SkillCampVR
Zurück zu News

Publication · 9 août 2026 · 8 min Lesezeit

The KRITIS-Dachgesetz: The Personnel Measures Almost Nobody Is Planning For — and Why the Delay Is an Opportunity

The KRITIS-Dachgesetz has been in effect since March 17, 2026, but the ordinance defining critical facilities is still a draft. Registration isn't mandatory yet. Operators should use this valuable planning window now. Once the deadline starts, securing people—not fences—will be the hardest task.

Von SkillCamp Redaktion

The KRITIS-Dachgesetz: The Personnel Measures Almost Nobody Is Planning For — and Why the Delay Is an Opportunity

Much of this summer's coverage treated 17 July 2026 as a KRITIS deadline. In fact, no deadline is currently running — because so far no facility qualifies as a critical facility.

The difference matters, because it changes what operators should be doing right now.

Where the law actually stands

The Dachgesetz zur Stärkung der physischen Resilienz kritischer Anlagen (KRITISDachG) entered into force on 17 March 2026 (BGBl. 2026 I Nr. 66), transposing the European CER Directive (2022/2557) into German law. It is the first uniform federal framework for the physical resilience of critical infrastructure — the counterpart to what NIS2 and the BSIG do for cyber security.

Under § 8 (1), an operator must register with the BBK within three months of a facility qualifying as a critical facility, but in no case earlier than 17 July 2026. Whether a facility qualifies, however, is governed by the implementing ordinance under § 4 (3) and § 5 (1) — the Kritisverordnung, which sets out facility categories and thresholds. The Federal Ministry of the Interior published a departmental draft at the end of May 2026; the stakeholder consultation closed in June, and inter-ministerial coordination is still under way.

The BBK's own FAQ states the consequence unmistakably:

"Zurzeit besteht noch keine Registrierungspflicht auf der Grundlage des KRITISDachG, da sich die konkretisierende Rechtsverordnung zur Bestimmung kritischer Anlagen gem. § 4 Abs. 3 und § 5 Abs. 1 KRITISDachG noch in Erarbeitung und Abstimmung befindet."

("There is currently no obligation to register under the KRITISDachG, because the implementing ordinance determining critical facilities under § 4 (3) and § 5 (1) KRITISDachG is still being drafted and coordinated.")

What the timetable looks like once it starts

Registration is the trigger for everything that follows, and § 8 (7) sets short intervals:

Nine months after registration: the operator's own risk analysis and risk assessment (§ 12), and at least every four years thereafter. Ten months after registration: the resilience obligations together with a documented resilience plan (§ 13), the reporting duties (§ 18), and the obligations of the management (§ 20).

Reporting under § 18 must be made without undue delay, and at the latest within 24 hours of becoming aware of a significant incident; a detailed report follows no later than one month after that point.

§ 20 places the obligation directly on the management: it must implement the resilience measures under § 13 (1) and ensure their implementation through appropriate organisational arrangements. Liability for culpably caused damage is governed primarily by the company-law rules applicable to the legal form in question; liability arises under the KRITISDachG itself only where those rules contain no corresponding liability provision.

So from registration onwards, an operator has roughly ten months to get from a risk analysis to a resilience plan that is not merely written but applied.

The measures almost nobody is planning for

§ 13 (3) lists the measures that can serve the law's four objectives: preventing incidents, physically protecting the facility, responding to incidents and limiting their consequences, and swiftly restoring the critical service.

Number 2 is the one that gets budgeted for: structural and technical security and organisational protection (Objektschutz) — such as property perimeter demarcations and resistant façade elements — instruments and procedures for monitoring the surrounding area, the use of detection equipment, and access controls.

Two further items in the same catalogue attract considerably less attention:

No. 5 — "ein angemessenes Sicherheitsmanagement hinsichtlich der Mitarbeitenden zu gewährleisten, einschließlich des Personals externer Dienstleister" (ensuring appropriate security management with regard to personnel, including the staff of external service providers)

No. 6 — "das Personal für die … genannten Maßnahmen durch Informationsmaterialien, Schulungen und Übungen vertraut zu machen" (familiarising personnel with the measures referred to, through information materials, training and exercises)

Two points here reward a close reading.

