Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryComplianceOT

KRITIS

KRITIS means critical infrastructures: facilities in Germany whose failure would cause supply shortages. Who counts, what the BSIG requires and what changed with NIS2.

Updated This page as Markdown

In short

KRITIS is the German term for critical infrastructures: organisations and facilities in sectors such as energy, water, health, transport, food, finance and IT whose failure would cause serious supply shortages or threaten public safety. Which facilities count is set by thresholds in the BSI-KritisV. Since the NIS2 implementation, the BSIG calls them operators of critical facilities (Betreiber kritischer Anlagen) and requires state-of-the-art security, attack detection systems, incident reporting, registration and proof to the BSI every three years.

What is KRITIS?

KRITIS is the German abbreviation for Kritische Infrastrukturen, critical infrastructures. These are organisations and facilities of major importance for society whose failure or impairment would result in sustained supply shortages, significant disruption of public safety or other dramatic consequences. The sectors in the BSI-KritisV are energy, water, food, information technology and telecommunications, health, finance and insurance, transport and traffic, and municipal waste disposal.

Not every company in those sectors is KRITIS. The BSI-KritisV defines facility types and thresholds per sector, usually derived from supplying 500,000 people. A utility below the threshold is not KRITIS, although it may be covered by the NIS2 rules anyway.

Where is it defined?

The legal basis is the BSIG, the Act on the Federal Office for Information Security, as rewritten by Germany’s NIS2 implementation act. The new BSIG uses the term operators of critical facilities (Betreiber kritischer Anlagen) and counts them among the particularly important entities (section 28(1)). The thresholds remain in the BSI-KritisV.

The core duties:

  • Risk management measures (section 30) that follow the catalogue of Article 21 NIS2: risk analysis, incident handling, business continuity, supply chain security, secure acquisition and development, effectiveness assessment, training, cryptography, access control and multi-factor authentication.
  • Special requirements for critical facilities (section 31): measures beyond the normal level are proportionate when the effort is not out of proportion to the consequences of a failure, and attack detection systems are mandatory for the systems that keep the facility running.
  • Reporting and registration (sections 32 and 33) with the BSI as the central contact.
  • Proof (section 39): operators prove implementation through security audits, tests or certifications every three years and submit the results, including the deficiencies found.

Physical resilience is regulated separately: the CER Directive (EU) 2022/2557 and its German implementation in the KRITIS-Dachgesetz cover protection against physical and natural hazards.

What it means in practice

Most KRITIS facilities are run by operational technology: SCADA systems in grid control rooms, PLCs in waterworks, building and medical technology in hospitals. The typical findings in this sector are therefore OT findings. Office IT and plant networks are separated on paper but connected through jump hosts, historians and engineering laptops. Remote maintenance by manufacturers runs over standing VPN tunnels. Attack detection covers the Windows domain but not the control network, where a passive sensor would see Modbus or IEC 60870-5-104 writes from unexpected sources. Proof audits based on a sector-specific security standard (B3S) check documents, and the documents are fine; the configuration behind them is where the gaps are.

Testing in these environments needs a different method than an IT pentest: passive analysis of the control network first, active tests on test systems or in maintenance windows, no scans against live controllers without the operator’s sign-off. Zyberum tests OT and IT of operators, runs gap analyses against section 30 and the B3S of the sector, and operates attack detection for OT and IT with the Zyberdome managed SOC. The formal proof under section 39 is submitted by the operator; we supply the tests and reports it rests on.

Common misunderstandings

KRITIS is not the same as the NIS2 scope. NIS2 covers particularly important and important entities in many more sectors and company sizes; KRITIS operators are the subset with the strictest duties. Suppliers to KRITIS operators are not KRITIS themselves, but they receive the requirements through contracts and supply chain clauses. And attack detection is a legal requirement for critical facilities, not a recommendation: section 31(2) BSIG expects systems that continuously and automatically collect and evaluate parameters from running operations.

FAQ

Frequently asked questions

How do I know whether my company is a KRITIS operator?

Check the BSI-KritisV. It lists, per sector, the types of facilities and the thresholds, usually derived from supplying 500,000 people, above which a facility is critical. If you operate such a facility you are an operator of a critical facility under the BSIG and must register with the BSI. If you are below the threshold you may still be an essential or important entity under the NIS2 rules, which apply to far more companies.

What does the BSIG require from KRITIS operators?

State-of-the-art risk management measures under section 30, which follow the list in Article 21 of NIS2, plus the special duties of section 31: measures proportionate to the consequences of a failure and mandatory attack detection systems. Operators register (section 33), report significant incidents (section 32) and prove implementation to the BSI through audits, tests or certifications every three years (section 39).

Is a penetration test mandatory for KRITIS?

The law does not use the word. It demands that measures are state of the art and that their implementation is proven through audits, tests or certifications. In practice the sector-specific security standards (B3S) and the auditors who check the proof expect regular technical tests, and a penetration test of the systems that keep the critical facility running is the most direct evidence.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab