{"id":4656,"date":"2026-05-21T11:31:24","date_gmt":"2026-05-21T09:31:24","guid":{"rendered":"https:\/\/visit.astrum-it.de\/?post_type=news&#038;p=4656"},"modified":"2026-05-21T11:31:24","modified_gmt":"2026-05-21T09:31:24","slug":"kritis-anforderungen","status":"publish","type":"news","link":"https:\/\/visit.astrum-it.de\/en\/news\/kritis-anforderungen\/","title":{"rendered":"What are the legal requirements for KRITIS operators?"},"content":{"rendered":"<p><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-margin-bottom:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1456px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-1\"><p><img decoding=\"async\" class=\"alignnone size-large wp-image-3387\" src=\"https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-anforderungen-1200x668.jpg\" alt=\"\" width=\"1200\" height=\"668\" srcset=\"https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-anforderungen-200x111.jpg 200w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-anforderungen-400x223.jpg 400w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-anforderungen-600x334.jpg 600w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-anforderungen-768x427.jpg 768w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-anforderungen-800x445.jpg 800w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-anforderungen-1200x668.jpg 1200w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-anforderungen-1536x855.jpg 1536w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/p>\n<p>But what specific <strong>KRITIS requirements<\/strong> does the new KRITIS umbrella law entail? And what organizational, technical, and strategic <strong>KRITIS measures<\/strong> are actually necessary to ensure the long-term <strong>protection of critical infrastructure<\/strong>?<\/p>\n<p>For operators of critical infrastructure, this is no longer just about IT security in the narrow sense. What is required is a holistic approach to resilience\u2014ranging from risk analysis and appropriate technical and organizational measures to reporting requirements and regular verification. Protecting critical infrastructure is therefore a core business responsibility that must be strategically embedded.<\/p>\n<p>The KRITIS Framework Act complements other regulatory requirements for cybersecurity\u2014in particular the European <strong>NIS 2 Directive<\/strong>. While NIS 2 primarily sets requirements for the<strong> IT and cybersecurity of many companies and organizations<\/strong>, the KRITIS Framework Act focuses more on the <strong>physical and organizational resilience<\/strong> of critical infrastructure. <strong><a href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=4668\">We will examine the specific requirements under NIS 2 in a separate article.<\/a><\/strong><\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-2 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-bottom:20px;--awb-margin-bottom:10px;--awb-background-color:var(--awb-custom_color_1);--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1456px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-1 fusion_builder_column_1_2 1_2 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:50%;--awb-margin-top-large:0px;--awb-spacing-right-large:3.84%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:3.84%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\" data-scroll-devices=\"small-visibility,medium-visibility,large-visibility\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-center fusion-content-layout-column\"><div class=\"fusion-text fusion-text-2\" style=\"--awb-font-size:1.3em;--awb-text-color:var(--awb-color1);\"><p>Visitor Management &amp; Yard Management (not just) for KRITIS companies.<\/p>\n<\/div><div style=\"text-align:left;\"><a class=\"fusion-button button-flat fusion-button-default-size button-custom fusion-button-default button-1 fusion-button-default-span fusion-button-default-type\" style=\"--awb-margin-right:20px;--awb-margin-bottom:20px;--button_accent_color:var(--awb-color1);--button_accent_hover_color:var(--awb-custom_color_1);--button_border_hover_color:var(--awb-color1);--button_border_width-top:2px;--button_border_width-right:2px;--button_border_width-bottom:2px;--button_border_width-left:2px;--button_gradient_top_color:var(--awb-custom_color_1);--button_gradient_bottom_color:var(--awb-custom_color_1);--button_gradient_top_color_hover:var(--awb-color1);--button_gradient_bottom_color_hover:var(--awb-color1);\" target=\"_self\" href=\"https:\/\/visit.astrum-it.de\/en\/contact\/\"><span class=\"fusion-button-text awb-button__text awb-button__text--default\">Get advice now<\/span><\/a><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-2 fusion_builder_column_1_2 1_2 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:50%;--awb-margin-top-large:0px;--awb-spacing-right-large:3.84%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:3.84%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\" data-scroll-devices=\"small-visibility,medium-visibility,large-visibility\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-center fusion-content-layout-column\"><div class=\"fusion-text fusion-text-3\" style=\"--awb-font-size:1.3em;--awb-text-color:var(--awb-color1);\"><p>Would you like to know if you are affected by KRITIS?