Skip to content

Services, Wiki-Artikel, Blog-Beiträge und Glossar-Einträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen

Regulation | Critical Infrastructure

KRITIS:
Germany's Critical Infrastructure Security Framework

Hospitals, power plants, water utilities, banks - operators of critical infrastructure in Germany are subject to special security obligations under §31 BSIG. A failure of these systems would endanger millions of people. NIS2 and the KRITIS Umbrella Act further tighten the requirements.

Last updated: March 2026

Regulated Sectors
10
Under BSI KRITIS Ordinance (BSI-KritisV)
Legal Basis
§31 BSIG
Proof obligation every 2 years with BSI
Audit Cycle
2 Years
Audit, certification or assessment
Threshold (typical)
500,000
Supply units (varies by sector)
KRITIS Sectors
10
BSIG Proof Obligation
§8a
Audit Cycle
2 Years
Supply Units (Threshold)
500,000

Fundamentals

What is KRITIS?

KRITIS (Kritische Infrastrukturen) is Germany's designation for critical infrastructure operators - organizations whose failure would cause sustained supply shortages, significant public safety disruptions, or other severe consequences. It is the German national implementation of the EU NIS2 framework, comparable to similar frameworks such as the UK NIS Regulations or the US CISA critical infrastructure program.

In Germany, KRITIS operators are legally defined under the BSI Act (BSIG) and the BSI KRITIS Ordinance (BSI-KritisV). An operator qualifies as KRITIS if it operates in one of ten regulated sectors and exceeds a sector-specific threshold - typically 500,000 supply units (residents, patients, customers).

Critical infrastructure operators are attractive targets for state-sponsored hacking groups, ransomware actors and hacktivists. The BSI Threat Report 2024 shows: hospitals, energy providers and government agencies are preferred attack targets - with potentially life-threatening consequences from successful attacks.

§8a
Technical and Organizational Measures
KRITIS operators must implement appropriate technical and organizational measures (state of the art) to prevent disruptions to the availability, integrity, authenticity and confidentiality of their IT systems essential to their critical services.
§8b
Registration and Reporting Obligations
Mandatory registration with the BSI including designation of a contact point. Significant IT disruptions must be reported to the BSI within 72 hours. The BSI coordinates the response and warns other operators.
§8a(3)
Biennial Proof of Compliance
KRITIS operators must demonstrate every two years that they meet §8a requirements - through security audits, assessments or certifications (e.g., ISO 27001, BSI IT-Grundschutz, B3S sector standards).
IT-SiG 2.0
Attack Detection Systems (SzA)
Since May 2023, KRITIS operators are required to operate attack detection systems (SzA) - in practice SIEM systems with continuous monitoring, typically operated through a SOC or MSSP.

BSI-KritisV

The 10 KRITIS Sectors with Thresholds

The BSI KRITIS Ordinance sets sector-specific thresholds above which an operator qualifies as critical infrastructure. Operators exceeding these thresholds are subject to the obligations under §31 BSIG.

Sector Example Industries Example Threshold
Energy Electricity, gas, district heating, petroleum 420 MW installed net capacity
Water Drinking water, wastewater 500,000 supplied residents
Food Food production and supply 434,500 tons/year
IT & Telecommunications Data centers, carriers, DNS 100,000 customers (IXP)
Health Hospitals, laboratories, pharma 30,000 inpatient cases/year
Finance & Insurance Banks, stock exchanges, payments 15 million transactions/year
Transport & Traffic Aviation, rail, maritime, roads 12 million passengers/year (rail)
Municipal Waste Waste management 500,000 supplied residents
State & Administration Federal agencies, parliaments, judiciary Federal agencies (flat rule)
Media & Culture (KRITIS Umbrella Act) Broadcasting, cultural institutions Not yet finally regulated
Source: BSI KRITIS Ordinance (BSI-KritisV) in the current version. Thresholds vary by service type within each sector. Full thresholds available at gesetze-im-internet.de/bsi-kritisv.

Compliance Obligations

§31 BSIG: Obligations and Accepted Frameworks

§31 BSIG requires KRITIS operators to demonstrate every two years to the BSI that they have implemented appropriate state-of-the-art IT security measures. The BSI accepts various frameworks as evidence.

