September 1, 2026 showed how exposed substations are.
On that day, confirmed attacks hit high-voltage grid assets: in Turnow-Preilack near the Jänschwalde lignite power plant in Brandenburg and at the Amprion Rommerskirchen substation in the Bergheim district of Rheidt, North Rhine-Westphalia. According to reporting, simple means were enough to trigger protection systems and temporarily disconnect large generation capacities from the grid [18].
The incident of September 1, 2026 at substations in Brandenburg and North Rhine-Westphalia illustrates the core thesis of this article: the physical and digital attack surfaces of critical infrastructure are now the same. Treating them separately protects only half of the asset. In Bergheim, five power plant units had to be taken off the grid, and the NRW interior minister spoke of an initial suspicion of anti-constitutional sabotage [20]. Anyone protecting substations therefore has to consider grid control technology, telecontrol technology and the supply chain together. That is where this article starts.
What changes in 2026 for critical infrastructure operators under NIS-2 and tighter BSI oversight?
The circle of regulated entities is growing significantly, and the BSI is stepping up oversight from 2026 [14][15]. NIS2 expands the scope massively: instead of a few thousand critical infrastructure operators, an estimated tens of thousands of companies fall under the obligations. Affected sectors include energy, transport, health, digital infrastructure, wastewater, food and parts of manufacturing [13]. A structured introduction to implementation is provided by the NIS-2 implementation overview.
The BSI-KritisV, the ordinance that defines critical infrastructure, was last amended by Article 3 (1) of the law of May 15, 2026 [19]. The BSI has also published an NIS-2 information package on security measures for procurement, development and vulnerability management [12]. For affected organisations, that means the requirements are concrete enough to translate into projects.
What deadlines apply when reporting significant security incidents to the BSI?
Significant security incidents must be reported to the BSI, with an initial report within 24 hours and staged follow-up reports [17]. Under NIS2, affected entities face many information and reporting duties that go beyond the previous KRITIS reporting obligations [17]. A process template for BSI reporting duties 24h/72h helps prepare the reporting chain.
In parallel, the reporting duties of the EU Cyber Resilience Act (CRA) apply. The Cyber Resilience Act (EU 2024/2847) is the first European regulation to set a minimum level of cybersecurity for all connected products on the EU market [6]. Since September 11, 2026, manufacturers must report actively exploited vulnerabilities to ENISA and the responsible national CSIRT within 24 hours; the vulnerability report follows within 72 hours at the latest, and the final report must be submitted within 14 days [10].
The following overview consolidates the key deadlines:
- Initial report of significant security incidents to the BSI: within 24 hours, staged follow-up reports, legal basis NIS2 reporting duties [17].
- Report of actively exploited vulnerabilities to ENISA and the national CSIRT: within 24 hours, legal basis CRA Article 14 [10].
- Vulnerability report (second stage) under the CRA: within 72 hours at the latest, legal basis CRA Article 14 [10].
- Final report under the CRA: within 14 days, legal basis CRA Article 14 [10].
- CRA reporting duties under Article 14 apply from September 11, 2026 [9].
- CRA Chapter IV on the notification of conformity assessment bodies applies from June 11, 2026 [9].
- Full applicability of the CRA: from December 11, 2027 [9].
- Entry into force of the CRA: December 10, 2024 [2].
Our position: reporting duties are not a paperwork format. Twenty-four hours to the initial report and 72 hours to the vulnerability report require prepared processes, clear roles and rehearsed procedures, not improvised emails at night. If you read the deadlines for the first time during an incident, you have already missed them.
When does a company count as a regulated entity under NIS2?
A company is subject to NIS2 when both conditions are met cumulatively: at least 50 employees and more than 10 million euros in annual revenue (or a balance sheet total above 10 million euros), plus membership in one of the covered sectors such as energy, transport, health, digital infrastructure, wastewater, food or parts of manufacturing [13]. Where the line between classic KRITIS and NIS2 runs is explained in the KRITIS vs. NIS-2 comparison.
This combination explains why the scope grows so much. Many companies have not seen themselves as part of critical infrastructure, even though they are directly connected to it through supply chains, software or maintenance access. A manufacturer of connected components for grid technology is one example.
