{"id":4671,"date":"2026-05-21T11:44:50","date_gmt":"2026-05-21T09:44:50","guid":{"rendered":"https:\/\/visit.astrum-it.de\/?post_type=news&#038;p=4671"},"modified":"2026-05-21T11:44:50","modified_gmt":"2026-05-21T09:44:50","slug":"bsi-access-control-and-visitor-management-for-kritis-companies","status":"publish","type":"news","link":"https:\/\/visit.astrum-it.de\/en\/news\/bsi-access-control-and-visitor-management-for-kritis-companies\/","title":{"rendered":"BSI Access Control and Visitor Management for KRITIS Companies"},"content":{"rendered":"<div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1456px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-1\"><p><img decoding=\"async\" class=\"alignnone size-large wp-image-3398\" src=\"https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-besuchermanagement-1200x668.jpg\" alt=\"\" width=\"1200\" height=\"668\" srcset=\"https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-besuchermanagement-200x111.jpg 200w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-besuchermanagement-400x223.jpg 400w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-besuchermanagement-600x334.jpg 600w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-besuchermanagement-768x427.jpg 768w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-besuchermanagement-800x445.jpg 800w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-besuchermanagement-1200x668.jpg 1200w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/kritis-besuchermanagement-1536x855.jpg 1536w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/p>\n<p>Companies classified as KRITIS operators must review and update their security policies. We provide an overview of the key background information and explain the role that modern visitor management systems can play in this process.<\/p>\n<\/div><div class=\"fusion-text fusion-text-2\" style=\"--awb-margin-top:20px;\"><h2>What is the KRITIS Framework Act about?<\/h2>\n<p>The KRITIS Framework Act transposes the EU CER Directive (Critical Entities Resilience, EU 2022\/2557) into national law and strengthens the resilience of critical infrastructure in Germany. It defines which facilities are considered <a href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=4657\" target=\"_blank\" rel=\"noopener\"><b>KRITIS entities<\/b><\/a> and sets out binding requirements for their physical security\u2014such as protective measures, risk assessments, and emergency preparedness. In addition to access controls, this includes, for example, protection against natural hazards or sabotage.<\/p>\n<p>While the KRITIS umbrella law primarily addresses the <b>physical security and resilience of critical facilities<\/b>, the European <a href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=3400\"><b>NIS2<\/b><\/a> Directive has a different focus: It defines requirements for <b>cybersecurity, IT risk management, and reporting obligations in the event of security incidents<\/b>.<\/p>\n<p>In the future, many organizations will be subject to <b>both sets of regulations<\/b> simultaneously\u2014albeit with different requirements and priorities.<\/p>\n<p>In a <a href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=4668\" target=\"_blank\" rel=\"noopener\"><b>separate article<\/b><\/a>, we explain <b>what requirements the NIS2 Directive places on visitor management and access controls from an IT perspective and how companies can implement them.<\/b><\/p>\n<p>The KRITIS umbrella law primarily affects companies providing essential services, such as in the energy, water, transportation, or healthcare sectors, generally serving a population of approximately 500,000 or more. The goal is to strengthen the long-term security of supply for systemically important services.<\/p>\n<\/div><div class=\"fusion-text fusion-text-3\" style=\"--awb-margin-top:20px;\"><h2>What does KRITIS have to do with access control and visitor management?<\/h2>\n<p>In the context of KRITIS, access control involves much more than traditional locking systems. Critical facilities such as data centers, control centers, or<\/p>\n<p>production plants must be protected reliably not only digitally but also physically.<\/p>\n<p>Mechanical keys are generally insufficient for this purpose, as they do not allow for audit-proof logging of access. This means that in an emergency, the necessary traceability is lacking\u2014for example, in the event of security incidents or audits. However, it is precisely this transparency that is becoming increasingly important: Security incidents must be reported, and operators of critical infrastructure must be able to determine <b>who had access to sensitive areas and when<\/b>.<\/p>\n<p>KRITIS operators are therefore required to implement comprehensive security concepts. These include, for example:<\/p>\n<ul>\n<li>Perimeter security (e.g., fences, access controls)<\/li>\n<li>Building security through electronic access systems<\/li>\n<li>Securing particularly sensitive areas<\/li>\n<li>Audit-proof documentation of access and visitor processes<\/li>\n<\/ul>\n<p>The law does not prescribe specific technologies but requires security measures in accordance with the \u201cstate of the art.\u201d Established standards such as ISO\/IEC 27001 or the BSI Basic Protection provide guidance.<\/p>\n<p>It is also crucial that the systems used are not only implemented but also regularly reviewed and updated. Modern visitor management solutions combine physical security measures with digital processes, thereby creating an integrated, traceable access management system.<\/p>\n<\/div><div class=\"fusion-text fusion-text-4\" style=\"--awb-margin-top:20px;\"><h2>Access Control According to BSI Basic Protection<\/h2>\n<p>In the module <b>INF.1.A7 \u201cAccess Regulation and Control\u201d<\/b>, BSI Basic Protection defines fundamental requirements for the physical security of access to buildings and rooms.<\/p>\n<p>These include, among other things:<\/p>\n<ul>\n<li>regulated and controlled access to areas requiring protection<\/li>\n<li>documented access authorizations<\/li>\n<li>a structured access concept<\/li>\n<\/ul>\n<p>For KRITIS operators, however, the practical requirements often go well beyond these minimum requirements. Especially in conjunction with regulatory requirements and internal security policies, digital systems for <a href=\"https:\/\/visit.astrum-it.de\/en\/news\/iso-27001-zutrittskontrolle-bsi-grundschutz-astrum-it\/\"><b>ISO 27001-compliant access control<\/b><\/a> and visitor management are therefore becoming increasingly important.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"featured_media":3397,"template":"","meta":{"_acf_changed":false,"rs_blank_template":"","rs_page_bg_color":"","slide_template_v7":"","_links_to":"","_links_to_target":""},"mediathek-kategorie":[50],"class_list":["post-4671","news","type-news","status-publish","has-post-thumbnail","hentry","mediathek-kategorie-technology-insights-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/news\/4671","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/news"}],"about":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/types\/news"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/media\/3397"}],"wp:attachment":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/media?parent=4671"}],"wp:term":[{"taxonomy":"mediathek-kategorie","embeddable":true,"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/mediathek-kategorie?post=4671"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}