Counter-drone defense at energy facilities: what Germany's KRITIS umbrella law now requires
This article separates three things that often blur together. What the KRITIS umbrella law actually requires. How real the drone threat to energy facilities is. And where the legal line runs between what an operator may do and what only the state may do. It ends with what a lawful detection layer looks like and what to do now.
Germany's KRITIS umbrella law (KRITISDachG) has been in force since 17 March 2026 and, for the first time, requires operators of critical facilities to provide physical protection under a single federal rule. It transposes the EU CER Directive (EU) 2022/2557, whose deadline Germany missed on 18 October 2024. The standard threshold is 500,000 people supplied by a facility (section 5). Affected operators register within three months of classification with the Federal Office of Civil Protection and Disaster Assistance, run a risk analysis at least every four years, and implement resilience measures. Breaches cost up to 1,000,000 euro (section 24). The threat is documented: the Federal Criminal Police Office counted more than 1,000 suspicious drone flights in 2025 and, from January to August 2026, 747 sightings over critical infrastructure with 1,068 drones identified. Active defense remains a state monopoly. Jamming, GNSS spoofing, control takeover, and takedown are prohibited for operators. Since the amendment to the Aviation Security Act on 6 March 2026, defense at airports rests with the Federal Police and the armed forces, coordinated by the Joint Counter-Drone Center in Berlin. What remains for operators is a lawful, layered detection chain of sensor fusion, evidence capture, and alerting the police.
What the KRITIS umbrella law demands of operators
Security stopped being optional on 17 March 2026 and became a documented duty with deadlines. The KRITIS umbrella law is Germany's first federal law for the physical protection of critical facilities. It is the counterpart to the NIS2 transposition on the cyber side: what the IT security act governs for IT, the KRITISDachG governs for fences, access roads and airspace.
European law sits behind it. The act transposes the CER Directive (EU) 2022/2557, whose transposition deadline actually expired on 18 October 2024. Germany was late, and the European Commission had already opened an infringement procedure. Now the law is in force, and the clock for operators is running.
What does that mean in practice? Anyone above the threshold has a chain of duties to work through. First, registration with the Federal Office of Civil Protection and Disaster Assistance (BBK), no later than three months after classification as a critical facility. Then the risk analysis, at least every four years, and from it a resilience plan with four goals: prevent incidents, protect physically, respond to incidents and limit consequences, restore operations.
The deadlines run in stages after registration. Resilience measures under section 12 are first due nine months later, further duties under sections 13, 18 and 20 after ten months. Ignore this and you risk fines. The maximum under section 24 is 1,000,000 euro for a breach of the registration duty, tiered below that for evidence and order breaches. Figures of ten million euro that circulate online are wrong, the statute caps at one million.
Drones are not named in the law. They still belong in any serious risk analysis, because they are the most visible physical threat from the air right now. How tightly these rules interlock with the cyber side is set out in the analysis of NIS2 and the KRITIS umbrella law.
How real the drone threat to energy facilities is
The numbers come from official situation reports, not from scare stories. Germany's Federal Criminal Police Office now counts drones over critical infrastructure in four-digit figures.
For 2025 the BKA reported more than 1,000 suspicious drone flights. The most affected: military sites, airports, critical infrastructure. From January to August 2026 a BKA situation update added 747 sightings over critical infrastructure, with 1,068 drones identified. The focus lay in Lower Saxony, North Rhine-Westphalia and Bavaria.
Aviation gives a second picture. The German air navigation service reported 161 drone disruptions in 2024 and 225 in 2025, a rise of about 40 percent. And the incidents do not stay abstract. At Munich Airport operations were halted twice within 24 hours between 2 and 5 October 2025, affecting some 10,000 travelers.
At energy facilities themselves, the clearest case is Brunsbüttel. From 8 August 2024, suspicious overflights recurred for weeks above the industrial area, the decommissioned nuclear plant and the LNG terminal. The Flensburg public prosecutor investigated on suspicion of intelligence activity for sabotage purposes. Whether a state actor stood behind it remains open. The point is a different one: an energy facility can be scouted from the air long before anyone touches a fence. On the cyber side, the same targeting is visible in how deliberately attackers go after energy plants, for example with the DynoWiper malware from the Sandworm group.
Who may act against drones, and who may not
This is the biggest misconception in the whole topic. An operator may protect its facility, but may not defend against the drone. Active defense is a state monopoly in Germany, and for good reason: a jammer takes down radio, GPS and neighboring systems alongside the drone, and a takedown endangers third parties.
What operators may do is the passive side: detect, classify, document, capture evidence, alert the police. Passive physical barriers over protected areas are possible too, as long as they work without electronic interference.
What operators may not do is anything active. Jamming requires a license from the Federal Network Agency that is not granted to civilians, and unauthorized operation is a criminal offence. GNSS spoofing and taking over control fall under the same state monopoly on countermeasures. Kinetic takedown is off limits for site security or service providers, where weapons law and the offence of dangerous interference with air traffic apply.
