Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen

Regulation | Critical Infrastructure

KRITIS: Germany's Critical Infrastructure Security Framework

Hospitals, power plants, water utilities, banks - operators of critical infrastructure in Germany are subject to special security obligations under §31 BSIG. A failure of these systems would endanger millions of people. NIS2 and the KRITIS Umbrella Act further tighten the requirements.

Last updated: March 2026

10
KRITIS Sectors
§39
BSIG Proof Obligation
3 Years
Audit Cycle
500,000
Supply Units (Threshold)

Fundamentals

What is KRITIS?

KRITIS (Kritische Infrastrukturen) is Germany's designation for critical infrastructure operators - organizations whose failure would cause sustained supply shortages, significant public safety disruptions, or other severe consequences. It is the German national implementation of the EU NIS2 framework, comparable to similar frameworks such as the UK NIS Regulations or the US CISA critical infrastructure program.

In Germany, KRITIS operators are legally defined under the BSI Act (BSIG) and the BSI KRITIS Ordinance (BSI-KritisV). An operator qualifies as KRITIS if it operates in one of ten regulated sectors and exceeds a sector-specific threshold - typically 500,000 supply units (residents, patients, customers).

Critical infrastructure operators are attractive targets for state-sponsored hacking groups, ransomware actors and hacktivists. The BSI Threat Report 2024 shows: hospitals, energy providers and government agencies are preferred attack targets - with potentially life-threatening consequences from successful attacks.

§30/§31
Technical and Organizational Measures
KRITIS operators must implement appropriate technical and organizational measures (state of the art) to prevent disruptions to the availability, integrity, authenticity and confidentiality of their IT systems essential to their critical services.
§32/§33
Registration and Reporting Obligations
Mandatory registration with the BSI including designation of a contact point (§33 BSIG). Significant security incidents must be reported in three stages (§32 BSIG): initial report within 24 hours, follow-up within 72 hours, final report within one month. The BSI coordinates the response and warns other operators.
§39
Triennial Proof of Compliance
KRITIS operators must demonstrate every three years that they meet the §30/§31 BSIG requirements - through security audits, assessments or certifications (e.g., ISO 27001, BSI IT-Grundschutz, B3S sector standards).
IT-SiG 2.0
Attack Detection Systems (SzA)
Since May 2023, KRITIS operators are required to operate attack detection systems (SzA) - in practice SIEM systems with continuous monitoring, typically operated through a SOC or MSSP.

BSI-KritisV

The 10 KRITIS Sectors with Thresholds

The BSI KRITIS Ordinance sets sector-specific thresholds above which an operator qualifies as critical infrastructure. Operators exceeding these thresholds are subject to the obligations under §31 BSIG.

Sector Example Industries Example Threshold
Energy Electricity, gas, district heating, petroleum 420 MW installed net capacity
Water Drinking water, wastewater 500,000 supplied residents
Food Food production and supply 434,500 tons/year
IT & Telecommunications Data centers, carriers, DNS 100,000 customers (IXP)
Health Hospitals, laboratories, pharma 30,000 inpatient cases/year
Finance & Insurance Banks, stock exchanges, payments 15 million transactions/year
Transport & Traffic Aviation, rail, maritime, roads 12 million passengers/year (rail)
Municipal Waste Waste management 500,000 supplied residents
State & Administration Federal agencies, parliaments, judiciary Federal agencies (flat rule)
Media & Culture (KRITIS Umbrella Act) Broadcasting, cultural institutions Not yet finally regulated
Source: BSI KRITIS Ordinance (BSI-KritisV) in the current version. Thresholds vary by service type within each sector. Full thresholds available at gesetze-im-internet.de/bsi-kritisv.

Compliance Obligations

§31 BSIG: Obligations and Accepted Frameworks

§31 BSIG requires KRITIS operators to implement appropriate state-of-the-art IT security measures; under §39 BSIG they must demonstrate this to the BSI every three years. The BSI accepts various frameworks as evidence.

An ISO 27001 certification is the most internationally recognized proof and is explicitly accepted by the BSI. Alternatively, BSI IT-Grundschutz provides a German, practice-oriented approach with concrete control catalogs. Sector-specific security standards (B3S) complement these general frameworks with sector-specific requirements.

Since May 2023, an additional obligation applies: KRITIS operators must operate attack detection systems (SzA). The BSI has published guidance describing specific requirements for logging, detection, processing and response.

Accepted Compliance Frameworks for §31 BSIG

ISO 27001
International ISMS Standard Recommended
Explicitly recognized by the BSI. Covers all material §30/§31 BSIG requirements. Internationally recognized, ideal for organizations with international operations.
IT-Grundschutz
BSI IT-Grundschutz (Standard Protection) Recommended
German framework with over 200 specific building blocks. ISO 27001 certificate based on IT-Grundschutz is possible. Particularly common in government agencies and public operators.
B3S
Sector-Specific Security Standards
BSI-approved sector-specific standards (e.g., B3S Hospital, B3S Energy). Complement general standards with sector-specific requirements.
IEC 62443
OT/SCADA Standard for Industrial Systems
Relevant standard for KRITIS operators with Operational Technology (OT) - energy, water, manufacturing. Addresses IT/OT convergence as a critical risk.

