Skip to main content
Solid Siemens deep blue background color.

KRITIS & NIS2: Security for critical infrastructures

Increasing attacks on critical infrastructures make it necessary to implement targeted legal measures to provide greater protection for properties and facilities in the future. We support you with our physical security and cybersecurity solutions. Implement the legal requirements directly at both levels – proven and reliable with one partner.

Image of an office building and security siveillance

Strengthen resilience against physical attacks and cyber threats

On 14 December 2022, the EU adopted the Critical Entities Resilience (CER) Directive to strengthen the physical security and resilience of critical infrastructures. The implementation into national law is carried out by the KRITIS framework law. In doing so, the legislator not only implements the requirements of the CER Directive, but also incorporates the requirements from the NIS2 Directive that apply to critical infrastructure. Thus, the KRITIS framework law contains requirements for both the physical and cybersecurity of critical infrastructures.

Whitepaper KRITIS Framework Act and NIS 2: Requirements and Protective Measures

The white paper explains the central requirements of both laws. It also shows how operators of critical infrastructures and industrial companies must analyze risks, implement effective protective measures and comply with reporting obligations, and why a holistic security approach is important to protect building infrastructure.

NIS2 and KRITIS law: Is your company affected?

The most important changes and our solutions at a glance

The KRITIS framework law aims to improve the resilience and responsiveness of critical infrastructures. It combines cybersecurity regulations with physical security regulations. The focus of the law is on the introduction of minimum standards for physical protection and the guarantee of security of supply.

Select...

Operators of critical plants are required to carry out a risk analysis and assessment of their properties. An initial analysis and evaluation will be carried out for the first time on 17 January 2026, and every four years thereafter. In this way, the risk assessment should be continuously reviewed and the security status of your building technology should be kept up-to-date according to any changes in your needs. With our Cybersecurity Service Gap Assessment, we analyze the security status of your building technology systems, including processes, organization and on-site technology. You will receive a detailed overview of possible points of attack as well as concrete recommendations for action to close these security gaps and reduce cyber risks.

Securing critical infrastructure

Why a holistic approach is key to KRITIS compliance.

Your partner for smart building security solutions

We support you in complying with the legal requirements with our many years of experience and know-how. Our extensive portfolio offers you tailor-made solutions for your individual needs, so that you not only achieve 360-degree protection for your building, but also optimize building use and business processes.

Select...

As a founding member of the Charter of Trust, we are committed to proactively providing and continuously developing the most modern protection of businesses and infrastructure. This includes a holistic approach that takes into account both cybersecurity and physical security. Secure by design means ensuring that our products and solutions are protected throughout their lifecycle – from initial product design that meets industry-specific requirements and regulations, to continuous monitoring, control and proactive defense to ensure business continuity.

c9535eff-9a54-464e-9c05-0960d993ad1b | Cybersecurity Visual 2022 1:1

FAQ KRITIS Umbrella Act and NIS2