Regulation | Critical Infrastructure
KRITIS: Germany's Critical Infrastructure Security Framework
Hospitals, power plants, water utilities, banks - operators of critical infrastructure in Germany are subject to special security obligations under §31 BSIG. A failure of these systems would endanger millions of people. NIS2 and the KRITIS Umbrella Act further tighten the requirements.
Last updated: March 2026
- 10
- KRITIS Sectors
- §39
- BSIG Proof Obligation
- 3 Years
- Audit Cycle
- 500,000
- Supply Units (Threshold)
Fundamentals
What is KRITIS?
KRITIS (Kritische Infrastrukturen) is Germany's designation for critical infrastructure operators - organizations whose failure would cause sustained supply shortages, significant public safety disruptions, or other severe consequences. It is the German national implementation of the EU NIS2 framework, comparable to similar frameworks such as the UK NIS Regulations or the US CISA critical infrastructure program.
In Germany, KRITIS operators are legally defined under the BSI Act (BSIG) and the BSI KRITIS Ordinance (BSI-KritisV). An operator qualifies as KRITIS if it operates in one of ten regulated sectors and exceeds a sector-specific threshold - typically 500,000 supply units (residents, patients, customers).
Critical infrastructure operators are attractive targets for state-sponsored hacking groups, ransomware actors and hacktivists. The BSI Threat Report 2024 shows: hospitals, energy providers and government agencies are preferred attack targets - with potentially life-threatening consequences from successful attacks.
BSI-KritisV
The 10 KRITIS Sectors with Thresholds
The BSI KRITIS Ordinance sets sector-specific thresholds above which an operator qualifies as critical infrastructure. Operators exceeding these thresholds are subject to the obligations under §31 BSIG.
| Sector | Example Industries | Example Threshold |
|---|---|---|
| Energy | Electricity, gas, district heating, petroleum | 420 MW installed net capacity |
| Water | Drinking water, wastewater | 500,000 supplied residents |
| Food | Food production and supply | 434,500 tons/year |
| IT & Telecommunications | Data centers, carriers, DNS | 100,000 customers (IXP) |
| Health | Hospitals, laboratories, pharma | 30,000 inpatient cases/year |
| Finance & Insurance | Banks, stock exchanges, payments | 15 million transactions/year |
| Transport & Traffic | Aviation, rail, maritime, roads | 12 million passengers/year (rail) |
| Municipal Waste | Waste management | 500,000 supplied residents |
| State & Administration | Federal agencies, parliaments, judiciary | Federal agencies (flat rule) |
| Media & Culture (KRITIS Umbrella Act) | Broadcasting, cultural institutions | Not yet finally regulated |
Compliance Obligations
§31 BSIG: Obligations and Accepted Frameworks
§31 BSIG requires KRITIS operators to implement appropriate state-of-the-art IT security measures; under §39 BSIG they must demonstrate this to the BSI every three years. The BSI accepts various frameworks as evidence.
An ISO 27001 certification is the most internationally recognized proof and is explicitly accepted by the BSI. Alternatively, BSI IT-Grundschutz provides a German, practice-oriented approach with concrete control catalogs. Sector-specific security standards (B3S) complement these general frameworks with sector-specific requirements.
Since May 2023, an additional obligation applies: KRITIS operators must operate attack detection systems (SzA). The BSI has published guidance describing specific requirements for logging, detection, processing and response.
Accepted Compliance Frameworks for §31 BSIG
Regulatory Development
KRITIS Umbrella Act and NIS2: The New Regulatory Layer
KRITIS and NIS2 are closely linked but not identical. NIS2 substantially expands the circle of regulated entities; the KRITIS Umbrella Act adds physical resilience requirements to existing IT security obligations.
Physical Security Requirements
The KRITIS Umbrella Act (Germany's implementation of the EU CER Directive EU 2022/2557) supplements the IT security obligations under §31 BSIG with binding physical security requirements. KRITIS operators must now also protect their physical facilities against sabotage and attacks.
- Perimeter protection: fences, access control, video surveillance
- Security concepts for critical facilities and operational sites
- Coordination with authorities (police, domestic intelligence)
- Binding minimum standards for physical resilience
- New sectors: space and media/culture
- Reporting obligations also for physical security incidents
Expanded Scope
NIS2 (EU 2022/2555) - transposed into German law since October 2024 - expands the regulated circle from approximately 2,000 KRITIS operators to up to 30,000 German companies. KRITIS operators are automatically "essential entities" under NIS2.