Regulatory Development

KRITIS Umbrella Act and NIS2: The New Regulatory Layer

KRITIS and NIS2 are closely linked but not identical. NIS2 substantially expands the circle of regulated entities; the KRITIS Umbrella Act adds physical resilience requirements to existing IT security obligations.

KRITIS Umbrella Act

Physical Security Requirements

The KRITIS Umbrella Act (Germany's implementation of the EU CER Directive EU 2022/2557) supplements the IT security obligations under §31 BSIG with binding physical security requirements. KRITIS operators must now also protect their physical facilities against sabotage and attacks.

  • Perimeter protection: fences, access control, video surveillance
  • Security concepts for critical facilities and operational sites
  • Coordination with authorities (police, domestic intelligence)
  • Binding minimum standards for physical resilience
  • New sectors: space and media/culture
  • Reporting obligations also for physical security incidents
NIS2 Directive

Expanded Scope

NIS2 (EU 2022/2555) - transposed into German law since October 2024 - expands the regulated circle from approximately 2,000 KRITIS operators to up to 30,000 German companies. KRITIS operators are automatically "essential entities" under NIS2.

  • 30,000 instead of 2,000 affected companies in Germany
  • New sectors: cloud, data centers, chemical industry
  • Personal management liability for NIS2 violations
  • Fines up to EUR 10 million or 2% of global turnover
  • 24h early warning + 72h report + 1-month final report
  • Supply chain security obligations towards suppliers
NIS2 Topic Page

Threat Landscape

Critical Infrastructure as a Prime Attack Target

According to the BSI Threat Report 2024, critical infrastructure operators are prime targets for state-sponsored hacking groups, ransomware actors and hacktivists. The consequences of successful attacks are devastating: power outages, water supply disruptions, operational failures in hospitals.

Particularly critical is the increasing convergence of IT and Operational Technology (OT). Many KRITIS operators use control systems (SCADA, PLCs) that were not originally designed for network connectivity and are now connected to IT networks - creating significant security risks.

High-profile incidents in recent years demonstrate the real damage potential: Landkreis Anhalt-Bitterfeld (2021), Klinikum Dortmund (2023), Viasat hack (2022) affecting European wind farms - KRITIS protection is not an abstract compliance exercise but a societal necessity.

KRITIS in Numbers

10

Regulated sectors under BSI KRITIS Ordinance

~2,000

KRITIS operators in Germany (§31 BSIG)

~30,000

Affected companies after NIS2 expansion

§39 Proof

Every 3 years - audit, certification or assessment

BSI-KritisV 2016

In force since 2016, updated multiple times since

72 Hours

Reporting deadline for significant IT disruptions to BSI

„§31 BSIG is not a bureaucracy project - it demands genuinely effective security measures. As an auditor with additional audit procedure competence under Section 8a BSIG, I see in assessments: organizations that treat information security as a strategic goal rather than a compliance checkbox pass the audit by far the best.“

Chris Wojzechowski

Auditor with additional audit procedure competence (Section 8a BSIG) · AWARE7 GmbH

Why AWARE7 for KRITIS Operators

What sets us apart from other providers

Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.

01

Research and teaching as our foundation

20 %

Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.

02

Digital sovereignty: no compromises

100 %

From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.

More on digital sovereignty
03

Fixed price within 24h: predictable project timelines

24 h

Within 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.

04

Your dedicated contact

1:1

A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.

Peer-reviewed publications

First page of the paper: Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations

Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations

ACM AsiaCCS 2025

Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

First page of the paper: A Platform for Physiological and Behavioral Security

A Platform for Physiological and Behavioral Security

NSPW 2025

Jan Hörnemann

First page of the paper: Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem

Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem

IEEE/IFIP DSN 2025

Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

First page of the paper: Understanding Regional Filter Lists: Efficacy and Impact

Understanding Regional Filter Lists: Efficacy and Impact

PoPETS 2025

Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

Who is AWARE7 the right partner for?

Mid-sized companies with 50-2,000 employees

Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.

IT managers & CISOs

Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.

Regulated industries

Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.

Frequently Asked Questions about KRITIS

Answers to the most common questions about KRITIS obligations, thresholds, §31 BSIG and NIS2 for critical infrastructure operators.

