Skip to content

KRITIS · Energy

NIS2, KRITIS evidence and the IT security catalogue in one system

KaitoSec brings information security, business continuity and data protection for energy utilities together in one data model. You work to ISO 27001 or BSI IT-Grundschutz, connect the OT landscape through integrations and produce the evidence records under Section 39 BSIG from live operations.

Catalog matrix in KaitoSec: fourteen ISO 27001 controls from chapter A.8 with their fulfilment and, beside each, the number of mapped requirements from DORA, NIS2 and SOC 2.
Counts for DORA, NIS2 and SOC 2
  • TeleTrusT trust seal, IT Security made in Germany
  • Member of BITMi, Bundesverband IT-Mittelstand e. V.
  • OMR Reviews5.0 out of 5
  • HOSTING INGERMANY
  • GDPR-COMPLIANT
  • GRUNDSCHUTZ++ READY

Four rulebooks, the same assets, the same auditor

Each rulebook on its own is manageable. What gets expensive is the duplicated upkeep: the same assets, processes and risks, documented four times and kept current four times.

  1. NIS2: Risk management and reporting duties

    NIS2 demands state-of-the-art measures, incident reporting on short deadlines and personal accountability of executive management. Implementation has to be demonstrable, not asserted.

  2. § 31, § 39 BSIG: Attack detection and evidence every three years

    Operators of critical installations have to run attack detection systems that evaluate operating parameters continuously and automatically, and evidence that every three years through security audits, inspections or certifications. What is required is current documentation, not a snapshot from the week before the date.

  3. § 11 EnWG: IT security catalogue with mandatory certification

    For grid operators, the Bundesnetzagentur's IT security catalogue requires a certified ISMS based on ISO 27001. The standard path is often set; the NIS2 duties come on top.

  4. Operations: Resilience counts, not the certificate

    Security of supply demands continuity: backup management, crisis organisation and recovery are among the NIS2 minimum measures and part of the audit expectation. A certificate keeps no plant running.

One data model instead of four binders

You maintain every requirement, every asset and every risk once. KaitoSec maps them to NIS2, ISO 27001, BSI IT-Grundschutz and the KRITIS evidence. Regulatory ballast shrinks because overlaps collapse instead of adding up.

  • Common today: One catalogue per rulebook, maintained in Excel and Word.

    With KaitoSec: One requirement, mapped to NIS2, ISO 27001, BSI IT-Grundschutz and the KRITIS evidence.

  • Common today: The OT landscape lives in a separate list kept by control engineering.

    With KaitoSec: IT and OT sit in the same model as assets with protection needs and dependencies.

  • Common today: BCM is a Word emergency handbook next to the ISMS.

    With KaitoSec: BIA, recovery plans and exercises work on the same assets and processes.

  • Common today: The evidence sprint starts before the KRITIS audit.

    With KaitoSec: Audit documentation accumulates during operations, every change with an audit trail.

  • Common today: Contributions from the group arrive by circular e-mail.

    With KaitoSec: AI interviews and the accountability portal collect contributions in structure.

  • Common today: Every catalogue update becomes a new project.

    With KaitoSec: Updated catalogues flow into the existing mapping; you work through the delta.

  1. The OT landscape belongs in the management system

    Grid control, substations and telecontrol carry the same protection needs as any server estate. KaitoSec models both in one structural model.

    • Assets instead of island lists. Control rooms, substations, telecontrol and business applications sit in the model as assets, with owners, protection needs and dependencies between IT and OT.
    • Protection needs with inheritance. Protection needs are assessed on the process and inherited along dependencies to installations and systems. The assessment stays consistent as the landscape changes.
    • Live state through integrations. Connections to EDR and XDR systems feed inventory and state data into the platform. What your systems already know, nobody types in again.
    Protection rating of an ERP database: confidentiality high, integrity very high, availability high, giving an elevated protection level, with rationale.
  2. BCMS built in, not bolted on

    NIS2 explicitly counts continuity among the minimum measures: backup management, crisis management, recovery. In KaitoSec, the BCMS is part of the same system, not a second tool.

