Regulation | Critical Infrastructure
KRITIS:
Germany's Critical Infrastructure Security Framework
Hospitals, power plants, water utilities, banks - operators of critical infrastructure in Germany are subject to special security obligations under §31 BSIG. A failure of these systems would endanger millions of people. NIS2 and the KRITIS Umbrella Act further tighten the requirements.
Last updated: March 2026
- KRITIS Sectors
- 10
- BSIG Proof Obligation
- §8a
- Audit Cycle
- 2 Years
- Supply Units (Threshold)
- 500,000
Fundamentals
What is KRITIS?
KRITIS (Kritische Infrastrukturen) is Germany's designation for critical infrastructure operators - organizations whose failure would cause sustained supply shortages, significant public safety disruptions, or other severe consequences. It is the German national implementation of the EU NIS2 framework, comparable to similar frameworks such as the UK NIS Regulations or the US CISA critical infrastructure program.
In Germany, KRITIS operators are legally defined under the BSI Act (BSIG) and the BSI KRITIS Ordinance (BSI-KritisV). An operator qualifies as KRITIS if it operates in one of ten regulated sectors and exceeds a sector-specific threshold - typically 500,000 supply units (residents, patients, customers).
Critical infrastructure operators are attractive targets for state-sponsored hacking groups, ransomware actors and hacktivists. The BSI Threat Report 2024 shows: hospitals, energy providers and government agencies are preferred attack targets - with potentially life-threatening consequences from successful attacks.
BSI-KritisV
The 10 KRITIS Sectors with Thresholds
The BSI KRITIS Ordinance sets sector-specific thresholds above which an operator qualifies as critical infrastructure. Operators exceeding these thresholds are subject to the obligations under §31 BSIG.
| Sector | Example Industries | Example Threshold |
|---|---|---|
| Energy | Electricity, gas, district heating, petroleum | 420 MW installed net capacity |
| Water | Drinking water, wastewater | 500,000 supplied residents |
| Food | Food production and supply | 434,500 tons/year |
| IT & Telecommunications | Data centers, carriers, DNS | 100,000 customers (IXP) |
| Health | Hospitals, laboratories, pharma | 30,000 inpatient cases/year |
| Finance & Insurance | Banks, stock exchanges, payments | 15 million transactions/year |
| Transport & Traffic | Aviation, rail, maritime, roads | 12 million passengers/year (rail) |
| Municipal Waste | Waste management | 500,000 supplied residents |
| State & Administration | Federal agencies, parliaments, judiciary | Federal agencies (flat rule) |
| Media & Culture (KRITIS Umbrella Act) | Broadcasting, cultural institutions | Not yet finally regulated |
Compliance Obligations
§31 BSIG: Obligations and Accepted Frameworks
§31 BSIG requires KRITIS operators to demonstrate every two years to the BSI that they have implemented appropriate state-of-the-art IT security measures. The BSI accepts various frameworks as evidence.
An ISO 27001 certification is the most internationally recognized proof and is explicitly accepted by the BSI. Alternatively, BSI IT-Grundschutz provides a German, practice-oriented approach with concrete control catalogs. Sector-specific security standards (B3S) complement these general frameworks with sector-specific requirements.
Since May 2023, an additional obligation applies: KRITIS operators must operate attack detection systems (SzA). The BSI has published guidance describing specific requirements for logging, detection, processing and response.
Accepted Compliance Frameworks for §31 BSIG
Regulatory Development
KRITIS Umbrella Act and NIS2: The New Regulatory Layer
KRITIS and NIS2 are closely linked but not identical. NIS2 substantially expands the circle of regulated entities; the KRITIS Umbrella Act adds physical resilience requirements to existing IT security obligations.
Physical Security Requirements
The KRITIS Umbrella Act (Germany's implementation of the EU CER Directive EU 2022/2557) supplements the IT security obligations under §31 BSIG with binding physical security requirements. KRITIS operators must now also protect their physical facilities against sabotage and attacks.
- Perimeter protection: fences, access control, video surveillance
- Security concepts for critical facilities and operational sites
- Coordination with authorities (police, domestic intelligence)
- Binding minimum standards for physical resilience
- New sectors: space and media/culture
- Reporting obligations also for physical security incidents
Expanded Scope
NIS2 (EU 2022/2555) - transposed into German law since October 2024 - expands the regulated circle from approximately 2,000 KRITIS operators to up to 30,000 German companies. KRITIS operators are automatically "essential entities" under NIS2.
- 30,000 instead of 2,000 affected companies in Germany
- New sectors: cloud, data centers, chemical industry
- Personal management liability for NIS2 violations
- Fines up to EUR 10 million or 2% of global turnover
- 24h early warning + 72h report + 1-month final report
- Supply chain security obligations towards suppliers
Threat Landscape
Critical Infrastructure as a Prime Attack Target
According to the BSI Threat Report 2024, critical infrastructure operators are prime targets for state-sponsored hacking groups, ransomware actors and hacktivists. The consequences of successful attacks are devastating: power outages, water supply disruptions, operational failures in hospitals.
