The CRITIS framework legislation is now in force, the first deadlines are approaching, and many organisations are currently grappling with a crucial question: Are we affected – and if so, what specific steps do we need to take now? Guidance is provided by the CRITIS guide published by the Association for Security Technology (VfS), a partner of Perimeter Protection. It outlines the legal requirements and provides a structured guide through the key stages: from assessing whether your organisation is affected, through registration, risk analysis and a resilience plan, to reporting obligations, audits and a permanently established resilience management system.
Such practical classifications are an essential part of the professional exchange at Perimeter Protection. As Europe’s leading trade fair for integrated perimeter protection, it brings together operators of critical infrastructure with security managers, manufacturers, integrators, planners, associations and public authorities. The focus is on how regulatory requirements can be translated into effective, integrated security concepts.
The following 10-step plan summarises the key measures set out in the VfS guidelines and highlights what affected companies should be focusing on now.
Checklist: Ten measures that companies should implement now
1. Assess whether the company is affected
Firstly, it must be clarified whether the company provides services in a critical sector such as energy, water, healthcare, telecommunications or transport, and whether at least 500,000 people depend on these services. Even below this threshold, particular regional significance may lead to classification as a critical infrastructure facility, for example where no equivalent alternatives are available. Furthermore, suppliers, manufacturers and service providers to CRITIS operators should also assess their role at an early stage, as requirements for protective measures and risk management are increasingly being passed on throughout the entire value chain.
2. Registration with the BBK
Once it has been established that a facility is affected, the operator must actively register their critical infrastructure. To this end, the Federal Office for Civil Protection and Disaster Assistance (BBK) and the Federal Office for Information Security (BSI) have set up a joint reporting and information portal (MIP). For existing facilities, the registration period runs from 17 July 2026 to 17 October 2026. New facilities must register within three months of it being established that they are affected.
3. Carry out a comprehensive risk analysis
The first systematic risk analysis must be drawn up and reported to the BBK no later than nine months after registration. Only a holistic analysis (all-hazards approach) provides the basis for effective protective measures. The broad spectrum of natural hazards, technical failure, human error, hybrid threats and terrorism must be taken into account in a risk analysis.
4. Develop a resilience plan
Specific technical, organisational and security-related measures must be derived from the risk analysis and documented in a resilience plan, which will serve as the main reference document for supervisory authorities in future. Measures must be defined for the four areas of prevention, protection, response and defence, and recovery.
5. Respond quickly in an emergency
Should a significant incident occur that disrupts or poses an immediate threat to the provision of a critical service, the pre-established crisis management procedures, as well as alert and response plans, must be activated. Technical detection systems help to verify the situation quickly and establish a reliable picture of the situation. On this basis, the defined escalation levels can be triggered and targeted defence and response measures initiated. The aim is to limit negative impacts, maintain the critical service as far as possible and restore normal operations quickly.
6. Submit the initial report in a timely manner
If a significant incident is identified, it must be reported immediately – and at the latest within 24 hours of becoming aware of it – via the joint reporting portal of the BBK and the BSI. The initial report should include details of the nature of the incident, the suspected causes and impacts, as well as the affected area and the number of users affected. In addition, an initial assessment of the expected duration of the disruption is required.
7. Submit a detailed report
A detailed report must be submitted to the competent authority no later than one month after the incident has come to light. The report must describe in detail the nature of the incident, its causes and its specific consequences. This must be based on a thorough root cause analysis. Feedback and recommendations for action from the BBK should then be evaluated and incorporated into the further development of the resilience plan.
8. Update the risk analysis following an incident
Following a reportable incident, the BBK may order a reassessment of existing risks. In this case, the risk analysis and the associated documentation must be updated to reflect the new findings. Depending on the severity of the incident, a completely new risk analysis may even be required.
9. Embedding resilience within the organisation
The CRITIS umbrella law requires a regular and structured resilience management process that is firmly embedded within the organisation’s structure. To this end, clear responsibilities, adequate budgets and specific protective measures must be established. Resilience thus becomes a corporate, societal and personal obligation to ensure security of supply.
10. Regularly assess risks and keep evidence to hand
Risk analyses and risk assessments must be carried out at least every four years and again in the event of significant changes. Based on the results, the resilience plan must also be reviewed and updated where necessary. At the same time, organisations should be able to demonstrate at any time that the specified measures have been implemented and are effective. The BBK may request relevant documentation, carry out audits or inspect the critical facility as part of an on-site inspection.
The CRITIS umbrella law makes it clear: resilience is not a project with a fixed end date, but an ongoing process. Those who address the new requirements at an early stage lay the foundations for compliance with legal requirements whilst at the same time strengthening the resilience of their own organisation. This is precisely why it is worth taking a holistic view of the issue. Physical perimeter protection, organisational processes and modern security technologies must work in tandem to effectively protect critical infrastructure. Equally important is dialogue with experts, authorities, planners and manufacturers, as many challenges can only be solved through collaboration.
As Europe’s leading trade fair for integrated perimeter protection, Perimeter Protection offers precisely this platform. It brings together all stakeholders along the security-related value chain, showcases state-of-the-art technologies from the security sector and provides a forum for professional exchange on the security concepts of tomorrow. After all, the best time to build resilience is before an emergency occurs.

