/ KRITIS Companies
Critical Infrastructure: Strict Rules for KRITIS Companies
The KRITIS Framework Act imposes stricter physical security requirements on operators of critical infrastructure. The law defines which facilities are considered critical infrastructure and therefore deserve special protection. In practice, however, many KRITIS companies are not actively informed that they are subject to these requirements.

KRITIS operators must therefore determine for themselves whether their organization qualifies as a critical infrastructure entity and whether they are required to register and comply with the relevant security regulations.
While the KRITIS Framework Act primarily regulates the physical protection of critical infrastructure and facilities, other regulations—in particular the EU NIS2 Directive—focus more on the cybersecurity of companies and organizations. We explain which companies are affected by NIS2 in a separate article.
What is critical infrastructure? What are KRITIS companies?
In Germany, the legal basis for classifying infrastructure as critical is the so-called KRITIS Framework Act. It defines which facilities and organizations are considered systemically important due to their central significance to the public.
According to this definition of critical infrastructure, this includes facilities, systems, and services whose failure or significant disruption would lead to sustained supply shortages, disruptions to public safety, or other serious consequences for the state, the economy, and society.
KRITIS companies or KRITIS operators are organizations that operate in one of the sectors defined by law and reach a certain level of supply relevance. As a rule, a supply threshold of at least 500,000 people served is decisive. For individual sectors, this threshold is sometimes determined by technical indicators—such as production volumes or capacities.
In addition, competent authorities may classify a company as a critical infrastructure entity regardless of this threshold if its importance to the functioning of society so requires.
The KRITIS Framework Act classifies critical infrastructure into the following sectors:
- Energy (electricity supply, natural gas supply, hydrogen supply, petroleum supply)
- Water
- Health
- Transportation and traffic (rail transport, maritime and inland waterway transport, water levels and tides, road transport, weather forecasting, air transport)
- Digital infrastructure (voice and data transmission, data storage and processing, public telecommunications networks and services)
- Finance (DORA services)
- Social security
- Space (ground stations)
- Government
- Food
- Waste management
Not all government agencies or financial sector actors are automatically subject to the general KRITIS regulations, as some are covered by their own regulatory frameworks.
Critical infrastructure companies thus bear a special responsibility for the stability and resilience of central supply and administrative structures. Their services form the foundation for economic performance, social security, and the government’s ability to act—and their systemic relevance within the legal framework is correspondingly high.
An important difference from regulations such as NIS2 is that the KRITIS umbrella law primarily targets particularly critical facilities with high supply relevance. NIS2 significantly expands the scope of regulated organizations and also includes many small and medium-sized enterprises from key economic sectors.
Stricter Security Requirements for KRITIS Companies
Ordinary companies are largely free to decide for themselves how well they protect themselves against sabotage, data theft, disasters, and other threats, and how they balance security costs against security risks. Operators of critical infrastructure, on the other hand, must at least comply with the KRITIS requirements for their security measures. We have compiled details on this in a separate article.
The focus here is primarily on physical security: surveillance systems, fences, security personnel, secure doors and gates with effective access controls, as well as other measures to protect critical facilities.
Cybersecurity regulations, on the other hand, are more heavily addressed in other regulatory frameworks, particularly in the EU’s NIS2 Directive. While KRITIS primarily addresses the protection of critical infrastructure itself, NIS2 requires a significantly larger number of companies to implement structured IT security measures.
For the concrete implementation of many security requirements, the regulations refer to the “state of the art.” DIN EN ISO/IEC 27001, for example, provides important guidance in this regard.
At VISIT, we support ISO 27001-compliant access control with our visitor management and yard management. For more details, please see our articles on KRITIS & Visitor Management and KRITIS & Yard Management.
Would you like to know how we can help you with your physical security?
Please contact us for advice.




