Definition: KRITIS (Critical Infrastructure)
KRITIS is the German legal designation, defined in the BSI-Gesetz and specified by the BSI-KritisV regulation, for organizations operating infrastructure whose failure would cause sustained supply shortages or significant public safety disruption.
Core characteristics of KRITIS
A company becomes a KRITIS operator once it crosses a sector-specific supply threshold, not because of its industry label. Designation brings binding BSI obligations, not voluntary best practice.
- Ten regulated sectors: energy, water, food, IT/telecom, health, finance, transport, media/culture, state/administration, waste
- Regular threshold of 500,000 supplied persons
- Mandatory registration with the BSI’s reporting portal
- Continuous, state-of-the-art IT-security measures
KRITIS vs. NIS2
NIS2 is the EU-level cybersecurity directive every member state must transpose into national law. KRITIS is Germany’s own, older designation, now nested inside the broader NIS2 framework: a KRITIS operator automatically counts as an “especially important facility” under Germany’s transposition, layering governance duties on top of the older KRITIS rules.
Importance of KRITIS in enterprise AI
KRITIS status shapes how a company may deploy AI. Under the EU AI Act, AI systems used as safety components in energy, water, or gas supply are classified as high-risk AI systems, triggering conformity assessment and human oversight before deployment. Bitkom’s Wirtschaftsschutz 2025 study found companies attributing attacks to foreign intelligence services rose from 7% to 28% between 2023 and 2025, with energy suppliers a primary target.
Methods and procedures for KRITIS
Determining and maintaining KRITIS status follows a defined compliance sequence.
Threshold self-assessment
Every company in a regulated sector must periodically check supply volumes against the BSI-KritisV thresholds, before the BSI makes contact.
- Calculate supplied persons or comparable metrics annually
- Compare results against the applicable threshold
- Document the assessment for audit purposes
BSI IT-Grundschutz implementation
Once designated, operators must run an information security management system aligned with BSI IT-Grundschutz, the control catalog KRITIS audits measure against.
Incident reporting under Section 32 BSIG
Section 32 BSIG obliges operators to report significant IT-security incidents to the BSI without undue delay, via an initial report, an update, and a final report through the Melde- und Informationsportal (MIP).
Important KPIs for KRITIS
Operators track compliance and resilience metrics to demonstrate ongoing readiness.
Operational compliance metrics
- Incident report submitted within 24 hours: target 100%
- Audit findings closed within agreed deadlines: target >95%
- Systems covered by IT-Grundschutz baseline: target 100%
- Business continuity plans tested annually: target 100%
Strategic resilience metrics
Beyond compliance checkboxes, operators are measured on resilience outcomes. The BSI reported 1,231 registered KRITIS operators with 2,180 facilities as of June 30, 2026, showing the scale now under active supervision since the KRITIS-Dachgesetz took effect.
Quality and audit metrics
Mature programs track evidence completeness for the two-year audit cycle and the time needed to close control gaps.
Risk factors and controls for KRITIS
KRITIS operators face risks beyond generic IT security.
Regulatory and liability exposure
Missing a registration deadline or an incident report carries direct regulatory consequences and personal management liability risk.
- Fines for non-compliance with registration or reporting duties
- Personal liability for managing directors under Section 38 BSIG
- Reputational damage from public disclosure
Supply chain and third-party risk
Operators depend on vendors, cloud providers, and AI integrators who are not themselves regulated but whose failures propagate into the supply chain. Contractual requirements and vendor audits are now standard controls.
Physical resilience gaps
The KRITIS-Dachgesetz added binding duties for physical protection, crisis management, and personnel security that many operators previously treated as informal practice.
Practical example
A 260-employee regional water utility in Lower Saxony found during a routine review that its supply volume had crossed the BSI-KritisV threshold, making KRITIS registration mandatory. It had already automated meter-reading anomaly detection with an AI system but never assessed it against EU AI Act high-risk criteria. With an external compliance partner, it registered with the BSI, mapped the AI system as a safety-relevant component, and built a reporting workflow into its operations software.
- Automated evidence collection for the biennial IT-Grundschutz audit
- A structured 24/72-hour incident escalation workflow with clear ownership
- A registered AI system inventory covering the anomaly detection model
- Quarterly management reporting on KRITIS and NIS2 obligations
Current developments and effects
Germany’s KRITIS regime has expanded significantly since early 2026.
Sector expansion and physical resilience
The KRITIS-Dachgesetz, in force since March 17, 2026, added waste management as a tenth sector and made physical resilience a binding operator duty.
- New requirement for documented crisis management plans
- Personnel security screening for critical roles
- Coordination duties with regional civil protection authorities
Convergence with the Cyber Resilience Act
Hardware and software sold into KRITIS environments increasingly need to satisfy the EU Cyber Resilience Act’s security-by-design requirements before operators can procure them. Finance-sector KRITIS operators additionally face DORA, which sets parallel ICT resilience duties for banks and insurers.
Rising attack pressure
Gartner forecasts worldwide information security spending will reach $244.2 billion in 2026, a 13.3% increase, with critical infrastructure among the sectors driving the fastest growth as geopolitical targeting intensifies.
Conclusion
KRITIS designation turns critical infrastructure operation into a continuously audited legal obligation, not a reputational label. As the KRITIS-Dachgesetz and NIS2 stack duties on the original BSI-Gesetz framework, the compliance burden for qualifying Mittelstand companies keeps growing. Understanding whether a company crosses the relevant thresholds is now a prerequisite for any AI deployment touching supply-critical processes. Companies that build compliance into their operating rhythm early avoid scrambling at the next audit cycle.
Frequently Asked Questions
What makes a company a KRITIS operator?
A company qualifies once its supply volume in a regulated sector, such as energy, water, or health, exceeds the BSI-KritisV threshold, most commonly 500,000 supplied persons. Designation rests on measurable supply data, not company size.
How does KRITIS relate to NIS2?
NIS2 sets a cybersecurity baseline across the EU, while KRITIS is Germany’s stricter, pre-existing designation for the highest-criticality operators. Under Germany’s transposition, KRITIS operators count as especially important facilities, so both obligations apply together.
Does KRITIS status apply to smaller Mittelstand companies?
Yes, if supply volumes cross the threshold. A regional water utility or hospital group with a few hundred employees can qualify just as easily as a national provider, since thresholds rest on people supplied, not headcount.
What does KRITIS mean for AI systems we deploy?
An AI system used as a safety component in energy or water supply is classified as high-risk under the EU AI Act, requiring conformity assessment and documented human oversight before go-live.
Do we need our own IT security team to become KRITIS-compliant?
Not necessarily. Many Mittelstand operators work with external partners to implement BSI IT-Grundschutz and manage the audit cycle, while keeping internal ownership of risk assessment and reporting.
What happens if a KRITIS operator misses an incident report deadline?
Missing the Section 32 BSIG deadlines can trigger fines and, under the newer rules, personal liability for managing directors. Operators typically automate monitoring and escalation to avoid missing the initial notification window.