<\/p>\n<\/div><div style=\"text-align:left;\"><a class=\"fusion-button button-flat fusion-button-default-size button-custom fusion-button-default button-2 fusion-button-default-span fusion-button-default-type\" style=\"--awb-margin-right:20px;--awb-margin-bottom:20px;--button_accent_color:var(--awb-color1);--button_accent_hover_color:var(--awb-custom_color_1);--button_border_hover_color:var(--awb-color1);--button_border_width-top:2px;--button_border_width-right:2px;--button_border_width-bottom:2px;--button_border_width-left:2px;--button_gradient_top_color:var(--awb-custom_color_1);--button_gradient_bottom_color:var(--awb-custom_color_1);--button_gradient_top_color_hover:var(--awb-color1);--button_gradient_bottom_color_hover:var(--awb-color1);\" target=\"_self\" href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=4657\"><span class=\"fusion-button-text awb-button__text awb-button__text--default\">Read more now<\/span><\/a><\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-3 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1456px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-3 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-4\"><p>It is particularly important to note that responsibility does not lie solely with the IT department or plant security. Management is obligated to implement appropriate organizational measures to ensure the security and resilience of the company\u2019s systems and processes. If management fails to adequately fulfill this obligation, <strong>the company faces not only substantial fines of up to 1 million euros<\/strong>. Under certain circumstances, <strong>personal liability of management<\/strong> may also be considered.<\/p>\n<p>Furthermore, the financial damage caused by preventable security incidents\u2014such as production downtime, reputational damage, or contractual penalties\u2014can far exceed the statutory fines.<\/p>\n<p>This makes it all the more important to analyze regulatory requirements in a structured manner at an early stage and translate them into robust, practical measures. In this article, you will learn which legal <strong>KRITIS requirements<\/strong> currently apply, which <strong>KRITIS measures<\/strong> must be implemented under the umbrella law, and how you can design the<strong> protection of critical infrastructure<\/strong> to be legally compliant and future-proof.<\/p>\n<\/div><div class=\"fusion-text fusion-text-5\" style=\"--awb-margin-top:20px;\"><h2>Registration of KRITIS companies<\/h2>\n<p>Under the KRITIS Framework Act, affected companies must self-register within three <strong>months<\/strong>. This process is overseen by a registration office jointly operated by the <strong>Federal Office for Civil Protection and Disaster Assistance (BBK)<\/strong> and the <strong>Federal Office for Information Security (BSI)<\/strong>. Approximately two weeks after registration, the company will be notified of the competent supervisory authority.<\/p>\n<p><strong>This means<\/strong> that companies must first <strong>determine for themselves<\/strong> whether they qualify as KRITIS operators. This classification is based on defined thresholds for individual sectors and facilities.<\/p>\n<\/div><div class=\"fusion-text fusion-text-6\" style=\"--awb-margin-top:20px;\"><h2>Risk Analyses<\/h2>\n<p>One of the key <strong>KRITIS requirements<\/strong> is the preparation of structured risk analyses. In addition to the individual risks associated with their own operations, KRITIS companies must also take systemic dependencies into account.<\/p>\n<p>These include, in particular:<\/p>\n<ul>\n<li>Risks identified in <strong>national risk analyses<\/strong><\/li>\n<li>Risks arising from <strong>dependencies on other operators<\/strong>, including those in other sectors<\/li>\n<li>Risks arising from <strong>other operators\u2019 dependence on one\u2019s own infrastructure<\/strong><\/li>\n<\/ul>\n<p>For example, a refinery operator may depend on the electricity supply or transportation capacity for crude oil. At the same time, the transportation sector or waste management sector may rely on the refinery\u2019s products.<\/p>\n<p>The initial risk analysis must be prepared no later than nine months after registration. It must then be updated at least every four years.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-4 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1456px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-4 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-7\"><h2>Resilience Measures, Implementation Plan, and Documentation<\/h2>\n<p>KRITIS companies are required to implement appropriate KRITIS measures <strong>within ten months of registration<\/strong> and to document these measures in an <strong>implementation plan<\/strong>.