Skip to main content

KRITIS & NIS2: Security for critical infrastructure

Increasing attacks on critical infrastructures make it necessary to implement targeted legal measures to provide greater protection for properties and facilities in the future.

Increasing attacks on critical infrastructure make it necessary to implement targeted legal measures to provide greater protection for properties and facilities in the future. We can support you with our physical security and cybersecurity solutions. Implement the legal requirements directly in both regards – with one proven and reliable partner.

Image of an office building and security siveillance

Strengthen resilience against physical attacks and cyber threats

On 14 December 2022, the EU adopted the Critical Entities Resilience (CER) Directive to strengthen the physical security and resilience of critical infrastructure. The implementation into national law is via the KRITIS framework law. In implementing this law, the legislator is not only implementing the requirements of the CER Directive, but also incorporating the requirements from the NIS2 Directive that apply to critical infrastructure. Thus, the KRITIS framework law contains requirements for both the physical security and cybersecurity of critical infrastructure.

White paper KRITIS Framework Act and NIS 2: Requirements and Protective Measures

The white paper explains the central requirements of both laws. It also shows how operators of critical infrastructure and industrial companies must analyse the risks, implement effective protective measures and comply with reporting obligations, and why a holistic security approach is important to protect building infrastructure.

The most important changes and our solutions at a glance

The KRITIS framework law aims to improve the resilience and responsiveness of critical infrastructure. It combines cybersecurity regulations with physical security regulations. The focus of the law is on the introduction of minimum standards for physical protection and the guarantee of security of supply.

Select...

Operators of critical plants are required to carry out a risk analysis and assessment of their properties. An initial analysis and evaluation will be carried out for the first time on 17 January 2026, and every four years thereafter. In this way, the risk assessment should be continuously reviewed and the security status of your building technology should be kept up-to-date in accordance with any changes in your needs. With our Cybersecurity Service Gap Assessment, we analyse the security status of your building technology systems, including processes, organisation and on-site technology. You will receive a detailed overview of possible points of attack as well as concrete recommendations for action to close these security gaps and reduce cyber risks.

Take the Test: How Secure is Your Building Technology?

With our two free quick checks, you get an initial overview of how your organization is positioned in the areas of physical security and cybersecurity.

Secure the outside, what counts inside!

Perimeter protection as a comprehensive concept.

Customer references

Cybersecurity in Practice

Example Healthcare: Klinik Oberwart

As a newly established medical care center, Klinik Oberwart aims to create a secure facility. One focus was NIS2 compliance to strengthen resilience and increase cyber protection.

Thoughtful doctor with tablet PC in medical clinic.

More

Example Charging Infrastructure: Aral Pulse

Since the operation of electric charging infrastructure has recently fallen under the NIS2 conditions of critical infrastructure, the concept of communication and security structure has been completely revised.

Hero-Website-Aral-Pulse-2560x1440

More

FAQ KRITIS Umbrella Act and NIS2