Critical Infrastructure in the Public Sector: What Structures Employers Must Now Put in Place
New Legal Framework Makes Infrastructure Resilience a Leadership and Management Responsibility Date: August 7, 2026With the KRITIS Framework Act, a uniform nationwide legal framework for the physical security and resilience of critical infrastructure came into effect for the first time on March 17, 2026. The law implements the European CER Directive and requires operators of critical facilities to systematically protect themselves against natural disasters, sabotage, technical failures, human error, and other hazards.
For public employers, this means more than just additional security plans. KRITIS is becoming an organization-wide management task—and thus an issue for agency leadership, human resources departments, municipal enterprises, and public institutions.
KRITIS is not solely the responsibility of the IT department
The overarching KRITIS Act focuses on the physical resilience of critical infrastructure. At the same time, the new BSI Act—which has been in effect since December 6, 2025, as a result of the NIS 2 implementation—regulates cyber and information security. Affected organizations must therefore consider both dimensions of protection together: the security of IT systems and networks, as well as the operational functionality of buildings, facilities, control centers, supply chains, and business processes.
Consequently, this responsibility cannot be delegated to a single IT specialist or an external data center operator. What is needed is a binding KRITIS governance framework that integrates information security, technical infrastructure, building security, emergency preparedness, data protection, procurement, and crisis management.
Which public employers may be affected
Whether a government agency or municipal institution falls directly under the KRITIS umbrella law depends on the facility it operates, the critical service it provides, its sectoral classification, and the applicable thresholds. The law covers, among other areas, energy, transportation, finance, healthcare, drinking water, wastewater, information technology, telecommunications, and public administration.
The issue is therefore of particular relevance to municipal utilities, public transit agencies, hospitals, municipal data centers, water and wastewater utilities, waste management companies, control centers, technical departments, and other public enterprises.
However, even public authorities that are not themselves directly classified as operators of a critical infrastructure must review their dependencies. This is because public services often depend on external data centers, energy suppliers, telecommunications companies, cloud providers, technical service providers, and specialized suppliers.
Establishing Responsibility at the Management Level
The first organizational step does not involve new software or a technical security product. Public employers must first determine who is responsible for KRITIS, resilience, and business continuity.
The leadership of the agency, utility, or business should establish binding objectives, responsibilities, resources, and escalation procedures. This also includes deciding which services must continue to operate or be restored particularly quickly even in the event of a serious incident.
KRITIS thus becomes a management responsibility. Security measures must be prioritized, funded, reviewed, and enforced organization-wide.
Establish Central KRITIS Coordination
Depending on the size and complexity of the organization, central responsibility can be structured as a staff unit, functional area, division, or program management.
Suitable job profiles include, for example:
- Head of the KRITIS and Information Security Division
- Head of KRITIS and Resilience Management
- Program Director for Operational Resilience
- Coordinator of Information Security and Emergency Management
- Head of Digitalization and KRITIS IT
- Business Continuity and Crisis Management
These positions are not required to implement all technical measures themselves. Their primary responsibility is to coordinate responsibilities, assess risks, manage projects, and ensure implementation by internal departments, data centers, and external service providers.
Establishing Cross-Functional Governance Structures
An effective KRITIS organization requires more than a single designated representative. It makes sense to establish a permanent steering team with representatives from IT, information security, technical operations, facilities management, data protection, legal, human resources, procurement, communications, and disaster response.
This committee should meet regularly to prioritize risks and monitor the status of implementation. At the same time, clear decision-making and escalation procedures must be established for emergencies.
Particularly in the public sector, care must be taken to ensure that responsibilities are not merely described in formal terms but are also backed by actual decision-making authority and sufficient resources.
Identify Critical Services and Dependencies
The starting point for every KRITIS organization is the question of which services must be maintained under exceptional conditions.
This applies not only to servers and networks. Buildings, control centers, technical facilities, power supply, communication channels, key personnel, supply chains, service providers, and alternative operating locations must also be identified.
A motor vehicle registration office, for example, may depend on traffic control centers, digital specialized procedures, communication networks, data center services, and technical traffic infrastructure. The failure of individual components can have significant impacts on traffic control, hazard prevention, and public safety.
Establish Risk Analyses and Resilience Plans
Operators of critical facilities must conduct their own risk analysis and risk assessment at least every four years. Based on this, proportionate technical, security-related, and organizational measures must be developed.
The law specifies, among other things:
- Emergency preparedness and crisis management
- structural, technical, and organizational physical security
- Access controls and perimeter surveillance
- Prescribed procedures for alarms and crises
- Emergency power supply and business continuity
- Alternative supply chains and restart procedures
- Security management for in-house and external personnel
- Regular training and drills
These measures must be documented in a resilience plan, implemented, and updated based on risk analyses and as needed to reflect relevant changes.
Jointly Managing KRITIS and Cybersecurity
At the same time, the new BSI Act requires affected organizations to implement comprehensive risk management measures for information security. These include, among other things, incident management, backup and recovery, crisis management, supply chain security, access controls, and securing the development, procurement, and maintenance of information technology systems.
Public employers should therefore avoid establishing separate, parallel structures for physical security, IT security, and emergency management. A more appropriate approach is an integrated management model with clearly defined interfaces.
New Positions Require Management and Project Expertise
The growing demand for personnel is not limited to traditional IT security specialists. There is an increasing need for specialists and managers who can combine technical, organizational, and administrative expertise.
Skills in the areas of digitalization, process management, information security, risk analysis, business continuity, technical infrastructure, data protection, and project and service provider management are particularly relevant.
For many public-sector employers, establishing such structures will only be possible through targeted recruitment. However, the job market for experienced IT security, KRITIS, and resilience experts is tight. Job profiles must therefore be realistically defined, clearly delineated in terms of technical scope, and accompanied by an attractive scope of responsibility.
Resilience Requires Organization and Qualified Personnel
The KRITIS umbrella law does not require every government agency to immediately establish a new department. However, it does increase the pressure to clearly define responsibilities and build effective structures.
Public employers should therefore assess:
- Which services and facilities are critical to their own operational capacity?
- What physical, digital, and personnel dependencies exist?
- Who bears overall responsibility for KRITIS and resilience?
- Are risk analysis, emergency planning, and crisis communication integrated with one another?
- Are the existing technical and managerial capacities sufficient?
- Do new positions, departments, or central coordination functions need to be created?
After all, critical infrastructure is not protected by technology alone. What is crucial are clear lines of responsibility, robust processes, and qualified employees who permanently embed security and resilience within the organization.