<\/p>\n<p>The goal is to provide comprehensive and robust <strong>protection for critical infrastructure<\/strong>\u2014from prevention and response to the restoration of operational capability.<\/p>\n<p>Essentially, the legal requirements can be divided into several areas of action.<\/p>\n<\/div><div class=\"accordian fusion-accordian\" style=\"--awb-border-size:1px;--awb-icon-size:13px;--awb-content-font-size:0.9em;--awb-icon-alignment:left;--awb-hover-color:#f9f9f9;--awb-border-color:#cccccc;--awb-background-color:#ffffff;--awb-divider-color:#e0dede;--awb-divider-hover-color:#e0dede;--awb-icon-color:#ffffff;--awb-title-color:var(--awb-custom_color_1);--awb-content-color:#747474;--awb-icon-box-color:var(--awb-custom_color_1);--awb-toggle-hover-accent-color:var(--awb-custom_color_1);--awb-title-font-family:&quot;industry&quot;;--awb-title-font-weight:400;--awb-title-font-style:normal;--awb-content-font-family:&quot;industry&quot;;--awb-content-font-style:normal;--awb-content-font-weight:400;\"><div class=\"panel-group fusion-toggle-icon-boxed\" id=\"accordion-4656-1\"><div class=\"fusion-panel panel-default panel-61896ce94e6760661 fusion-toggle-has-divider\" style=\"--awb-content-font-family:&quot;Industry-Book&quot;;--awb-content-font-style:normal;--awb-content-font-weight:400;--awb-title-font-family:&quot;Industry-Bold&quot;;--awb-title-font-weight:400;--awb-title-font-style:normal;--awb-title-color:var(--awb-custom_color_1);--awb-content-color:#000000;\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_61896ce94e6760661\"><a aria-expanded=\"false\" aria-controls=\"61896ce94e6760661\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-4656-1\" data-target=\"#61896ce94e6760661\" href=\"#61896ce94e6760661\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">1. Prevention: Systematically preventing incidents <\/span><\/a><\/h4><\/div><div id=\"61896ce94e6760661\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_61896ce94e6760661\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>A key component of the <strong>KRITIS requirements<\/strong> is proactive emergency preparedness. Operators must identify and assess risks at an early stage and define appropriate countermeasures.<\/p>\n<p>These include, among other things:<\/p>\n<ul>\n<li>structured risk analyses and threat assessments<\/li>\n<li>preventive emergency plans<\/li>\n<li>clear responsibilities and escalation mechanisms<\/li>\n<\/ul>\n<p>The goal is to prevent disruptions, attacks, or outages in advance, detect them early, or significantly reduce the likelihood of their occurrence.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-d55172f7607a366de fusion-toggle-has-divider\" style=\"--awb-content-font-family:&quot;Industry-Book&quot;;--awb-content-font-style:normal;--awb-content-font-weight:400;--awb-title-font-family:&quot;Industry-Bold&quot;;--awb-title-font-weight:400;--awb-title-font-style:normal;--awb-title-color:var(--awb-custom_color_1);--awb-content-color:#000000;\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_d55172f7607a366de\"><a aria-expanded=\"false\" aria-controls=\"d55172f7607a366de\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-4656-1\" data-target=\"#d55172f7607a366de\" href=\"#d55172f7607a366de\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">2. Physical protection of critical facilities and properties <\/span><\/a><\/h4><\/div><div id=\"d55172f7607a366de\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_d55172f7607a366de\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>The <strong>protection of critical infrastructure<\/strong> is not limited to cybersecurity. Adequate physical protection of buildings, production facilities, servers, warehouses, and technical equipment is equally essential.<\/p>\n<p>This includes, in particular:<\/p>\n<ul>\n<li>Structural, organizational, and technical security measures (e.g., perimeter protection, secured access points, facility protection, or <a href=\"https:\/\/visit.astrum-it.de\/en\/yard-management\/\">yard management<\/a>)<\/li>\n<li>Clear demarcation of security-sensitive areas<\/li>\n<li>Surveillance of the surrounding area<\/li>\n<li>Use of detection and alarm systems<\/li>\n<li>Controlled and documented access controls and <a href=\"https:\/\/visit.astrum-it.de\/en\/visitor-management\/\">visitor management<\/a><\/li>\n<\/ul>\n<p>These <strong>KRITIS measures<\/strong> are designed to prevent unauthorized access, sabotage, or physical tampering. At the same time, <a href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=4657\" target=\"_blank\" rel=\"noopener\">KRITIS companies<\/a> must also be designed to be as resilient as possible to natural disasters or accidents.