The CRA adds further pressure. Manufacturers must assess cybersecurity risks, develop products according to the essential requirements, address vulnerabilities, provide security updates over the support period, create technical documentation, carry out the conformity assessment, issue an EU declaration of conformity and affix the CE marking [4]. The CRA entered into force on December 10, 2024; from December 2027, manufacturers, importers and distributors must meet strict requirements, from updates and reporting duties to CE marking [2].
For the security industry, this brings a noticeable shift: from 2027, strict EU rules apply to manufacturers and installers of security products [5]. The draft to strengthen cyber protection for critical infrastructure foresees mandatory risk analyses and incident reporting [11].
Why are substations and grid control technology a realistic target?
Substations are a realistic attack target because concentrating generation and distribution at a few points achieves a large effect with simple means: on September 1, 2026, according to reporting, simple means were enough to disconnect five power plant units in Bergheim from the grid [18][20].
What matters is the link between the physical and digital layers. Grid control technology manages switching states, while telecontrol technology transmits measurements and commands between the control centre and the asset. Anyone who gains access there can influence operations without loosening a single bolt. Raising fences and adding cameras is therefore not enough.
The supply chain adds another dimension. Maintenance access, remote maintenance software and third-party components are part of the attack surface. An attack does not have to start at the substation; it can find its way there through an update, a certificate or an account.
Our position: resilience comes from architecture, not from regulation alone. Zero trust, secure identities and post-quantum cryptography belong in the same roadmap as the reporting duties.
Which technical measures support NIS-2 obligations?
Four building blocks map directly onto NIS2 and CRA duties: zero trust, secure digital identities, post-quantum cryptography and disciplined vulnerability management. The BSI Congress 2026 addressed exactly these topics along with NIS-2 implementation; one focus was integrating human behaviour more strongly into security concepts [16].
- Zero trust: No access is trusted based on network position alone. Every request is verified, every access is limited and traceable. NIS2 explicitly names such access controls and the protection of communications as minimum measures in Article 21. For grid control technology, that means separated zones, clear boundaries and logs that stand out when a command does not fit the pattern. How this is implemented architecturally is described in the zero trust architecture.
- Secure digital identities: They ensure that people and machines are clearly identifiable. In telecontrol technology this is demanding, because devices typically stay in the field for 10 to 20 years and are rarely updated. The effort still pays off, because without reliable identity any access control remains patchwork.
- Post-quantum cryptography: It belongs in long-term planning, because cryptography has long lifecycles; whoever defines procurement and protocols today decides the security of the coming decades. The BSI has published an NIS-2 information package on security measures for procurement, development and vulnerability management [12]. A practical starting point is the post-quantum cryptography migration guide.
- Vulnerability management: It closes the loop. If you know which components are in use, you can assess vulnerabilities and meet deadlines. Without an inventory, every report becomes guesswork. A vulnerability management framework provides the necessary structure.
Post-quantum cryptography (quantum-safe cryptography) refers to cryptographic methods designed to withstand attacks by future quantum computers with a sufficiently large number of qubits.
Because cryptography remains in use for decades, today's procurement and protocol choices decide the security of the coming decades. The BSI has published an NIS-2 information package on security measures for procurement, development and vulnerability management [12].
What does a resilient roadmap look like?
A resilient roadmap connects three strands: exercises, roles and documentation. Exercises test the reporting chain before it is needed. Roles define who decides, who reports and who communicates externally. Documentation records what happened and when, so deadlines and evidence line up.
We consider it sensible to start with the reporting path, because it carries the shortest deadline. Twenty-four hours to the initial report leaves little room for coordination. Keeping a prepared skeleton for the initial report buys time for the substantive assessment.
Architecture comes next. Zero trust, secure identities and post-quantum cryptography are not isolated projects but a sequence of decisions. Putting them in the same roadmap as the reporting duties avoids contradictions between operations, procurement and compliance.
The incidents of September 1, 2026 show why this is urgent. Attacks on substations affect not only assets but also supply and trust [18][20]. Mountain Road supports organisations in bringing reporting duties and architecture together, insofar as permitted and within the applicable requirements.