- 30,000 instead of 2,000 affected companies in Germany
- New sectors: cloud, data centers, chemical industry
- Personal management liability for NIS2 violations
- Fines up to EUR 10 million or 2% of global turnover
- 24h early warning + 72h report + 1-month final report
- Supply chain security obligations towards suppliers
Threat Landscape
Critical Infrastructure as a Prime Attack Target
According to the BSI Threat Report 2024, critical infrastructure operators are prime targets for state-sponsored hacking groups, ransomware actors and hacktivists. The consequences of successful attacks are devastating: power outages, water supply disruptions, operational failures in hospitals.
Particularly critical is the increasing convergence of IT and Operational Technology (OT). Many KRITIS operators use control systems (SCADA, PLCs) that were not originally designed for network connectivity and are now connected to IT networks - creating significant security risks.
High-profile incidents in recent years demonstrate the real damage potential: Landkreis Anhalt-Bitterfeld (2021), Klinikum Dortmund (2023), Viasat hack (2022) affecting European wind farms - KRITIS protection is not an abstract compliance exercise but a societal necessity.
KRITIS in Numbers
Regulated sectors under BSI KRITIS Ordinance
KRITIS operators in Germany (§31 BSIG)
Affected companies after NIS2 expansion
Every 3 years - audit, certification or assessment
In force since 2016, updated multiple times since
Reporting deadline for significant IT disruptions to BSI
„§31 BSIG is not a bureaucracy project - it demands genuinely effective security measures. As an auditor with additional audit procedure competence under Section 8a BSIG, I see in assessments: organizations that treat information security as a strategic goal rather than a compliance checkbox pass the audit by far the best.“
Chris Wojzechowski
Auditor with additional audit procedure competence (Section 8a BSIG) · AWARE7 GmbH
Why AWARE7 for KRITIS Operators
What sets us apart from other providers
Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.
Research and teaching as our foundation
20 %Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.
Digital sovereignty: no compromises
100 %From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.
More on digital sovereigntyFixed price within 24h: predictable project timelines
24 hWithin 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.
Your dedicated contact
1:1A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.
Peer-reviewed publications
Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations
ACM AsiaCCS 2025
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
A Platform for Physiological and Behavioral Security
NSPW 2025
Jan Hörnemann
Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem
IEEE/IFIP DSN 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Understanding Regional Filter Lists: Efficacy and Impact
PoPETS 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Who is AWARE7 the right partner for?
Mid-sized companies with 50-2,000 employees
Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.
IT managers & CISOs
Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.
Regulated industries
Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.
Frequently Asked Questions about KRITIS
Answers to the most common questions about KRITIS obligations, thresholds, §31 BSIG and NIS2 for critical infrastructure operators.
What is KRITIS - Germany's Critical Infrastructure regulation?
Which 10 sectors fall under KRITIS?
What does §31 BSIG require of critical infrastructure operators?
How is the KRITIS threshold determined?
What is the KRITIS Umbrella Act (KRITIS-DachG)?
How are KRITIS and NIS2 related?
Which frameworks are accepted as §39 BSIG proof of compliance?
How does AWARE7 support KRITIS operators?
Aus dem Blog
Weiterführende Artikel
Browser-Härtung: Sicherheitsrichtlinien für Chrome, Edge und Firefox
Browser-Sicherheit per GPO/Intune: Extensions-Management, HTTPS-Only, Browser-Isolation (RBI) und Abwehr von Malvertising und Drive-by-Downloads.
10 häufige Fehler bei Informationssicherheits-Schulungen vermeiden
Vermeiden Sie die häufigsten Fehler bei Mitarbeiterschulungen zur Informationssicherheit und stärken Sie Ihre Sicherheitskultur nachhaltig
Security Key für $20: Wie Google Phishing vollständig eliminiert hat
Phishing Kampagnen sind für Google kein Problem mehr. Ein Security Key im Wert von $20 schützt die Unternehmenssicherheit bei Google ab sofort.
Prepare Your §31 BSIG Compliance
AWARE7 guides KRITIS operators through the entire compliance cycle - from gap analysis to a successful BSI audit. Chris Wojzechowski holds the additional audit procedure competence (Section 8a BSIG).
Free · 30 minutes · No obligation