First, the catalogue is expressly indicative — "Zu den Maßnahmen … können die folgenden zählen" ("the measures may include the following") — and the measures are chosen on the basis of the operator's own risk analysis, subject to a proportionality standard and a means-ends assessment (§ 13 (2)). Neither No. 5 nor No. 6 establishes a free-standing training obligation. § 13 (4), however, requires the resilience plan to set out "die den Maßnahmen zugrunde liegenden Erwägungen" — the reasoning underlying the measures — with reference to that same risk analysis. A plan that documents detection technology in detail while remaining silent on the people who operate it will have to set out its reasoning on that point in any case.

Second, No. 5 expressly covers the staff of external service providers. At most critical facilities, the people at the perimeter are not the operator's own employees. They are the contracted security provider, the ground handling company, the cleaning firm. A personnel measure that stops at the boundary of one's own payroll reaches less far than the catalogue in § 13 (3) No. 5 suggests.

Why the personnel side is the longest road

A fence can be procured. Detection technology can be installed over a weekend by a specialist contractor. Bringing several thousand shift-based, multilingual frontline personnel — including the service providers' staff — to demonstrable competence without taking the site out of operation is the slowest item in a ten-month plan, and the one most likely to give way.

Conventional classroom instruction makes this harder in three respects: it takes people off the roster precisely when the roster is already thin, it requires trainers who are themselves in short supply, and it concentrates learning into one-off sessions, after which the questions resurface on shift.

And the staffing base was already under strain beforehand. In the first EU-wide study on labour and skills shortages in private security, published in 2022 under the INTEL project by CoESS and UNI Europa, 92% of companies reported growing difficulty finding staff, and 48% reported difficulty meeting market demand. The workforce expected to carry the KRITIS personnel measures is the same one the industry has been struggling to secure for years.

What makes sense in this window

Three steps are possible now, before the clock starts.

Establish which roles are affected in personnel terms along the four objectives of § 13 (1). Which roles actually act on prevention, physical protection, response and restoration — and which of those roles sit with a service provider rather than on your own payroll?

Decide the delivery model before you are inside the ten-month window, not during it. Immersive training is one of the few approaches that shortens the time to confident, competent action rather than consuming roster capacity. PwC's enterprise study found that VR learners completed training up to four times faster than in classroom format and felt up to 275% more confident applying what they had learned. The study examined soft-skills training among PwC's own junior managers — the mechanism transfers more readily than the precise multiple does. And the mechanism is the relevant part: continuous time on task, and repeatable practice of exactly those rare, high-consequence events that a resilience plan is about. Intrusion, sabotage, drone sighting, evacuation — rehearsed without having to stage them in live operations.

Build the evidence as you go, not after the fact. Completions, competence levels and refresher intervals by role — service providers included — turn "we train our people" into something that holds up when § 13 (4) asks for the underlying reasoning and § 20 puts a name behind it.

None of this is a compliance guarantee, and no training platform certifies anyone under the KRITISDachG. The point is narrower than that: of the measures in § 13, the personnel ones take the longest and are the most likely to be planned too tightly.

What to watch next

The draft Kritisverordnung reaches further than the current regime — a genuinely new space sector, district cooling, pharmaceutical manufacturing and EU reference laboratories, along with lower thresholds and more finely differentiated categories for energy storage and power-to-gas facilities. Worth noting: the AG KRITIS consultation response points out that several categories described in the explanatory memorandum as "newly included" are in fact relabelled continuations of facilities already covered — port facilities, for instance. The draft retains the standard threshold of 500,000 persons supplied, even though the Bundesrat had previously pressed for a lower figure. Once the ordinance is enacted, facilities qualify as critical — and the three-month registration period begins.

Operators who use this interval to work out how they will train their people — including the people who work for their service providers — will spend those ten months implementing. Operators who wait will spend them finding out how long training takes.

At SkillCampVR, this is exactly the problem we work on: VR training and AI support grounded in approved procedures, for workforces in live operations — more than 60 active client locations and around 2,000 VR training sessions per week. GDPR-compliant and hosted in Germany.

Bereit, VR-Training in Ihrem Unternehmen einzusetzen?

Sprechen Sie mit unseren Experten und erfahren Sie, wie SkillCampVR Ihre Schulungen transformieren kann.