COMPLIANCE · KRITIS
KRITIS demandsstate-of-the-art proofevery three years.
Under the new BSI-Gesetz, operators of critical installations must demonstrate to the BSI every three years – through security audits, reviews or certifications under §39 BSIG – that their security measures are implemented. We deliver the technical evidence that prüfende Stellen and the BSI accept.
01 · SCOPE
Who is in scope – and what changed on 6 December 2025.
KRITIS covers operators of critical installations across energy, water, food, information technology and telecommunications, health, finance, social insurance and basic income support, transport, as well as municipal waste disposal. The BSI-Kritisverordnung defines the thresholds above which an installation counts as a kritische Anlage. Since 6 December 2025 the BSI-Gesetz as recast by the NIS2UmsuCG applies: §8a BSIG a. F. is gone, the operator duties now sit in §§30 and 31 BSIG, the reporting duty in §32 BSIG and the evidence obligation in §39 BSIG – on a three-year rather than a two-year cycle.
02 · OBLIGATIONS
What the BSI-Gesetz requires from operators of critical installations.
- BLOCK · 01
Risk management (§30 BSIG)
§30 BSIG requires appropriate, proportionate and effective technical and organisational measures – from risk analysis through supply chain security to cryptography and access control. It explicitly demands policies and procedures for assessing the effectiveness of those measures; that effectiveness is exactly what we test.
- BLOCK · 02
Attack detection (§31 BSIG)
For critical installations, §31 Abs. 1 BSIG treats measures beyond the general protection level as proportionate as long as the effort they require is not out of proportion to the consequences of an outage or impairment of the installation; §31 Abs. 2 BSIG additionally requires systems for attack detection that continuously and automatically capture and evaluate parameters from live operations. We test detection coverage against realistic attack paths and document where signals are missing or unreliable.
- BLOCK · 03
Incident reporting (§32 BSIG)
Under §32 BSIG, significant security incidents must be reported within 24 hours as an early warning, within 72 hours as an assessed notification and after one month at the latest as a final report; operators of critical installations add details on the affected installation and service. We deliver the technical analysis that holds up under that time pressure – and prepare the forensic baseline to back it up.
- BLOCK · 04
Evidence every three years (§39 BSIG)
§39 Abs. 1 BSIG requires operators to demonstrate implementation every three years through security audits, reviews or certifications – including the security deficiencies those uncover. If your evidence deadline under the old rules would have expired within twelve months of entry into force, you may still file under the previous requirements during that window (§39 Abs. 3 BSIG).
03 · OUR CONTRIBUTION
How we feed the §39 BSIG evidence.
The evidence stands or falls on the quality of the underlying findings. We test the relevant attack paths against operational and IT systems and map the findings to the Prüfgrundlage that the prüfende Stelle defines. Branchenspezifische Sicherheitsstandards, which operators may propose under §30 Abs. 9 BSIG and whose suitability the BSI confirms, are – per the BSI's own Orientierungshilfe – the starting point for that Prüfgrundlage, not the Prüfgrundlage itself. Our retest results close the loop and feed directly into the report the prüfende Stelle submits to the BSI.
§39 PREPARATION
The next evidence deadline arrives faster than you think.
Under §39 Abs. 3 BSIG, the BSI sets the new evidence date – at the earliest three years after the last evidence submitted under §8a Abs. 3 BSIG a. F. We review with you the open findings from that submission, the gap to the current state of the art and the test scope for the one ahead.