KRITIS (Kritische Infrastrukturen) is Germany's framework for protecting critical infrastructure operators. Defined by the Federal Office for Information Security (BSI), KRITIS covers organizations whose failure would cause sustained supply shortages, significant disruptions to public safety, or other severe consequences. Operators are legally defined under the BSI Act (BSIG) and the BSI KRITIS Ordinance (BSI-KritisV). KRITIS is Germany's implementation of the EU NIS2 framework at the national level - similar in scope to the UK NIS Regulations or the US CISA Critical Infrastructure framework, but specifically tailored to German law.
The BSI KRITIS Ordinance defines ten sectors as critical infrastructure: (1) Energy: electricity, gas, district heating, petroleum and fuels. (2) Water: drinking water supply and wastewater disposal. (3) Food: food production and supply. (4) IT and Telecommunications: information technology and telecommunications services. (5) Transport and Traffic: aviation, rail, inland waterways, maritime and road transport. (6) Health: hospitals, laboratories, pharmacies and pharmaceutical companies. (7) Finance and Insurance: banks, stock exchanges, insurance companies and payment operators. (8) Municipal Waste Management: waste industry and disposal. (9) State and Administration: federal agencies, parliaments and judiciary. (10) Media and Culture: broadcasting and major cultural institutions.
§31 BSIG (in conjunction with §30 BSIG) requires critical infrastructure operators to implement appropriate organizational and technical measures to prevent disruptions to the availability, integrity, authenticity and confidentiality of their IT systems, components or processes that are essential to the functioning of their critical infrastructure. These measures must comply with the state of the art. Under §39 BSIG, KRITIS operators must demonstrate compliance every three years through security audits, assessments or certifications. Proof is submitted to the BSI. Significant security incidents must be reported in three stages (§32 BSIG: initial report within 24 hours, follow-up within 72 hours, final report within one month), and registration with the BSI is mandatory (§33 BSIG).
The KRITIS threshold determines from which supply capacity an operator is considered critical infrastructure. It is sector-specific and defined in the BSI KRITIS Ordinance (BSI-KritisV). Most thresholds are set at 500,000 "supply units" - depending on the sector this may be residents, customers, patients, transactions or other metrics. Examples: Energy: 3,700 GWh/year installed generation capacity; Drinking water: 500,000 supplied residents; Health: 30,000 inpatient cases per year; Finance: 15 million transactions/year; IT and telecommunications: 100,000 customers. Organizations should determine their KRITIS status through a structured self-assessment based on the BSI-KritisV.
The KRITIS Umbrella Act (KRITIS-Dachgesetz) is Germany's implementation of the EU CER Directive (EU 2022/2557) on the resilience of critical entities. While §31 BSIG addresses IT security (cybersecurity), the KRITIS Umbrella Act mandates physical security measures: perimeter protection (fences, access control, video surveillance), security concepts for critical facilities, coordination with authorities and law enforcement, and binding minimum standards for physical resilience. The act also expands the circle of regulated entities and introduces new sectors (space, media and culture).
KRITIS and NIS2 are closely interlinked but not identical. KRITIS is the German term for regulated critical infrastructure operators under the BSIG; NIS2 (Directive EU 2022/2555) is the European framework transposed into German law by the NIS2UmsuCG, in force since 6 December 2025 (the EU deadline of October 2024 was missed by Germany). KRITIS operators automatically fall under NIS2 as "essential entities." However, NIS2 goes significantly further than KRITIS: instead of approximately 2,000 KRITIS operators, NIS2 affects up to 30,000 German companies. NIS2 expands the regulated sectors (including cloud providers, data centers, chemical industry) and tightens requirements - particularly through personal management liability. Learn more on our NIS2 topic page at /en/topics/nis2/.
The BSI accepts various security frameworks as evidence of §31 BSIG compliance: ISO/IEC 27001 (international standard for information security management systems) is the most commonly used and explicitly recognized by the BSI. BSI IT-Grundschutz (baseline or standard protection) is the German approach with detailed control catalogs; an ISO 27001 certification based on IT-Grundschutz is possible. Sector-specific security standards (B3S) are BSI-approved sector-specific standards developed by industry associations - e.g., for hospitals (B3S Hospital) or energy suppliers. IEC 62443 is the relevant standard for OT/SCADA systems in sectors such as energy or water. A combination of these frameworks is possible and often advisable.
AWARE7 supports KRITIS operators with specialized services for the entire Section 39 BSIG compliance cycle: gap analysis against ISO 27001, BSI IT-Grundschutz or sector-specific B3S standards; ISMS implementation and operations; penetration tests and vulnerability scans to verify technical measures; support implementing attack detection systems (SzA/SIEM requirements); preparation for BSI audits and external assessments; NIS2 gap analysis for organizations newly regulated under the directive. Chris Wojzechowski holds the additional audit procedure competence (Section 8a BSIG) for KRITIS compliance audits, which are now governed by Section 39 BSIG.

Prepare Your §31 BSIG Compliance

AWARE7 guides KRITIS operators through the entire compliance cycle - from gap analysis to a successful BSI audit. Chris Wojzechowski holds the additional audit procedure competence (Section 8a BSIG).

Free · 30 minutes · No obligation

Rufen Sie uns an

Mo-Fr, 8:00-17:00 Uhr - persönlich und unverbindlich.

0209 8830 6764
Jetzt anrufen