An ISO 27001 certification is the most internationally recognized proof and is explicitly accepted by the BSI. Alternatively, BSI IT-Grundschutz provides a German, practice-oriented approach with concrete control catalogs. Sector-specific security standards (B3S) complement these general frameworks with sector-specific requirements.

Since May 2023, an additional obligation applies: KRITIS operators must operate attack detection systems (SzA). The BSI has published guidance describing specific requirements for logging, detection, processing and response.

Accepted Compliance Frameworks for §31 BSIG

ISO 27001
International ISMS Standard
Recommended
Explicitly recognized by the BSI. Covers all material §8a requirements. Internationally recognized, ideal for organizations with international operations.
IT-Grundschutz
BSI IT-Grundschutz (Standard Protection)
Recommended
German framework with over 200 specific building blocks. ISO 27001 certificate based on IT-Grundschutz is possible. Particularly common in government agencies and public operators.
B3S
Sector-Specific Security Standards
BSI-approved sector-specific standards (e.g., B3S Hospital, B3S Energy). Complement general standards with sector-specific requirements.
IEC 62443
OT/SCADA Standard for Industrial Systems
Relevant standard for KRITIS operators with Operational Technology (OT) - energy, water, manufacturing. Addresses IT/OT convergence as a critical risk.

Regulatory Development

KRITIS Umbrella Act and NIS2: The New Regulatory Layer

KRITIS and NIS2 are closely linked but not identical. NIS2 substantially expands the circle of regulated entities; the KRITIS Umbrella Act adds physical resilience requirements to existing IT security obligations.

KRITIS Umbrella Act

Physical Security Requirements

The KRITIS Umbrella Act (Germany's implementation of the EU CER Directive EU 2022/2557) supplements the IT security obligations under §31 BSIG with binding physical security requirements. KRITIS operators must now also protect their physical facilities against sabotage and attacks.

  • Perimeter protection: fences, access control, video surveillance
  • Security concepts for critical facilities and operational sites
  • Coordination with authorities (police, domestic intelligence)
  • Binding minimum standards for physical resilience
  • New sectors: space and media/culture
  • Reporting obligations also for physical security incidents
NIS2 Directive

Expanded Scope

NIS2 (EU 2022/2555) - transposed into German law since October 2024 - expands the regulated circle from approximately 2,000 KRITIS operators to up to 30,000 German companies. KRITIS operators are automatically "essential entities" under NIS2.

  • 30,000 instead of 2,000 affected companies in Germany
  • New sectors: cloud, data centers, chemical industry
  • Personal management liability for NIS2 violations
  • Fines up to EUR 10 million or 2% of global turnover
  • 24h early warning + 72h report + 1-month final report
  • Supply chain security obligations towards suppliers

Threat Landscape

Critical Infrastructure as a Prime Attack Target

According to the BSI Threat Report 2024, critical infrastructure operators are prime targets for state-sponsored hacking groups, ransomware actors and hacktivists. The consequences of successful attacks are devastating: power outages, water supply disruptions, operational failures in hospitals.

Particularly critical is the increasing convergence of IT and Operational Technology (OT). Many KRITIS operators use control systems (SCADA, PLCs) that were not originally designed for network connectivity and are now connected to IT networks - creating significant security risks.

High-profile incidents in recent years demonstrate the real damage potential: Landkreis Anhalt-Bitterfeld (2021), Klinikum Dortmund (2023), Viasat hack (2022) affecting European wind farms - KRITIS protection is not an abstract compliance exercise but a societal necessity.

KRITIS in Numbers

10
Regulated sectors under BSI KRITIS Ordinance
~2,000
KRITIS operators in Germany (§31 BSIG)
~30,000
Affected companies after NIS2 expansion
§8a Proof
Every 2 years - audit, certification or assessment
BSI-KritisV 2016
In force since 2016, updated multiple times since
72 Hours
Reporting deadline for significant IT disruptions to BSI
„§31 BSIG is not a bureaucracy project - it demands genuinely effective security measures. As an auditor with §31 BSIG audit qualification, I see in assessments: organizations that treat information security as a strategic goal rather than a compliance checkbox pass the audit by far the best.“

Chris Wojzechowski

Auditor with §31 BSIG Audit Qualification · AWARE7 GmbH

Why AWARE7 for KRITIS Operators

Was uns von anderen Anbietern unterscheidet

Reine Awareness-Plattformen testen keine Systeme. Reine Beratungskonzerne sind zu weit weg. AWARE7 verbindet beides: Wir hacken Ihre Infrastruktur und schulen Ihre Mitarbeiter - mittelstandsgerecht, persönlich, ohne Enterprise-Overhead.

