KRITIS is the German term for critical infrastructure: facilities whose failure would substantially endanger the supply of the population — energy, water, food, health, IT and telecommunications, finance, transport and further sectors. Whether an operator falls under the duties is determined by thresholds in the BSI KRITIS regulation.
Operators must take appropriate precautions according to the state of the art, prove this to the BSI regularly and report significant incidents. With the NIS2 implementation and the planned KRITIS umbrella act, the circle of obligated parties and the scope of duties keep growing.
What KRITIS operators must deliver
The core is section 8a of the BSI Act: appropriate organisational and technical precautions to avoid disruptions — proven every two years through audits, examinations or certifications. Added to this are reporting duties for significant disruptions to the BSI, a reachable point of contact and, since the recent amendments, attack detection systems.
Translated technically: resilient network and system architecture with redundancy, segmentation — especially between IT and OT —, monitoring and attack detection, rehearsed incident processes and clean documentation. The duty of proof turns every measure into a documentation task as well.
Typical fields of action in KRITIS environments
- IT/OT separation and microsegmentation against spread into the process network.
- Attack detection (SIEM/NDR) with documented response paths.
- Redundant connectivity and DDoS protection for critical services.
- Audit-ready processes: passing audits, not just owning technology.