{"id":4657,"date":"2026-05-21T11:37:23","date_gmt":"2026-05-21T09:37:23","guid":{"rendered":"https:\/\/visit.astrum-it.de\/?post_type=news&#038;p=4657"},"modified":"2026-05-21T12:26:09","modified_gmt":"2026-05-21T10:26:09","slug":"kritis-companies","status":"publish","type":"news","link":"https:\/\/visit.astrum-it.de\/en\/news\/kritis-companies\/","title":{"rendered":"Critical Infrastructure: Strict Rules for KRITIS Companies"},"content":{"rendered":"<p><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1456px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-1\"><p><img decoding=\"async\" class=\"alignnone size-large wp-image-3425\" src=\"https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritische-infrastruktur-1200x668.jpg\" alt=\"Kritische Infrastruktur wie diese Raffinerie in Wesseling und der Rhein als Schifffahrtstra\u00dfe brauchen besonderen Schutz. Daher gelten f\u00fcr KRITIS-Unternehmen besondere Regeln.\" width=\"1200\" height=\"668\" srcset=\"https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritische-infrastruktur-200x111.jpg 200w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritische-infrastruktur-400x223.jpg 400w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritische-infrastruktur-600x334.jpg 600w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritische-infrastruktur-768x427.jpg 768w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritische-infrastruktur-800x445.jpg 800w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritische-infrastruktur-1200x668.jpg 1200w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritische-infrastruktur-1536x855.jpg 1536w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/p>\n<p>KRITIS operators must therefore determine for themselves whether their organization qualifies as a <strong>critical infrastructure<\/strong> entity and whether they are required to register and comply with the relevant security regulations.<\/p>\n<p>While the KRITIS Framework Act primarily regulates the <strong>physical protection of critical infrastructure and facilities<\/strong>, other regulations\u2014in particular the EU <strong>NIS2 Directive<\/strong>\u2014focus more on the <strong>cybersecurity of companies and organizations<\/strong>. We explain which companies are affected by NIS2 in a <strong><a href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=3400\" target=\"_blank\" rel=\"noopener\">separate article<\/a><\/strong>.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-2 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-background-color:var(--awb-color3);--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1456px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-1 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-2\"><h2>What is critical infrastructure? What are KRITIS companies?<\/h2>\n<p>In Germany, the legal basis for classifying infrastructure as critical is the so-called <strong>KRITIS Framework Act<\/strong>. It defines which facilities and organizations are considered systemically important due to their central significance to the public.<\/p>\n<p>According to this definition of <strong>critical infrastructure<\/strong>, this includes facilities, systems, and services whose failure or significant disruption would lead to sustained supply shortages, disruptions to public safety, or other serious consequences for the state, the economy, and society.<\/p>\n<p><strong>KRITIS companies<\/strong> or <strong>KRITIS operators<\/strong> are organizations that operate in one of the sectors defined by law and reach a certain level of supply relevance. As a rule, a supply threshold of at least <strong>500,000 people<\/strong> served is decisive. For individual sectors, this threshold is sometimes determined by technical indicators\u2014such as production volumes or capacities.<\/p>\n<p>In addition, competent authorities may classify a <strong>company as a critical infrastructure entity<\/strong> regardless of this threshold if its importance to the functioning of society so requires.<\/p>\n<p>The <strong>KRITIS Framework Act<\/strong> classifies critical infrastructure into the following sectors:<\/p>\n<ul>\n<li>Energy (electricity supply, natural gas supply, hydrogen supply, petroleum supply)<\/li>\n<li>Water<\/li>\n<li>Health<\/li>\n<li>Transportation and traffic (rail transport, maritime and inland waterway transport, water levels and tides, road transport, weather forecasting, air transport)<\/li>\n<li>Digital infrastructure (voice and data transmission, data storage and processing, public telecommunications networks and services)<\/li>\n<li>Finance (DORA services)<\/li>\n<li>Social security<\/li>\n<li>Space (ground stations)<\/li>\n<li>Government<\/li>\n<li>Food<\/li>\n<li>Waste management<\/li>\n<\/ul>\n<p>Not all government agencies or financial sector actors are automatically subject to the general <strong>KRITIS regulations<\/strong>, as some are covered by their own regulatory frameworks.