Particularly critical is the increasing convergence of IT and Operational Technology (OT). Many KRITIS operators use control systems (SCADA, PLCs) that were not originally designed for network connectivity and are now connected to IT networks - creating significant security risks.
High-profile incidents in recent years demonstrate the real damage potential: Landkreis Anhalt-Bitterfeld (2021), Klinikum Dortmund (2023), Viasat hack (2022) affecting European wind farms - KRITIS protection is not an abstract compliance exercise but a societal necessity.
KRITIS in Numbers
„§31 BSIG is not a bureaucracy project - it demands genuinely effective security measures. As an auditor with §31 BSIG audit qualification, I see in assessments: organizations that treat information security as a strategic goal rather than a compliance checkbox pass the audit by far the best.“
Chris Wojzechowski
Auditor with §31 BSIG Audit Qualification · AWARE7 GmbH
Why AWARE7 for KRITIS Operators
Was uns von anderen Anbietern unterscheidet
Reine Awareness-Plattformen testen keine Systeme. Reine Beratungskonzerne sind zu weit weg. AWARE7 verbindet beides: Wir hacken Ihre Infrastruktur und schulen Ihre Mitarbeiter - mittelstandsgerecht, persönlich, ohne Enterprise-Overhead.
Forschung und Lehre als Fundament
Rund 20% unseres Umsatzes stammen aus Forschungsprojekten für BSI und BMBF. Unsere Studien analysieren Millionen von Websites und Zehntausende Phishing-E-Mails - publiziert auf ACM- und Springer-Konferenzen. Drei unserer Führungskräfte sind gleichzeitig Professoren an deutschen Hochschulen.
Digitale Souveränität - keine Kompromisse
Alle Daten werden ausschließlich in Deutschland gespeichert und verarbeitet - ohne US-Cloud-Anbieter. Keine Freelancer, keine Subunternehmer in der Wertschöpfung. Alle Mitarbeiter sind sozialversicherungspflichtig angestellt und einheitlich rechtlich verpflichtet. Auf Anfrage VS-NfD-konform.
Festpreis in 24h - planbare Projektzeiträume
Innerhalb von 24 Stunden erhalten Sie ein verbindliches Festpreisangebot - kein Stundensatz-Risiko, keine Nachforderungen, keine Überraschungen. Durch eingespieltes Team und standardisierte Prozesse erhalten Sie einen klaren Zeitplan mit definiertem Starttermin und Endtermin.
Ihr fester Ansprechpartner - jederzeit erreichbar
Ein persönlicher Projektleiter begleitet Sie vom Erstgespräch bis zum Re-Test. Sie buchen Termine direkt bei Ihrem Ansprechpartner - keine Ticket-Systeme, kein Callcenter, kein Wechsel zwischen wechselnden Beratern. Kontinuität schafft Vertrauen.
Für wen sind wir der richtige Partner?
Mittelstand mit 50–2.000 MA
Unternehmen, die echte Security brauchen - ohne einen DAX-Konzern-Dienstleister zu bezahlen. Festpreis, klarer Scope, ein Ansprechpartner.
IT-Verantwortliche & CISOs
Die intern überzeugend argumentieren müssen - und dafür einen Bericht mit Vorstandssprache brauchen, nicht nur technische Findings.
Regulierte Branchen
KRITIS, Gesundheitswesen, Finanzdienstleister: NIS-2, ISO 27001, DORA - wir kennen die Anforderungen und liefern Nachweise, die Auditoren akzeptieren.
Mitwirkung an Industriestandards
OWASP · 2023
OWASP Top 10 for Large Language Models
Prof. Dr. Matteo Große-Kampmann als Contributor im Core-Team des international anerkannten OWASP LLM-Sicherheitsstandards.
BSI · Allianz für Cyber-Sicherheit
Management von Cyber-Risiken
Prof. Dr. Matteo Große-Kampmann als Mitwirkender des offiziellen BSI-Handbuchs für die Unternehmensleitung (dt. Version).
Frequently Asked Questions about KRITIS
Answers to the most common questions about KRITIS obligations, thresholds, §31 BSIG and NIS2 for critical infrastructure operators.
What is KRITIS - Germany's Critical Infrastructure regulation?
Which 10 sectors fall under KRITIS?
What does §31 BSIG require of critical infrastructure operators?
How is the KRITIS threshold determined?
What is the KRITIS Umbrella Act (KRITIS-DachG)?
How are KRITIS and NIS2 related?
Which frameworks are accepted as §8a proof of compliance?
How does AWARE7 support KRITIS operators?
Aus dem Blog
Weiterführende Artikel
Alle ArtikelPrepare Your §31 BSIG Compliance
AWARE7 guides KRITIS operators through the entire compliance cycle - from gap analysis to a successful BSI audit. Chris Wojzechowski holds the §31 BSIG audit qualification.
Kostenlos · 30 Minuten · Unverbindlich