Physical resilience starts before the first person enters.
Self-contained detection, camera-based alarm verification and defined intervention processes for critical facilities – including sites without power or internet. Approach and unauthorised entry can be detected early, assessed and turned into a defined response.
AEGIS Protect supports operators with a technical and organisational building block for meeting the KRITIS umbrella act: detection, verification and alarm paths – matched to site, risk and security concept.
No existing power or internet connection required.
Early detection
Detect suspicious activity before critical areas are reached.
Defined response
Alerting, verification and intervention according to defined processes.
The KRITIS umbrella act (KRITISDachG) has been in force since 17 March 2026 and strengthens the physical resilience of critical facilities. Section 13 expressly refers to environmental monitoring, detection devices and procedures in the event of an alarm. AEGIS Protect supports operators in practical implementation: self-contained detection, camera-based verification, defined alarm paths and optional control-centre connection and intervention.
Detect before damage occurs
Critical infrastructure does not end at the IT interface.
Cyber security is only one side of resilience. Sabotage, unauthorised entry, theft, vandalism or targeted interference often start physically – on the grounds, at a construction site, at a technical location or at an as yet unsecured outer boundary.
The KRITIS umbrella act puts the physical protection of critical facilities firmly in focus.
Unauthorised entry
People enter sensitive operational or plant areas.
Sabotage & tampering
Technical equipment is deliberately damaged or influenced.
Remote sites
Substations, corridors, construction fields or outdoor plant are hard to secure with conventional infrastructure.
What the KRITIS umbrella act requires – and how we support you
AEGIS Protect supports operators in implementing physical-resilience requirements. Our security solution can form a central technical and organisational building block of your resilience concept.
Requirement 01 · § 13 Abs. 1 Nr. 1 KRITISDachG
Prevent incidents
Operators should prevent incidents from occurring as far as possible.
AEGIS implementation
Early detection can identify suspicious activity at vulnerable outdoor areas. The aim is to recognise a situation and initiate countermeasures before it becomes a security incident at the critical facility.
early detection
monitoring of defined risk areas
rapid alarm transmission
flexible adaptation to changing risk areas
Requirement 02 · § 13 Abs. 1 Nr. 2 und Abs. 3 KRITISDachG
Ensure physical protection
Adequate physical protection of premises and critical facilities must be ensured.
AEGIS implementation
Self-contained detection and camera technology watches sensitive outdoor areas even where no conventional security infrastructure exists. That maps directly to measures named in the act, such as environmental monitoring and detection devices.
self-contained detection
camera-based verification
perimeter and open-area surveillance
temporary or permanent use
modular and scalable
Requirement 03 · § 13 Abs. 1 Nr. 3 KRITISDachG
Respond to incidents and counter threats
Incidents must be responded to and countered, and negative effects limited.
AEGIS implementation
A detected alarm must not end at the sensor. Detection therefore becomes a defined security process: detection → transmission → verification → alarm action → intervention. Depending on the agreed security concept, the control centre, contacts or intervention officers can be involved.
defined alarm paths
camera-based situation assessment
optional control-centre integration
intervention depending on the security concept
Requirement 04 · § 13 Abs. 1 Nr. 3 und Nr. 4 KRITISDachG
Limit the impact
Negative effects of incidents should be limited and the critical service restored as quickly as possible.
AEGIS implementation
The earlier a situation is detected and assessed, the earlier defined countermeasures can be triggered. Critical areas can be protected, responsible persons informed and intervention measures initiated.
early situation assessment
defined escalation
traceable event chain
Requirement 05 · § 13 Abs. 4 KRITISDachG
Organise measures so they can be traced
Resilience measures taken must be set out in a resilience plan and applied. For response, the act also refers to predefined procedures in the event of an alarm.
AEGIS implementation
Technical security measures, monitored areas and agreed alerting paths can be documented in a traceable way and integrated into the operator’s resilience concept. AEGIS does not automatically produce the full statutory resilience plan.
documented security areas
agreed alarm processes
link to the operator’s concept
Physical resilience is not solely a plant-security task.
The KRITIS umbrella act also anchors implementation of resilience measures at management level (section 20 KRITISDachG). AEGIS Protect helps you put suitable measures for the physical protection of critical facilities into practice – as a robust building block for technology, alarm process and organisation.
Protection where conventional infrastructure reaches its limits.
Critical facilities are not always inside fully developed plant sites. Outdoor installations, substations, construction sites, temporary work areas, cable projects or remote technical locations often have no existing power or usable internet connection.
Our solution was designed precisely for those operating conditions.
No existing power connection
The security solution operates independently and does not rely on an existing building supply.
No existing internet connection
Required communications run independently of local network infrastructure.
Separate from site IT
The system is independent of the site’s infrastructure and IT. It forms its own security layer – without connecting to existing operational networks or IT systems on site.
Quick to relocate
If the area to be protected changes, the cover can be adapted and redeployed.
Modular expansion
From a single risk point through to covering larger open areas.
For temporary and long-term projects
Suitable for changing construction phases as well as longer-term vulnerable plant areas.
A defined risk area is monitored and suspicious activity is detected.
02
Verify
The event is checked by camera so a technical detection becomes an assessable situation.
03
Alert
A relevant event is forwarded via the defined alarm path.
04
Respond
Depending on the security concept, contacts, the control centre or intervention officers are involved.
05
Document
Events and measures can be recorded in a traceable way and used by the security organisation.
For sensitive sites with a higher need for protection.
Typical uses for self-contained perimeter surveillance: where critical facilities are extensive, remote or still without fixed security infrastructure.
Critical infrastructure does not begin only at commissioning.
Even during construction, expansion and modernisation of critical infrastructure, sensitive areas arise. Materials, technical components, cables and prepared plant may sit for months or years on extensive, changing work fields.