<\/p>\n<p>Critical infrastructure companies thus bear a special responsibility for the stability and resilience of central supply and administrative structures. Their services form the foundation for economic performance, social security, and the government\u2019s ability to act\u2014and their systemic relevance within the legal framework is correspondingly high.<\/p>\n<p>An important difference from regulations such as <strong>NIS2<\/strong> is that the <strong>KRITIS umbrella law<\/strong> primarily targets <strong>particularly critical facilities with high supply relevance<\/strong>. NIS2 significantly expands the scope of regulated organizations and also includes many small and medium-sized enterprises from key economic sectors.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-3 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1456px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-2 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-3\"><h2>Stricter Security Requirements for KRITIS Companies<\/h2>\n<p>Ordinary companies are largely free to decide for themselves how well they protect themselves against sabotage, data theft, disasters, and other threats, and how they balance security costs against security risks. Operators of critical infrastructure, on the other hand, must at least comply with the <strong><a href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=4656\" target=\"_blank\" rel=\"noopener\">KRITIS requirements<\/a><\/strong> for their security measures. We have compiled details on this in a <strong><a href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=4656\" target=\"_blank\" rel=\"noopener\">separate article<\/a><\/strong>.<\/p>\n<p>The focus here is primarily on <strong>physical security<\/strong>: surveillance systems, fences, security personnel, secure doors and gates with effective access controls, as well as other measures to protect critical facilities.<\/p>\n<p><strong>Cybersecurity<\/strong> regulations, on the other hand, are more heavily addressed in other regulatory frameworks, particularly in the EU\u2019s <strong>NIS2 Directive<\/strong>. While KRITIS primarily addresses the protection of critical infrastructure itself, NIS2 requires a significantly larger number of companies to implement structured IT security measures.<\/p>\n<p>For the concrete implementation of many security requirements, the regulations refer to the \u201c<strong>state of the art<\/strong>.\u201d <strong>DIN EN ISO\/IEC 27001<\/strong>, for example, provides important guidance in this regard.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-4 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-background-color:var(--awb-color8);--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1456px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-3 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-4\" style=\"--awb-font-size:1.3em;\"><p><span style=\"color: #ffffff;\">At VISIT, we support<strong><em> <a style=\"color: #ffffff;\" href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=4656\" target=\"_blank\" rel=\"noopener\">ISO 27001-compliant access control<\/a><\/em><\/strong> with our <strong><em><a style=\"color: #ffffff;\" href=\"https:\/\/visit.astrum-it.de\/en\/visitor-management\/\">visitor management<\/a> <\/em><\/strong>and<strong><em> <a style=\"color: #ffffff;\" href=\"https:\/\/visit.astrum-it.de\/en\/yard-management\/\">yard management<\/a><\/em><\/strong>. For more details, please see our articles on <em><strong><a style=\"color: #ffffff;\" href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=4671\" target=\"_blank\" rel=\"noopener\">KRITIS &amp; Visitor Management<\/a><\/strong><\/em> and<a style=\"color: #ffffff;\" href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=4658\" target=\"_blank\" rel=\"noopener\"> <strong>KRITIS &amp; Yard Management<\/strong><\/a>.<\/span><\/p>\n<\/div><\/div><\/div><\/div><\/div><\/p>\n","protected":false},"featured_media":3424,"template":"","meta":{"_acf_changed":false,"rs_blank_template":"","rs_page_bg_color":"","slide_template_v7":"","_links_to":"","_links_to_target":""},"mediathek-kategorie":[50],"class_list":["post-4657","news","type-news","status-publish","has-post-thumbnail","hentry","mediathek-kategorie-technology-insights-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/news\/4657","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/news"}],"about":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/types\/news"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/media\/3424"}],"wp:attachment":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/media?parent=4657"}],"wp:term":[{"taxonomy":"mediathek-kategorie","embeddable":true,"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/mediathek-kategorie?post=4657"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}