Forschung und Lehre als Fundament

Rund 20% unseres Umsatzes stammen aus Forschungsprojekten für BSI und BMBF. Unsere Studien analysieren Millionen von Websites und Zehntausende Phishing-E-Mails - publiziert auf ACM- und Springer-Konferenzen. Drei unserer Führungskräfte sind gleichzeitig Professoren an deutschen Hochschulen.

Digitale Souveränität - keine Kompromisse

Alle Daten werden ausschließlich in Deutschland gespeichert und verarbeitet - ohne US-Cloud-Anbieter. Keine Freelancer, keine Subunternehmer in der Wertschöpfung. Alle Mitarbeiter sind sozialversicherungspflichtig angestellt und einheitlich rechtlich verpflichtet. Auf Anfrage VS-NfD-konform.

Festpreis in 24h - planbare Projektzeiträume

Innerhalb von 24 Stunden erhalten Sie ein verbindliches Festpreisangebot - kein Stundensatz-Risiko, keine Nachforderungen, keine Überraschungen. Durch eingespieltes Team und standardisierte Prozesse erhalten Sie einen klaren Zeitplan mit definiertem Starttermin und Endtermin.

Ihr fester Ansprechpartner - jederzeit erreichbar

Ein persönlicher Projektleiter begleitet Sie vom Erstgespräch bis zum Re-Test. Sie buchen Termine direkt bei Ihrem Ansprechpartner - keine Ticket-Systeme, kein Callcenter, kein Wechsel zwischen wechselnden Beratern. Kontinuität schafft Vertrauen.

Für wen sind wir der richtige Partner?

Mittelstand mit 50–2.000 MA

Unternehmen, die echte Security brauchen - ohne einen DAX-Konzern-Dienstleister zu bezahlen. Festpreis, klarer Scope, ein Ansprechpartner.

IT-Verantwortliche & CISOs

Die intern überzeugend argumentieren müssen - und dafür einen Bericht mit Vorstandssprache brauchen, nicht nur technische Findings.

Regulierte Branchen

KRITIS, Gesundheitswesen, Finanzdienstleister: NIS-2, ISO 27001, DORA - wir kennen die Anforderungen und liefern Nachweise, die Auditoren akzeptieren.

Mitwirkung an Industriestandards

LLM

OWASP · 2023

OWASP Top 10 for Large Language Models

Prof. Dr. Matteo Große-Kampmann als Contributor im Core-Team des international anerkannten OWASP LLM-Sicherheitsstandards.

BSI

BSI · Allianz für Cyber-Sicherheit

Management von Cyber-Risiken

Prof. Dr. Matteo Große-Kampmann als Mitwirkender des offiziellen BSI-Handbuchs für die Unternehmensleitung (dt. Version).

Frequently Asked Questions about KRITIS

Answers to the most common questions about KRITIS obligations, thresholds, §31 BSIG and NIS2 for critical infrastructure operators.

