IT for Critical Infrastructures (KRITIS)
Available, secure and verifiable. We bring the IT of KRITIS operators to the level that law and supervision require.
Critical infrastructures (KRITIS) are organisations whose failure would cause lasting supply shortages or endanger public safety, in sectors such as energy, water, healthcare, transport, IT and telecommunications. Their operators face special legal duties, from attack detection systems to registration and evidence obligations.
What you gain
As an operator of critical infrastructure you carry special obligations and high risk. We deliver the complete IT support, from availability through attack detection to evidence towards the supervisory authority, aligned with the German IT Security Act 2.0.
Scope of service
- Managed services with 24/7 monitoring, maintenance and support in line with the IT Security Act 2.0.
- Attack detection systems (SzA) in line with BSI requirements, implementation and operation.
- Secure cloud solutions, migration and operation under KRITIS requirements.
- Compliance management, support in meeting KRITIS-specific requirements.
- Redundant network infrastructure, design and implementation for high availability.
How we work
- We assess protection needs and regulatory requirements.
- We implement availability, attack detection and compliance.
- We operate, monitor and deliver the evidence.
Frequently asked questions
Who is this for?
For operators of critical infrastructure and companies with high demands on availability and verifiability.
What is an attack detection system (SzA)?
A solution required by the BSI that detects and reports attacks. We implement and operate it, among others with ZephSense.
What are critical infrastructures?
Organisations whose failure would cause lasting supply shortages or endanger public safety, for example energy, water, healthcare, transport, IT and telecommunications. In Germany the KRITIS regulation defines thresholds per sector.
Who counts as a KRITIS operator?
Anyone operating a facility in a KRITIS sector that reaches the thresholds of the German KRITIS regulation, as a rule of thumb supplying around 500,000 people. Operators must register and prove their security measures regularly.
What does NIS-2 require from KRITIS operators?
Registration with the BSI, risk management measures, a strict reporting chain for incidents (24 hours for the first report, 72 hours for the assessment), attack detection systems and regular evidence audits.
What is the difference between KRITIS and NIS-2?
KRITIS describes the operators of critical facilities above certain thresholds. NIS-2 is the EU-wide legal framework that additionally obliges many important and particularly important entities. KRITIS operators keep the strictest duties within it.
NIS-2 and KRITIS
The German NIS-2 implementation act (NIS2UmsuCG) has been in force since 6 December 2025. It extends cybersecurity duties far beyond classic KRITIS operators to many important and particularly important entities. Registration with the BSI is mandatory, and significant incidents must be reported within 24 hours, followed by an assessment within 72 hours.
For KRITIS operators the stricter rules remain in place: attack detection systems, registration and regular evidence audits. Our NOC and SOC cover the operational side of these duties, from monitoring to the reporting chain. Whether and how your organisation is affected is best clarified in a short conversation.
Our NIS-2 page covers duties, deadlines and the way out of registration arrears in detail.