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-87a7a6e5f68f7e6b7 fusion-toggle-has-divider\" style=\"--awb-content-font-family:&quot;Industry-Book&quot;;--awb-content-font-style:normal;--awb-content-font-weight:400;--awb-title-font-family:&quot;Industry-Bold&quot;;--awb-title-font-weight:400;--awb-title-font-style:normal;--awb-title-color:var(--awb-custom_color_1);--awb-content-color:#000000;\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_87a7a6e5f68f7e6b7\"><a aria-expanded=\"false\" aria-controls=\"87a7a6e5f68f7e6b7\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-4656-1\" data-target=\"#87a7a6e5f68f7e6b7\" href=\"#87a7a6e5f68f7e6b7\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">3. Response, Mitigation, and Consequence Management in the Event of Incidents <\/span><\/a><\/h4><\/div><div id=\"87a7a6e5f68f7e6b7\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_87a7a6e5f68f7e6b7\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>Despite preventive measures, incidents cannot be completely ruled out. For this reason, the <strong>KRITIS requirements<\/strong> mandate robust structures for rapid response and damage control.<\/p>\n<p>Requirements include, among others:<\/p>\n<ul>\n<li>an established risk management system<\/li>\n<li>a formalized crisis management framework with clearly defined roles<\/li>\n<li>documented crisis response plans and alert procedures<\/li>\n<li>regular review and updating of protocols<\/li>\n<\/ul>\n<p>The ability to act in a structured manner in an emergency is a key factor in determining the impact of an incident on supply security and the company\u2019s reputation.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-123dc8827f8724bda fusion-toggle-has-divider\" style=\"--awb-content-font-family:&quot;Industry-Book&quot;;--awb-content-font-style:normal;--awb-content-font-weight:400;--awb-title-font-family:&quot;Industry-Bold&quot;;--awb-title-font-weight:400;--awb-title-font-style:normal;--awb-title-color:var(--awb-custom_color_1);--awb-content-color:#000000;\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_123dc8827f8724bda\"><a aria-expanded=\"false\" aria-controls=\"123dc8827f8724bda\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-4656-1\" data-target=\"#123dc8827f8724bda\" href=\"#123dc8827f8724bda\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">4. Restoration of critical services <\/span><\/a><\/h4><\/div><div id=\"123dc8827f8724bda\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_123dc8827f8724bda\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>A key element in <strong>protecting critical infrastructure<\/strong> is ensuring operational continuity\u2014even in the event of a disruption. Companies must take steps to restore their critical services as quickly as possible and minimize downtime.<\/p>\n<p>These include:<\/p>\n<ul>\n<li>Plans for maintaining operations (e.g., emergency power supply, redundancies, or backup systems)<\/li>\n<li>Emergency and recovery plans<\/li>\n<li>Identification and securing of alternative supply chains<\/li>\n<\/ul>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-cde7e53167f68394a fusion-toggle-has-divider\" style=\"--awb-content-font-family:&quot;Industry-Book&quot;;--awb-content-font-style:normal;--awb-content-font-weight:400;--awb-title-font-family:&quot;Industry-Bold&quot;;--awb-title-font-weight:400;--awb-title-font-style:normal;--awb-title-color:var(--awb-custom_color_1);--awb-content-color:#000000;\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_cde7e53167f68394a\"><a aria-expanded=\"false\" aria-controls=\"cde7e53167f68394a\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-4656-1\" data-target=\"#cde7e53167f68394a\" href=\"#cde7e53167f68394a\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">5. Safety Management for In-House and External Personnel<\/span><\/a><\/h4><\/div><div id=\"cde7e53167f68394a\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_cde7e53167f68394a\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>Effective security management encompasses not only technology and processes, but also the human factor. Operators must ensure that both their own and external personnel are reliably integrated and vetted.<\/p>\n<p>This includes, for example:<\/p>\n<ul>\n<li>defined security requirements for service providers<\/li>\n<li>contractual obligations regarding security standards<\/li>\n<li>regulated authorization and access models<\/li>\n<\/ul>\n<p>Especially for outsourced services, a structured governance model is essential to fully meet<strong> KRITIS requirements<\/strong>.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-952dc81d335f36930 fusion-toggle-has-divider\" style=\"--awb-content-font-family:&quot;Industry-Book&quot;;--awb-content-font-style:normal;--awb-content-font-weight:400;--awb-title-font-family:&quot;Industry-Bold&quot;;--awb-title-font-weight:400;--awb-title-font-style:normal;--awb-title-color:var(--awb-custom_color_1);--awb-content-color:#000000;\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_952dc81d335f36930\"><a aria-expanded=\"false\" aria-controls=\"952dc81d335f36930\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-4656-1\" data-target=\"#952dc81d335f36930\" href=\"#952dc81d335f36930\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">6. Training, drills, and awareness-raising <\/span><\/a><\/h4><\/div><div id=\"952dc81d335f36930\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_952dc81d335f36930\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>Regular training sessions and practical exercises are a mandatory component of KRITIS measures. Employees must be made aware of risks, threat scenarios, and rules of conduct.