KRITIS (Kritische Infrastrukturen) is Germany's framework for protecting critical infrastructure operators. Defined by the Federal Office for Information Security (BSI), KRITIS covers organizations whose failure would cause sustained supply shortages, significant disruptions to public safety, or other severe consequences. Operators are legally defined under the BSI Act (BSIG) and the BSI KRITIS Ordinance (BSI-KritisV). KRITIS is Germany's implementation of the EU NIS2 framework at the national level - similar in scope to the UK NIS Regulations or the US CISA Critical Infrastructure framework, but specifically tailored to German law.
The BSI KRITIS Ordinance defines ten sectors as critical infrastructure: (1) Energy: electricity, gas, district heating, petroleum and fuels. (2) Water: drinking water supply and wastewater disposal. (3) Food: food production and supply. (4) IT and Telecommunications: information technology and telecommunications services. (5) Transport and Traffic: aviation, rail, inland waterways, maritime and road transport. (6) Health: hospitals, laboratories, pharmacies and pharmaceutical companies. (7) Finance and Insurance: banks, stock exchanges, insurance companies and payment operators. (8) Municipal Waste Management: waste industry and disposal. (9) State and Administration: federal agencies, parliaments and judiciary. (10) Media and Culture: broadcasting and major cultural institutions.
§8a of the BSI Act (BSIG) requires critical infrastructure operators to implement appropriate organizational and technical measures to prevent disruptions to the availability, integrity, authenticity and confidentiality of their IT systems, components or processes that are essential to the functioning of their critical infrastructure. These measures must comply with the state of the art. KRITIS operators must demonstrate compliance every two years through security audits, assessments or certifications. Proof is submitted to the BSI. There is also a 72-hour mandatory reporting obligation for significant IT disruptions and a mandatory registration requirement with the BSI.
The KRITIS threshold determines from which supply capacity an operator is considered critical infrastructure. It is sector-specific and defined in the BSI KRITIS Ordinance (BSI-KritisV). Most thresholds are set at 500,000 "supply units" - depending on the sector this may be residents, customers, patients, transactions or other metrics. Examples: Energy: 3,700 GWh/year installed generation capacity; Drinking water: 500,000 supplied residents; Health: 30,000 inpatient cases per year; Finance: 15 million transactions/year; IT and telecommunications: 100,000 customers. Organizations should determine their KRITIS status through a structured self-assessment based on the BSI-KritisV.
The KRITIS Umbrella Act (KRITIS-Dachgesetz) is Germany's implementation of the EU CER Directive (EU 2022/2557) on the resilience of critical entities. While §31 BSIG addresses IT security (cybersecurity), the KRITIS Umbrella Act mandates physical security measures: perimeter protection (fences, access control, video surveillance), security concepts for critical facilities, coordination with authorities and law enforcement, and binding minimum standards for physical resilience. The act also expands the circle of regulated entities and introduces new sectors (space, media and culture).
KRITIS and NIS2 are closely interlinked but not identical. KRITIS is the German term for regulated critical infrastructure operators under the BSIG; NIS2 (Directive EU 2022/2555) is the European framework transposed into German law since October 2024. KRITIS operators automatically fall under NIS2 as "essential entities." However, NIS2 goes significantly further than KRITIS: instead of approximately 2,000 KRITIS operators, NIS2 affects up to 30,000 German companies. NIS2 expands the regulated sectors (including cloud providers, data centers, chemical industry) and tightens requirements - particularly through personal management liability. Learn more on our <a href="/en/topics/nis2/" style="color: inherit; text-decoration: underline;">NIS2 topic page</a>.
The BSI accepts various security frameworks as evidence of §31 BSIG compliance: ISO/IEC 27001 (international standard for information security management systems) is the most commonly used and explicitly recognized by the BSI. BSI IT-Grundschutz (baseline or standard protection) is the German approach with detailed control catalogs; an ISO 27001 certification based on IT-Grundschutz is possible. Sector-specific security standards (B3S) are BSI-approved sector-specific standards developed by industry associations - e.g., for hospitals (B3S Hospital) or energy suppliers. IEC 62443 is the relevant standard for OT/SCADA systems in sectors such as energy or water. A combination of these frameworks is possible and often advisable.
AWARE7 supports KRITIS operators with specialized services for the entire §8a compliance cycle: gap analysis against ISO 27001, BSI IT-Grundschutz or sector-specific B3S standards; ISMS implementation and operations; penetration tests and vulnerability scans to verify technical measures; support implementing attack detection systems (SzA/SIEM requirements); preparation for BSI audits and external assessments; NIS2 gap analysis for organizations newly regulated under the directive. Chris Wojzechowski holds the §31 BSIG audit qualification, which is required for certain audit activities in the KRITIS environment.

Prepare Your §31 BSIG Compliance

AWARE7 guides KRITIS operators through the entire compliance cycle - from gap analysis to a successful BSI audit. Chris Wojzechowski holds the §31 BSIG audit qualification.

Kostenlos · 30 Minuten · Unverbindlich