    • BIA on real processes. The business impact analysis uses the same processes and assets as the ISMS. Recovery times and dependencies live on the object, not in a document's annex.
    • Plans that match the estate. Emergency and recovery plans reference the assets directly. When an installation changes, you see which plan has gone stale.
    • Exercises with evidence. Exercises are planned, run and documented. Findings return to the management system as measures and are demonstrable at the next audit.
    Impact development of a process over time: for each category, when the damage turns medium, high or critical, from one hour to two weeks.
  3. Contributions from the group without chasing people

    Energy utilities spread accountability across entities: grid, generation, retail, shareholdings. KaitoSec collects the information where it lives.

    • AI interviews. Subject-matter owners answer questions in a guided interview. Answers land structured on the requirement and the asset, not as free text in an inbox.
    • Accountability portal. Tasks reach owners as assigned work items with deadline and context. Feedback and evidence return to the management system, documented.
    • Continuous, not annual. Reviews and resubmissions keep entries current. Collection is routine during operations, not a yearly campaign before the audit date.
    Two KaitoSec AI suggestions for the Statement of Applicability: one applied, one declined, both with the proposed justification.
  4. The orchestration layer for governance, continuity and data protection

    KaitoSec connects the systems you already run and becomes the central layer above governance, continuity and data protection work.

    • MCP server for local AI. Your local AI systems access your data through the MCP server: your own dashboards, analyses, patch priorities. You quickly see which systems need patching, and the data stays with you.
    • Open API for legacy systems. You connect existing systems with an API yourself or together with us. Once connected, they deliver continuously instead of via manual export.
    • EDR and XDR connected. Security tooling reports status and findings straight into the management system. Controls are checked against the live state instead of the last self-assessment.
    Import wizard: the columns of a CSV file are matched to the inventory fields automatically.
  5. Hosted in Germany, on-premise capable

    For KRITIS operators, the place of operation is not a footnote. You decide where the system runs and who has access.

    • Hosting in Germany. Operations run sovereign in Germany. No dependency on jurisdictions your auditor will question.
    • On-premise operation. On request, KaitoSec runs in your own infrastructure, behind your network boundary and under your operational control.
    • Data sovereignty with audit trail. Every change and every approval is documented on the object. You can always see who decided what, and why.
    A rejected piece of evidence for patch management with its reason: export without a date, two servers missing from the list. Below it, an accepted one.
Protection rating of an ERP database: confidentiality high, integrity very high, availability high, giving an elevated protection level, with rationale.

Inventory and state of IT and OT come from the systems you already run.

100+ integrations

All integrations
  • Microsoft Defender
  • PRTG
  • macmon NAC
  • i-doit
  • Docusnap 365
  • Matrix42
  • Microsoft Entra ID
  • Microsoft Intune
  • Personio
  • Microsoft Defender
  • PRTG
  • macmon NAC
  • i-doit
  • Docusnap 365
  • Matrix42
  • Microsoft Entra ID
  • Microsoft Intune
  • Personio
  • AWS
  • Microsoft Azure
  • Google Cloud
  • SharePoint Online
  • Confluence
  • Jira
  • Microsoft Teams
  • Excel & CSV
  • AWS
  • Microsoft Azure
  • Google Cloud
  • SharePoint Online
  • Confluence
  • Jira
  • Microsoft Teams
  • Excel & CSV

Frequent questions from energy utilities

We work to BSI IT-Grundschutz, not ISO 27001. Does that fit?

Yes. KaitoSec ships both paths with the corresponding catalogues, and the NIS2 requirements are mapped to both. The choice of standard stays with you and your auditor.

How does our OT landscape get into the system?

Through the structural model: control technology, substations and telecontrol become assets with protection needs and dependencies. Inventory and state data arrive through integrations and the open API, including from legacy systems with their own interface.

Does KaitoSec support the evidence records under Section 39 BSIG?

The evidence records accumulate from live operations: control status, risk treatment and documents per requirement, with an audit trail. The auditing body and the approval stay with you.

Does KaitoSec run on-premise?

Yes. You choose between sovereign operation in Germany and installation in your own infrastructure.

One system for NIS2 and the KRITIS evidence.

A personal demo in 30 minutes: bring your standard, your OT landscape and the next audit date. Using your own case, we show you how the data model ends the duplicated upkeep.