/ KRITIS Access Control
BSI Access Control and Visitor Management for KRITIS Companies
The KRITIS Framework Act introduces new requirements for operators of critical infrastructure—including in the areas of access control and visitor management.

Companies classified as KRITIS operators must review and update their security policies. We provide an overview of the key background information and explain the role that modern visitor management systems can play in this process.
What is the KRITIS Framework Act about?
The KRITIS Framework Act transposes the EU CER Directive (Critical Entities Resilience, EU 2022/2557) into national law and strengthens the resilience of critical infrastructure in Germany. It defines which facilities are considered KRITIS entities and sets out binding requirements for their physical security—such as protective measures, risk assessments, and emergency preparedness. In addition to access controls, this includes, for example, protection against natural hazards or sabotage.
While the KRITIS umbrella law primarily addresses the physical security and resilience of critical facilities, the European NIS2 Directive has a different focus: It defines requirements for cybersecurity, IT risk management, and reporting obligations in the event of security incidents.
In the future, many organizations will be subject to both sets of regulations simultaneously—albeit with different requirements and priorities.
In a separate article, we explain what requirements the NIS2 Directive places on visitor management and access controls from an IT perspective and how companies can implement them.
The KRITIS umbrella law primarily affects companies providing essential services, such as in the energy, water, transportation, or healthcare sectors, generally serving a population of approximately 500,000 or more. The goal is to strengthen the long-term security of supply for systemically important services.
What does KRITIS have to do with access control and visitor management?
In the context of KRITIS, access control involves much more than traditional locking systems. Critical facilities such as data centers, control centers, or
production plants must be protected reliably not only digitally but also physically.
Mechanical keys are generally insufficient for this purpose, as they do not allow for audit-proof logging of access. This means that in an emergency, the necessary traceability is lacking—for example, in the event of security incidents or audits. However, it is precisely this transparency that is becoming increasingly important: Security incidents must be reported, and operators of critical infrastructure must be able to determine who had access to sensitive areas and when.
KRITIS operators are therefore required to implement comprehensive security concepts. These include, for example:
- Perimeter security (e.g., fences, access controls)
- Building security through electronic access systems
- Securing particularly sensitive areas
- Audit-proof documentation of access and visitor processes
The law does not prescribe specific technologies but requires security measures in accordance with the “state of the art.” Established standards such as ISO/IEC 27001 or the BSI Basic Protection provide guidance.
It is also crucial that the systems used are not only implemented but also regularly reviewed and updated. Modern visitor management solutions combine physical security measures with digital processes, thereby creating an integrated, traceable access management system.
Access Control According to BSI Basic Protection
In the module INF.1.A7 “Access Regulation and Control”, BSI Basic Protection defines fundamental requirements for the physical security of access to buildings and rooms.
These include, among other things:
- regulated and controlled access to areas requiring protection
- documented access authorizations
- a structured access concept
For KRITIS operators, however, the practical requirements often go well beyond these minimum requirements. Especially in conjunction with regulatory requirements and internal security policies, digital systems for ISO 27001-compliant access control and visitor management are therefore becoming increasingly important.
Would you like to bring your access control, visitor management, and yard management up to modern and secure standards?
Contact us – we’d be happy to assist you.




