01
Beyond cybersecurity
KRITIS-DG obliges operators of critical entities beyond cybersecurity: physical security, supply chain resilience and organisational continuity. KaitoSec models those layers on one inventory.
KRITIS-DG
The German transposition of the EU CER Directive covers physical security, supply-chain resilience and organisational continuity on top of cybersecurity. KaitoSec runs all of it on the same data model as your ISMS, BCMS and DSMS.
One control, several standards
Standards overlap far more than they differ. A control entered once is mapped to every framework whose requirement it answers, so the second audit inherits the evidence from the first.
One control
Supplier & third-party due diligence
From control to policy
A control is not a line in a register. It belongs to a management system, and it is carried by the policies and procedures your people actually read, so it flows through both.
One control
Supplier & third-party due diligence
Management systems
Policies and procedures
01
KRITIS-DG obliges operators of critical entities beyond cybersecurity: physical security, supply chain resilience and organisational continuity. KaitoSec models those layers on one inventory.
02
Most KRITIS operators carry both KRITIS-DG and NIS2 obligations. KaitoSec maps the two regimes against the same controls so an investment made for one is captured as evidence for the other. That leaves no parallel programmes and no duplicate audit cycles.
03
The ISO 22301 BCMS, the asset register, the supplier list and the physical-site catalogue live in one workspace. A failure of a primary site, a supplier or an ICT system traces through the same BIA chain that feeds your CER reporting.
01
A single view of your KRITIS-DG obligations: sector classification, designated entities, physical security measures, BC plans, incident notifications and supervisory deadlines. Each obligation shows ownership, evidence status and the next supervisory checkpoint.
02
Sites, perimeters, controlled areas, ICT systems and processing activities share the same inventory. The KRITIS-DG resilience plan and the ISO 22301 BIA both read from the same source.
03
KRITIS-DG inherits the EU CER incident notification structure. KaitoSec calculates the relevant reporting deadlines, pre-fills the notification template, and connects the supervisory submission to the same incident workflow that feeds NIS2 reporting.
The KRITIS-Dachgesetz is the German law transposing the EU Critical Entities Resilience (CER) Directive 2022/2557, in force since March 2026. It defines critical entities across 11 sectors and obliges their operators to maintain physical security, business continuity and supply-chain resilience measures, on top of the cybersecurity obligations that NIS2 imposes.
NIS2 (transposed in Germany through NIS2UmsuCG) governs cybersecurity for critical and important entities. KRITIS-DG governs physical and organisational resilience for critical entities. The two regimes overlap heavily for operators and are intended to be implemented together. BSIG covers reporting and obligations for KRITIS operators historically and is updated alongside the new regimes. For a deeper comparison, see how KRITIS-DG and NIS2 relate in practice.
Operators in 11 sectors including energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space and food. The Bundesamt für Bevölkerungsschutz und Katastrophenhilfe (BBK) plays the supervisory role together with the BSI for cyber matters.
Most of your cybersecurity controls already serve KRITIS-DG. What KRITIS-DG adds is the physical, organisational and supply-chain resilience dimension: site security, BC plans for non-ICT disruption, supplier resilience and resilience plans for the entity as a whole. KaitoSec models these on top of the same asset register your ISMS and BCMS already use.