How NIS2 and the KRITIS-Dachgesetz Redrew the Map for Space and Aviation
For most of the last decade, "critical infrastructure protection" in Europe was a conversation about power grids, water utilities, and hospitals. Satellites and airspace sat somewhere off to the side — strategically vital, obviously, but treated as a matter for defence ministries and aerospace primes rather than for the cybersecurity and resilience regulators who set rules for everyone else.
That separation is over. Two pieces of European legislation have redrawn the map. And the organisations that run Europe's space and aviation infrastructure are still working out how much of it they are now standing on.
## The two laws that changed the question
The first is NIS2 — Directive (EU) 2022/2555 — transposed into German law through the NIS2-Umsetzungsgesetz (NIS2UmsG), which took effect on 6 December 2025 as an extensive amendment to the BSI Act (BSIG). The numbers tell the story of its ambition: the BSI's supervised population jumps from a few thousand organisations to roughly 29,500, spread across eighteen sectors. NIS2 is a cybersecurity instrument — risk management, incident reporting, supply-chain security, and direct management responsibility, including potential liability consequences.
The second is the KRITIS-Dachgesetz — the German implementation of the EU's CER (Critical Entities Resilience) Directive. This is the one that tends to get overlooked, because it does something NIS2 does not: it regulates physical resilience. Risk analyses, disruption monitoring, and cross-sector resilience obligations explicitly reach beyond the IT layer to the protection of the physical facility itself. The Bundesrat approved the law on 6 March 2026; it was promulgated on 16 March and has applied since 17 March 2026, with critical-facility operators due to register with the federal civil-protection agency (BBK) by mid-2026 and detailed thresholds still tied to a forthcoming regulation.
The two laws also divide the supervisory work between them: the BSI oversees the NIS2 cybersecurity obligations, while the BBK takes the physical-resilience side. The enforcement structure mirrors that split — purely physical breaches can draw fines up to €500,000, rising to the NIS2 ceiling of €10 million or 2% of global turnover where a failure touches both regimes at once.
Read together, these two laws say something that the older KRITIS framework never quite did: a critical service is only as resilient as the hardware it physically depends on, and the regulator now wants evidence that operators have thought about both.
## Where space comes in
Under NIS2, space is no longer adjacent to the critical-infrastructure conversation — it is named within it, classified as a sector of high criticality. The directive reaches the operators of ground-based infrastructure that support space-based services, and it brings with it the same incident-reporting logic applied to energy or telecoms: a cyber event that could disrupt satellite operations or ground-station function becomes a reportable event.
And space is not only an NIS2 matter. It also sits among the sectors covered by the CER Directive — which the KRITIS-Dachgesetz implements — meaning the same orbital and ground assets now fall inside the *physical* resilience framework as well, not just the cyber one. Both halves of the European approach point at the same infrastructure from different directions.
The German picture is more nuanced, and more revealing. Satellites themselves are, by any sensible definition, critical infrastructure — a fact underscored by the federal civil-protection agency's own recommendation that satellite communication serve as a backup channel for crisis situations. Yet only a fraction of the ground stations that make those satellites useful have historically been regulated as KRITIS. Industry and research bodies, including voices from the digital-infrastructure and aerospace communities, have increasingly pointed to this gap: the orbital asset is treated as critical, while the terrestrial node that commands and downlinks it can fall outside the formal designation.
That asymmetry is precisely what the new resilience framework is built to close. The value of a satellite constellation does not live only in orbit. It lives in the antennas, teleport sites, modems, cabinets, access points and cabling on the ground — the "ground segment" — where the service becomes physically reachable. That is also where the system is often most exposed: not through a spectacular attack on space assets, but through ordinary field infrastructure that can be opened, damaged, bypassed or left insufficiently monitored.
## Where airspace comes in
Aviation enters through the transport sector, where air carriers, airport managing bodies, and air-traffic-management providers all sit within NIS2's scope. The exposure here is conceptually similar to the space case but geographically distributed across thousands of installations: navigation aids, communication and surveillance equipment, perimeter systems, and the field cabinets that house them, scattered across approach paths, airfields, and remote sites.
The legislative momentum is visible in the timing. At the very session in which it approved the KRITIS-Dachgesetz, the Bundesrat also waved through amendments to the Aviation Security Act (Luftsicherheitsgesetz) addressing drone defence and airport security — physical aviation-security measures advancing in step with the broader resilience framework rather than trailing behind it. Air-traffic infrastructure has always been hardened against the obvious threats. What the resilience mandate adds is an expectation that operators can demonstrate a structured view of all the ways a service can be degraded — including the unglamorous, physical, on-site ones that do not show up in a SOC dashboard.
## The shift worth internalising
The instinct, when a cybersecurity directive lands, is to route it to the CISO and treat it as a software and process problem. NIS2 reinforces that instinct. But the KRITIS-Dachgesetz, sitting alongside it, points somewhere the CISO's mandate often does not reach: the physical perimeter of the asset itself.
For space and aviation operators, that combination is the genuinely new thing. Their orbital and airborne assets were always treated as critical. Their ground and field infrastructure was, too often, treated as estate. European law has now placed both inside the same resilience question — and the operators who answer it convincingly will be the ones who stopped drawing a line between the part of the system that flies and the part that is bolted to the ground.
For suppliers, integrators and operators, that means physical anti-tamper measures are no longer just site-security details. They are becoming part of the evidence base for resilience: proof that critical services are protected not only in software, but also at the bolts, cabinets, access points and field installations on which those services ultimately depend.
---
*The regulatory positions described here reflect the German transposition of NIS2 through the NIS2UmsG, in force from 6 December 2025, and the KRITIS-Dachgesetz implementing the EU CER Directive, in force from 17 March 2026. Scope thresholds and detailed obligations under forthcoming implementing rules may continue to evolve; operators should confirm their own classification against current BSI and BBK guidance.*