<\/p>\n<p>These include:<\/p>\n<ul>\n<li>Awareness programs<\/li>\n<li>Emergency drills and crisis simulations<\/li>\n<li>Training on security and reporting obligations<\/li>\n<\/ul>\n<p>Effective <strong>protection of critical infrastructure<\/strong> can only be achieved when organizational, technical, and personnel measures work together.<\/p>\n<\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-5 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1456px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-5 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-8\"><h2>Relationship to NIS2<\/h2>\n<p>The KRITIS Framework Act supplements the requirements of the <strong>NIS2 Directive<\/strong> but does not replace them. In the future, many companies <strong>may be subject to both regimes simultaneously<\/strong>.<\/p>\n<p>While NIS2 primarily addresses<strong> cybersecurity, IT risk management, and reporting obligations for IT security incidents<\/strong>, the KRITIS Framework Act focuses more on the overall <strong>resilience of critical infrastructure<\/strong>\u2014including physical security, organizational measures, and operational emergency preparedness.<\/p>\n<p>The KRITIS Framework Act generally does <strong>not impose any documentation requirements that go beyond the requirements of NIS2<\/strong>. However, the competent supervisory authorities may request additional documentation.<\/p>\n<p>We explain in detail which companies are affected by NIS2 and what specific security requirements result from it in our article on<strong><a href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=4668\" target=\"_blank\" rel=\"noopener\"> NIS2 requirements for companies.<\/a><\/strong><\/p>\n<\/div><div class=\"fusion-text fusion-text-9\"><h2>Mandatory Reporting of Incidents<\/h2>\n<p>KRITIS companies are required to <strong>report<\/strong> any incident that significantly disrupts or could disrupt the provision of a critical service.<\/p>\n<p>The report must be submitted to the Federal Office for Civil Protection and Disaster Assistance <strong>within 24 hours<\/strong>. A detailed report must also be submitted within <strong>one month<\/strong> at the latest.<\/p>\n<p><strong>Audit-proof documentation of security-related processes<\/strong>\u2014such as access controls or visitor access\u2014is often a key component in investigating such incidents.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-6 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-background-color:var(--awb-color8);--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1456px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-6 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-10\" style=\"--awb-font-size:1.3em;--awb-text-color:var(--awb-color1);\"><p>As an <em><strong><span style=\"color: #ffffff;\"><a style=\"color: #ffffff;\" href=\"https:\/\/visit.astrum-it.de\/en\/news\/iso-27001-zutrittskontrolle-bsi-grundschutz-astrum-it\/\" target=\"_blank\" rel=\"noopener\">ISO 27001<\/a><\/span><\/strong><\/em>-certified software provider, we are happy to assist companies with their initiatives, particularly when it comes to\u00a0<span style=\"color: #ffffff;\"><em><strong><a style=\"color: #ffffff;\" href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=3395&amp;preview=true\" target=\"_blank\" rel=\"noopener\">KRITIS-compliant access control<\/a><\/strong><\/em><\/span> and <em><span style=\"color: #ffffff;\"><strong><a style=\"color: #ffffff;\" href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=4658\" target=\"_blank\" rel=\"noopener\">KRITIS-compliant yard management<\/a><\/strong><\/span><\/em>.<\/p>\n<\/div><\/div><\/div><\/div><\/div><\/p>\n","protected":false},"featured_media":3386,"template":"","meta":{"_acf_changed":false,"rs_blank_template":"","rs_page_bg_color":"","slide_template_v7":"","_links_to":"","_links_to_target":""},"mediathek-kategorie":[50],"class_list":["post-4656","news","type-news","status-publish","has-post-thumbnail","hentry","mediathek-kategorie-technology-insights-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/news\/4656","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/news"}],"about":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/types\/news"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/media\/3386"}],"wp:attachment":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/media?parent=4656"}],"wp:term":[{"taxonomy":"mediathek-kategorie","embeddable":true,"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/mediathek-kategorie?post=4656"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}