On 29 January 2026, the Bundestag adopted the KRITIS Umbrella Act, thereby transposing the CER Directive (EU) 2022/2557 into German national law. For the first time, this legislation establishes an independent, nationwide legal framework for the physical protection and resilience of critical infrastructures. The aim of the Act is to systematically and sustainably strengthen the resilience of critical facilities against physical threats, natural hazards, and hybrid risks.
What is the KRITIS Umbrella Act?
The KRITIS Umbrella Act (Critical Infrastructure Umbrella Act) is a major regulatory framework in Germany that addresses the protection of critical infrastructure. Its aim is to prevent outages or disruptions to these infrastructures, which could have massive impacts on public safety, the economy, and social life.
Who is affected by the KRITIS Umbrella Act?
It applies to all operators of facilities that are classified as critical. This includes facilities and systems that are essential to the functioning of our society, such as those in the sectors of energy supply, water supply, information technology, telecommunications, transport, healthcare, and finance.
Quelle: Critical Infrastructure sectors
What does this law cover?
The law defines requirements and obligations for operators of the above-mentioned critical infrastructures to ensure the security and availability of their systems and services. Its objective is to strengthen the protection of these infrastructures against threats such as cyberattacks, natural disasters, fires, and technical failures.
Among other things, the law stipulates:
-
Identification and classification of critical infrastructure:
Operators must assess which parts of their infrastructure are to be classified as critical.
-
Reporting obligations:
Operators are required to report significant disruptions or security incidents to the competent authorities.
-
Protective measures:
Appropriate technical and organizational measures must be implemented to ensure the security of critical infrastructure.
-
Regular reviews:
The effectiveness of security measures must be regularly reviewed and adapted as necessary
Why is compliance with the KRITIS Umbrella Act mandatory?
The KRITIS Umbrella Act is not optional but mandatory for affected operators. There are several reasons for this:
-
Public safety:
The failure of critical infrastructure can have catastrophic consequences. Compliance with the law helps minimize the risk of such disruptions.
-
Legal consequences:
Operators that fail to comply with the requirements of the KRITIS Umbrella Act may face severe penalties, including fines and, in cases of gross negligence, criminal liability.
-
Trust and responsibility:
Operators of critical infrastructure bear a special responsibility. Compliance with the law is therefore also a matter of trust toward society and the users of their services.
Fire protection as a key factor: How the KRITIS Umbrella Act protects lives and infrastructure
A key aspect of the KRITIS Umbrella Act is the consideration of fire protection measures. Protecting critical infrastructure involves not only safeguarding against cyber or physical attacks, but also protection against fires. Fires can have devastating effects in a very short time, particularly in sectors such as energy supply or telecommunications, where even minor disruptions can lead to major consequences.
Fire protection measures include:
-
Early fire detection systems:
These systems enable rapid fire detection and timely intervention.
-
Emergency plans:
Detailed emergency plans must be in place for fire incidents, including clear evacuation and firefighting procedures.
-
Regular maintenance and inspections:
Fire protection systems must be regularly maintained and tested to ensure they function effectively in an emergency.
-
Staff training:
Personnel must be trained to respond quickly and correctly in the event of a fire in order to minimize damage.
Achieving KRITIS compliance with Rotarex Firetec: Innovative fire protection solutions for secure and compliant infrastructure
Rotarex Firetec offers certified and proven fire protection solutions that comprehensively protect essential infrastructure and facilities against fire risks. Our gas fire suppression systems INEREX®, RX5112, and RXCO2 effectively safeguard data centers, hospitals, banks, offices, energy providers, and transport operators.

For the protection of commercial kitchens, we recommend our TRIPLESTAR® fire suppression system, while our COMPACT LINE® fire suppression system is ideal for vehicle engines. In addition, our FireDETEC® local application systems provide reliable protection for smaller assets such as control cabinets and industrial machinery.

Conclusion
The KRITIS Umbrella Act is a key instrument for ensuring the functionality and security of critical infrastructure in Germany and across the EU. Compliance with the law is not only a legal obligation, but also an essential contribution to public safety and societal stability. Operators of critical infrastructure bear a high level of responsibility and must therefore implement comprehensive protective measures including fire protection and review them regularly.
Regardless of the type of critical infrastructure or assets you need to protect, Rotarex Firetec supports you in achieving KRITIS compliance and offers tailor-made fire protection solutions precisely adapted to your needs.
Learn more about our products on our website at https://rotarexfiretec.com/ or contact our experts for individual advice.