Germany’s KRITIS Umbrella Act (KRITIS-Dachgesetz) has been in force since 17 March 2026. It transposes EU Directive 2022/2557 (the CER Directive) into German law and, for the first time, explicitly obliges operators of critical facilities to ensure physical resilience – alongside cybersecurity under NIS2. The sectors covered include digital infrastructure, and therefore data centers.
Key obligations at a glance
- Registration of critical facilities with the Federal Office of Civil Protection and Disaster Assistance (BBK).
- Risk assessments based on the national risk assessment.
- Resilience measures and a resilience plan – technical, organisational and security-related, including emergency preparedness, physical and personnel security and regular training.
- Reporting obligations for significant incidents.
- Management accountability for implementation – breaches can lead to substantial fines.
Deadlines are linked to registration. Which facilities are covered is determined by thresholds set by ordinance – every operator needs to assess its own situation.
Why it matters on the construction site
A data center does not become critical infrastructure only when it goes live. Controlling and documenting access, keys, materials and personnel during construction lays the groundwork operators will later need to evidence in their risk assessment and resilience plan. Gaps from the construction phase – unclear access rights, unvetted staff, missing records – are hard to close once the site is operational.
What this means when choosing a security provider
- Personnel security: vetted staff with police clearance, registered in the German security register, with NDAs – extended checks on request.
- Fixed staff pool: named teams instead of rotating floaters.
- Documented access control: badges, visitors, keys, tool and material checks – recorded audit-proof.
- Training records: inductions, fire safety assistant, first aid, de-escalation – evidenced.
- Incident management: clear reporting and escalation paths with complete reports.
- Seamless transition from construction to live operations without changing provider.
How Solid Safety supports you
Solid Safety specialises in data centers and has supported 40+ data center projects – with experience at KRITIS facilities. Our teams work with a digital logbook, documented patrols and PDF reports, with no subcontractors in Germany, certified to ISO 9001, ISO 45001 and DIN 77200. More at Data center security company.
Note: this article provides a general overview and is not legal advice. For your specific facility, please consult your legal or compliance advisers.
Data center project in planning? Talk to us →