Glossary · simply explained

KRITIS (critical infrastructure in Germany)

KRITIS is the German term for critical infrastructure: facilities whose failure would substantially endanger the supply of the population — energy, water, food, health, IT and telecommunications, finance, transport and further sectors. Whether an operator falls under the duties is determined by thresholds in the BSI KRITIS regulation.

Operators must take appropriate precautions according to the state of the art, prove this to the BSI regularly and report significant incidents. With the NIS2 implementation and the planned KRITIS umbrella act, the circle of obligated parties and the scope of duties keep growing.

What KRITIS operators must deliver

The core is section 8a of the BSI Act: appropriate organisational and technical precautions to avoid disruptions — proven every two years through audits, examinations or certifications. Added to this are reporting duties for significant disruptions to the BSI, a reachable point of contact and, since the recent amendments, attack detection systems.

Translated technically: resilient network and system architecture with redundancy, segmentation — especially between IT and OT —, monitoring and attack detection, rehearsed incident processes and clean documentation. The duty of proof turns every measure into a documentation task as well.

Typical fields of action in KRITIS environments

  • IT/OT separation and microsegmentation against spread into the process network.
  • Attack detection (SIEM/NDR) with documented response paths.
  • Redundant connectivity and DDoS protection for critical services.
  • Audit-ready processes: passing audits, not just owning technology.

Frequently asked questions about KRITIS (critical infrastructure in Germany)

How do I know whether my company is KRITIS?

Sector and thresholds of the BSI KRITIS regulation are decisive — such as supplied population figures or throughput per facility. Whoever reaches thresholds is an operator in the legal sense and must register with the BSI. In doubt, the assessment belongs to legal counsel.

What does section 8a of the BSI Act require?

Appropriate precautions according to the state of the art to avoid disruptions of the critical service — with proof to the BSI every two years through suitable audits or examinations. Sector-specific security standards (B3S) concretise this per sector.

How do KRITIS and NIS2 differ?

KRITIS is the established German framework for critical infrastructure; NIS2 is the broader EU directive covering many more companies. Both interlock in the German implementation: KRITIS operators belong to the particularly important entities with the strictest duties.

What does the attack detection obligation mean?

Operators must use systems that can continuously detect attacks on their IT — practically: logging, detection (SIEM, EDR, NDR) and defined response, appropriate to the risk. The BSI guidance describes maturity levels for this.

Do suppliers of KRITIS operators count as KRITIS too?

Not automatically — but operators pass requirements on contractually, and NIS2 addresses supply chain security explicitly. Suppliers of critical operators should expect security requirements and evidence questions from their audits.

Want to put this into practice in your own network? Talk to KAEMI, aligned to your requirements and with a managed service from a single source.