Fixed security infrastructure is often not yet in place. That is where self-contained, relocatable protection is strongest.
The security area changes? The protection changes with it.
§ 13 KRITISDachG
How do you protect against unauthorised entry or approach?
On physical protection, the KRITIS umbrella act refers among other things to:
Instruments and procedures for monitoring the surroundings
Defined alarm paths turn a technical alert into a concrete response.
Detection is the start. Response decides.
From a single detector to a security concept.
The technical solution should not be viewed in isolation. Together with the operator, AEGIS Protect considers:
Which areas are particularly at risk?
Where are possible approach routes?
Which areas need to be monitored early?
Which events should trigger an alarm?
Who assesses an alarm?
Who must be informed afterwards?
When is intervention required?
How are measures and events documented?
That is how security technology becomes a defined process for physical resilience.
Security must work in an emergency.
AEGIS Protect combines self-contained detection technology with control-centre expertise, intervention and documented procedures – from a single source, matched to your security concept.
Own control centre
Alarms can be connected to our alarm receiving centre and assessed there – depending on the agreed concept.
Intervention
Intervention officers to VdS 2172 – optionally integrated into the alarm process.
Proven quality
DIN 77200, ISO 9001 and NATO NCAGE – not a KRITIS certification, but demonstrable quality and organisational standards.
How well is your critical facility physically protected?
Let us look together at where unauthorised entry can be detected early and how detection, verification and intervention can be integrated into your security concept.
Short, factual answers on the KRITIS umbrella act and AEGIS Protect’s role in the physical protection of critical facilities. This is not legal advice.
What does the KRITIS umbrella act regulate?
The KRITIS umbrella act (KRITISDachG) is intended to strengthen the physical resilience of critical facilities against a range of threats. It complements existing cyber and IT-security requirements with duties on physical protection, risk analysis, a resilience plan and incident reporting. The primary source is the KRITISDachG; AEGIS Protect does not provide legal advice.
When did the KRITIS umbrella act come into force?
The KRITIS umbrella act entered into force on 17 March 2026. Further detail, including the ordinance defining critical facilities and cross-sector minimum requirements, was still being drafted as of August 2026. The BBK recommends that operators use the time to review physical protection measures.
Which companies are affected by the KRITIS umbrella act?
Not every company in a KRITIS sector is automatically in scope. What matters are critical services, facility categories, statutory criteria and thresholds or official determinations under sections 4 and 5 KRITISDachG. The concrete designation of critical facilities is made by ordinance, which is still being implemented.
What does the KRITIS umbrella act require for physical protection?
Section 13 KRITISDachG requires suitable and proportionate measures to prevent incidents, physically protect premises and critical facilities, respond to incidents and restore the critical service. For physical protection the act refers among other things to structural and technical security, organisational site protection, environmental monitoring, detection devices, access controls and predefined procedures in the event of an alarm.
What does section 13 KRITISDachG specifically require on detection?
Section 13(3) KRITISDachG expressly names instruments and procedures for monitoring the surroundings and the use of detection devices as possible physical-protection measures. For responding to incidents the act refers to risk and crisis-management procedures and predefined alarm procedures. AEGIS Protect addresses exactly that: self-contained detection, camera-based verification and defined alarm paths.
Does the AEGIS solution automatically fulfil the KRITIS umbrella act?
No. The AEGIS security solution can be an important technical and organisational building block of the required resilience measures. Which measures are required depends on the individual risk analysis, the facility, the sector and the applicable requirements. AEGIS Protect does not provide legal advice and does not replace the full risk analysis under section 12, the full resilience plan, statutory incident reports, or all structural and organisational measures.
Does the security solution replace the risk analysis under section 12?
No. Operators of critical facilities must carry out their own risk analysis and assessment on a regular basis under the statutory rules – at least every four years or when needed. AEGIS security measures can be planned and implemented on the basis of such an assessment, but they do not replace it.
What is a resilience plan under section 13(4) KRITISDachG?
Resilience measures taken must be set out by the operator in a resilience plan and applied. AEGIS Protect can map technical and organisational security measures, monitored areas and agreed alerting paths in a traceable way. AEGIS does not automatically produce the full statutory resilience plan.
Who is responsible under section 20 KRITISDachG?
The management of an affected operator is responsible for implementing and organisationally ensuring the required resilience measures. Physical resilience is therefore not solely a plant-security task, but is anchored at board level.
Does the solution work without power and internet?
Yes. AEGIS Protect’s self-contained detection and alerting solution is designed for sites with no existing power or internet connection. The specific design is agreed with you in a site discussion.
Can the solution also be used during construction and modernisation?
Yes. Changing work areas, expansion projects and temporarily vulnerable areas are a core use case. Critical infrastructure does not begin only at commissioning. If the area to be protected changes, the cover can be adapted and moved – without fixed cabling.
What happens after a detected event?
Detection becomes a defined process: camera-based verification, a defined alarm path, and where applicable the control centre or intervention, plus documentation. Which steps apply depends on the agreed security concept. Control-centre connection and intervention can be integrated optionally.
We will call you back shortly on the number provided.
Cookie notice
Cookies and similar technologiesWithout optional consent we only use what is technically required: e.g. session cookies for the protected client area (after login) and security cookies (CSRF). We do not use these for advertising or profiling on our behalf.
With "Necessary only" you allow essential cookies only and decline optional analytics (e.g. Google Tag Manager).
By choosing "Accept all" you also agree to Google Tag Manager (reach and usage analysis) as described in our
privacy policy.
On forms we may load Google reCAPTCHA for spam protection.
We do not sell personal data. Details on vendors, retention and your rights are in the privacy policy.