On the state side, 2026 brought movement. The second amendment to the Aviation Security Act has been in force since 6 March 2026. It gives the Federal Police nationwide responsibility for detection and defense at airports and allows the armed forces to assist in urgent cases and shoot down a drone where that is the only means to prevent a particularly serious accident. That takedown power is constitutionally contested. New too is a dedicated criminal offence: anyone who enters an airport's security area without authorization to disrupt traffic faces up to five years in prison.
Since 17 December 2025 the response has been coordinated by the Joint Counter-Drone Center (GDAZ) in Berlin, which operates around the clock and brings together the Federal Police, the BKA, state police forces and the armed forces. Whether site security will get extended defense powers is under political debate. As things stand it is not law, and nobody should build their security planning on it.
Technical protection concepts: the lawful detection layer
For operators the investment pays off exactly where the lawful response chain ends: at detection. And that only works in layers, no single sensor covers everything.
Four sensor types work together. RF and HF sensors listen to the radio traffic, detect and classify drones passively and sometimes even locate the pilot, but fail against autonomous or encrypted aircraft. Radar picks up signal-quiet drones and covers large areas, but is expensive and prone to false alarms from buildings or weather. EO/IR cameras provide visual verification and documentation, but need a line of sight and struggle at night and in fog. Acoustic sensors are cheap and passive, their range is short and quickly exhausted in a noisy industrial setting.
The trick is not the best single sensor but sensor fusion. Only the combination closes the blind spots of the individual methods and cuts the false-alarm rate that a control room will otherwise start to ignore. Anyone already running attack detection for OT networks knows the principle from IT security: many weak signals only become reliable once they are correlated.
The response chain breaks into four stages: detect, identify, assess, respond. For operators, respond ends at alerting and handover to the police. Everything after that, meaning jamming, spoofing, capture nets, takedown, high-power microwave or laser, sits with state bodies.
What does it cost? Few vendors quote hard prices openly, but the orders of magnitude are clear. Simple detection solutions start in the five-figure range, fixed multi-sensor systems sit in the six-figure range, and KRITIS-grade installations above that. Add maintenance, software licenses, integration, training and staff over the life cycle. How such physical concepts interlock with existing security standards is set out in the analysis of OT security under IEC 62443.
What operators should do now
The duty is running, and the deadlines run with it. Anyone operating a critical facility treats drones as a separate entry in the risk catalogue and rehearses the alerting chain before the first real incident.
The next steps
-
Check scope and deadlines
Match your facility against the threshold of 500,000 people supplied and the sector criteria, and check state law, because the opening clause lets the federal states classify smaller facilities too. Once classified, you have three months until registration with the BBK.
-
Set up a risk analysis with a drone scenario
Put the drone threat explicitly into the risk analysis, from reconnaissance to physical disruption. From it follows the resilience plan along the four goals. The deadlines under section 12 (nine months) and sections 13, 18, 20 (ten months) after registration are fixed in the calendar.
-
Build a lawful detection layer
Rely on sensor fusion of RF, radar, EO/IR and acoustics with clean evidence capture. Do not procure active countermeasures. Choose service providers only with civil-legal systems and rule out jamming, spoofing and takedown by contract.
-
Define and rehearse the alerting chain
Set who alerts whom on a sighting, from the control room through the state or federal police to coordination with the GDAZ. Rehearse the flow with the authorities. An emergency plan nobody has practiced rarely survives the first real overflight.
Further reading
Frequently asked questions
Germany's KRITIS umbrella law has applied since 17 March 2026 and, for the first time, requires operators of critical facilities to provide physical protection under a single federal rule. They must register with the Federal Office of Civil Protection and Disaster Assistance (BBK), carry out a risk analysis at least every four years, and implement resilience measures with four goals: prevent, protect, respond, restore. Breaches can be fined up to 1,000,000 euro. Drones belong in the threat catalogue.
No. Active defense is a state monopoly in Germany. Jamming requires a license from the Federal Network Agency that is not granted to civilians. GNSS spoofing, taking over control, and kinetic takedown are prohibited for operators and can be criminal offences. What is allowed is the passive side: detect, classify, document, capture evidence, and alert the police. Since the amendment to the Aviation Security Act on 6 March 2026, active defense at airports rests with the Federal Police and the armed forces.
Germany's Federal Criminal Police Office (BKA) counted more than 1,000 suspicious drone flights in 2025, with military sites, airports and critical infrastructure most affected. From January to August 2026 the BKA recorded 747 sightings over critical infrastructure with 1,068 drones identified, concentrated in Lower Saxony, North Rhine-Westphalia and Bavaria. The German air navigation service reported 161 drone disruptions in 2024 and 225 in 2025.
For operators a lawful concept is a layered detection chain, not active defense. It combines several sensor types: RF and HF sensors detect and classify radio signals, radar picks up signal-quiet drones, EO/IR cameras provide visual verification, and acoustic sensors cover the near range. Only sensor fusion closes the blind spots and reduces false alarms. The chain follows the stages detect, identify, assess, respond, and for operators ends at documented alerting and handover to the police.
The standard threshold under section 5(2) of the KRITIS umbrella law is 500,000 people supplied by a facility, complemented by qualitative criteria such as interdependencies and market share. Through an opening clause the federal states can classify further facilities below this federal threshold as critical. After classification, operators have three months to register with the BBK, after which the deadlines for resilience measures start to run.