germany has transposed the Directive through the comprehensive KRITIS umbrella law, which came into force on 17 March 2026.
Shift in focus: German law is undergoing a transition from the mere protection of physical infrastructure to ensuring the continuous provision of essential services to society.
Threshold: The legislation applies to facilities that are essential to the overall supply of services and serve more than 500,000 people.
Regulatory structure: Supervisory responsibility is divided between the Federal Office for Civil Protection and Disaster Assistance (BBK) for physical resilience and the Federal Office for Information Security (BSI) for cyber security.
By 17 July 2026, all EU Member States must determine, on the basis of national risk analyses, which specific organisations are to be designated as ‘critical infrastructure’. Following formal notification, the organisations concerned will have just 10 months to fully comply with the extensive resilience obligations.
The creation of a uniform European resilience framework faces several hurdles:
Overlaps and duplication of regulation (NIS2 vs. CER): Organisations must closely coordinate physical security strategies (e.g. BBK) and IT security requirements (e.g. BSI), which leads to additional organisational burdens.
Inconsistent criteria and thresholds: As the CER is a directive, Member States apply different thresholds or self-assessment procedures (such as Germany, with a threshold of 500,000 people served, or specific national regulations).
Cross-border interdependencies: Critical infrastructure does not stop at national borders. Where supply chains or energy and transport networks span several EU countries, differing national requirements create complexity for multinational corporations.
Tight implementation deadlines for companies: Following designation, operators must, within 9 to 10 months, carry out risk analyses (to be renewed every four years), draw up resilience plans, establish incident reporting procedures (24-hour initial reporting) and implement security vetting of staff.
Compliance with the CER and KRITISDachG requirements demands that operators implement specific technical, structural and organisational protective measures for day-to-day operations. As the control room forms the nerve centre of any critical facility, the physical resilience, ergonomics and reliability of control rooms play a key role.
Send us a non-binding inquiry
We’re here for you!
Whether you need individual solutions, technical advice or a personal consultation – we’re happy to help. Just fill out the contact form and our team will get in touch with you as soon as possible.
We look forward to your message!
Knürr GmbH Headquarters
Mariakirchener Straße 38, 94424 Arnstorf
Get in touch now!
In cooperation with our local partner, we ensure that your enquiry is processed quickly and personally.
Get in touch now!
In cooperation with our local partner, we ensure that your enquiry is processed quickly and personally.
Get in touch now!
In cooperation with our local partner, we ensure that your enquiry is processed quickly and personally.
Get in touch now!
In cooperation with our local partner, we ensure that your enquiry is processed quickly and personally.
Knürr France
Romain Fayol (+33 671 030 194)
Gilles Chevreux (+33 662 94 15 84)
Get in touch now!
In cooperation with our local partner, we ensure that your enquiry is processed quickly and personally.
Get in touch now!
In cooperation with our local partner, we ensure that your enquiry is processed quickly and personally.
Get in touch now!
In cooperation with our local partner, we ensure that your enquiry is processed quickly and personally.
Get in touch now!
In cooperation with our local partner, we ensure that your enquiry is processed quickly and personally.
Get in touch now!
In cooperation with our local partner, we ensure that your enquiry is processed quickly and personally.
Get in touch now!
In cooperation with our local partner, we ensure that your enquiry is processed quickly and personally.
Get in touch now!
In cooperation with our local partner, we ensure that your enquiry is processed quickly and personally.