Skip to content

KRITIS-DG

KRITIS-Dachgesetz is physical and digital. So is the platform.

The German transposition of the EU CER Directive covers physical security, supply-chain resilience and organisational continuity on top of cybersecurity. KaitoSec runs all of it on the same data model as your ISMS, BCMS and DSMS.

CER critical-entity sectors transposed into German law
11 sectors
KRITIS-DG and NIS2 cross-mapped onto the same controls
2 regimes
ISO 22301 BC plans serve KRITIS-DG continuity evidence
1 BCMS

One control, several standards

Do the work once, satisfy it everywhere

Standards overlap far more than they differ. A control entered once is mapped to every framework whose requirement it answers, so the second audit inherits the evidence from the first.

One control, entered once, satisfies a requirement in each of the standards listed below.

One control

Supplier & third-party due diligence

  • KRITIS-DGRequirement satisfied
  • ISO 27001Requirement satisfied
  • ISO 22301Requirement satisfied
  • NIS2Requirement satisfied
  • GDPRRequirement satisfied

From control to policy

Where a control ends up

A control is not a line in a register. It belongs to a management system, and it is carried by the policies and procedures your people actually read, so it flows through both.

One control feeds the four management systems, which in turn carry it into the policies and procedures listed below.

One control

Supplier & third-party due diligence

Management systems

  • BCMSBusiness continuity
  • ISMSInformation security
  • DSMSData protection
  • AIMSAI governance

Policies and procedures

  • Information security policy
  • Supplier policy
  • Continuity plan

What changes for your team

01

Beyond cybersecurity

KRITIS-DG obliges operators of critical entities beyond cybersecurity: physical security, supply chain resilience and organisational continuity. KaitoSec models those layers on one inventory.

02

One resilience programme, two regimes

Most KRITIS operators carry both KRITIS-DG and NIS2 obligations. KaitoSec maps the two regimes against the same controls so an investment made for one is captured as evidence for the other. That leaves no parallel programmes and no duplicate audit cycles.

03

BCMS and physical security on one inventory

The ISO 22301 BCMS, the asset register, the supplier list and the physical-site catalogue live in one workspace. A failure of a primary site, a supplier or an ICT system traces through the same BIA chain that feeds your CER reporting.

The workflow

01

Track obligations, evidence and deadlines

A single view of your KRITIS-DG obligations: sector classification, designated entities, physical security measures, BC plans, incident notifications and supervisory deadlines. Each obligation shows ownership, evidence status and the next supervisory checkpoint.

02

Physical and ICT asset register on one model

Sites, perimeters, controlled areas, ICT systems and processing activities share the same inventory. The KRITIS-DG resilience plan and the ISO 22301 BIA both read from the same source.

03

Incident notification and reporting

KRITIS-DG inherits the EU CER incident notification structure. KaitoSec calculates the relevant reporting deadlines, pre-fills the notification template, and connects the supervisory submission to the same incident workflow that feeds NIS2 reporting.

FAQ

What is the KRITIS-Dachgesetz?

The KRITIS-Dachgesetz is the German law transposing the EU Critical Entities Resilience (CER) Directive 2022/2557, in force since March 2026. It defines critical entities across 11 sectors and obliges their operators to maintain physical security, business continuity and supply-chain resilience measures, on top of the cybersecurity obligations that NIS2 imposes.

How does KRITIS-DG relate to NIS2 and BSIG?

NIS2 (transposed in Germany through NIS2UmsuCG) governs cybersecurity for critical and important entities. KRITIS-DG governs physical and organisational resilience for critical entities. The two regimes overlap heavily for operators and are intended to be implemented together. BSIG covers reporting and obligations for KRITIS operators historically and is updated alongside the new regimes. For a deeper comparison, see how KRITIS-DG and NIS2 relate in practice.

Who is in scope of KRITIS-DG?

Operators in 11 sectors including energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space and food. The Bundesamt für Bevölkerungsschutz und Katastrophenhilfe (BBK) plays the supervisory role together with the BSI for cyber matters.

We already run NIS2. What does KRITIS-DG add?

Most of your cybersecurity controls already serve KRITIS-DG. What KRITIS-DG adds is the physical, organisational and supply-chain resilience dimension: site security, BC plans for non-ICT disruption, supplier resilience and resilience plans for the entity as a whole. KaitoSec models these on top of the same asset register your ISMS and BCMS already use.