KRITIS in the Compliance Jungle - Successfully Leveraging Synergies between Laws and Standards
The BSI Act forms the legal foundation of German KRITIS regulation and defines in § 8a the central obligations for operators of critical infrastructures. Since the last amendment, KRITIS companies must not only take appropriate organizational and technical precautions but also provide proof of compliance with minimum standards every two years - either through ISO 27001 certification or IT-Grundschutz attestations. The IT Security Act 2.0 has significantly tightened these requirements and granted the BSI new enforcement capabilities, including expanding the consideration to the entire supply chain and extending reporting obligations even for attempted attacks.
Key Insights:
Integrated ISMS structures consolidate all regulatory requirements under one roof Automation through GRC tools minimizes compliance risks and reduces efforts Proactive integration optimally prepares for future regulatory developments The NIS2 Directive significantly expands the circle of regulated companies and harmonizes cybersecurity requirements at the European level. While the German KRITIS regime previously focused on a few particularly critical sectors, NIS2 brings new areas such as social security, expanded areas of the energy sector, and digital services into the regulatory scope. For companies already subject to KRITIS, this means a duplication of supervisory structures and partially different requirements for risk management and reporting procedures, while the directive introduces uniform sanction mechanisms with fines of up to 2% of the worldwide annual turnover.
The General Data Protection Regulation creates important points of contact with KRITIS regulation, as both frameworks aim to protect critical information and systems. Especially in the case of cybersecurity incidents, the reporting obligations overlap: while IT security disruptions must be reported to the BSI under the BSIG, the GDPR requires parallel reporting to the data protection authority within 72 hours in the event of data breaches. The technical and organizational measures under Art. 32 GDPR complement the KRITIS minimum standards with data protection-specific security requirements, requiring companies to design their ISMS structures to address both cybersecurity and privacy requirements in an integrated manner.
Industry-Specific Regulation: Sectoral Deep Dives
Energy Sector: EnWG
The Energy Industry Act (EnWG) supplements general KRITIS requirements with specific regulations for energy supply, creating partially parallel compliance structures. Sections 11 and 16b EnWG obligate energy supply companies to ensure supply security, explicitly including cybersecurity measures. While KRITIS operators direct their reports to the BSI, energy companies must also inform the Federal Network Agency about disruptions, leading to dual reporting obligations and differing assessment criteria.
Healthcare: KHZG
The Hospital Future Act (KHZG) links digitalization funding with cybersecurity requirements, creating new compliance dimensions for healthcare institutions. Funding for digital infrastructures is tied to the demonstration of adequate IT security measures, effectively requiring hospitals to implement KHZG security standards parallel to KRITIS requirements. This becomes particularly complex due to the special protection requirements for patient data, which go beyond general GDPR provisions and require specific security architectures.
Aviation: LuftSiG
The Aviation Security Act (LuftSiG) expands traditional aviation security to include cybersecurity aspects, bridging the gap between physical and digital security. Airports and air navigation service providers must meet not only KRITIS requirements but also specific aviation security standards that implement international ICAO guidelines, which are often stricter than general IT security regulations. Critical Air Traffic Management systems are subject to both national and international oversight, requiring complex coordination processes between various authorities.
Synergies and Overlaps: Efficiency through Integration
Common Governance Structures
An integrated Information Security Management System (ISMS) can serve as an overarching structure coordinating all compliance requirements from KRITIS to NIS2, GDPR, and industry-specific regulations. By establishing unified governance bodies that address IT security, data protection, and industry-specific compliance issues, duplicate structures can be avoided and decision-making processes accelerated. Risk management particularly benefits from this integration, as many threat scenarios affect multiple regulations simultaneously, and a holistic assessment is more effective than separate risk analyses for each standard.
Automation and Tool Support
Modern GRC platforms (Governance, Risk & Compliance) allow managing various regulatory requirements in a unified system, automatically identifying and utilizing overlaps. Monitoring systems can simultaneously oversee compliance with KRITIS minimum standards, ISO 27001 controls, and GDPR measures, while automated reporting functions efficiently fulfill the various reporting obligations to BSI, data protection authorities, and specialist supervisory authorities. The integration of incident response processes into these platforms ensures that in the event of security incidents, all relevant reporting paths are automatically triggered, and different reporting deadlines are met, significantly reducing the risk of compliance violations.
Step by Step to a Certifiable ISMS
With the fuentis ISMS tool, you implement current standards automatically and efficiently. Our turnkey modules, workflows, and expert support make building an ISMS simple and time-saving—whether you're starting from scratch or adapting existing systems.
Multi-Compliance ISMS
A comprehensive ISMS tool that easily guides you to ISO 27001 certification while covering other compliance requirements. We speak compliance, whether it's Grundschutz, TISAX®, or NIS2.
Automated Processes
Automated ISMS processes and workflows guide you step-by-step through the certification process—even without prior knowledge.
Review Questionnaires
Simple and customizable questionnaires that help you quickly and clearly determine protection needs. Risk-based information security has never been easier.
Personal Support
Personal support from experienced consultants who clearly explain what needs to be done—from the initial analysis to audit support.
Synergies and Overlaps: Efficiency through Integration
Common Governance Structures
An integrated Information Security Management System (ISMS) can serve as an overarching structure coordinating all compliance requirements from KRITIS to NIS2, GDPR, and industry-specific regulations. By establishing unified governance bodies that address IT security, data protection, and industry-specific compliance issues, duplicate structures can be avoided and decision-making processes accelerated. Risk management particularly benefits from this integration, as many threat scenarios affect multiple regulations simultaneously, and a holistic assessment is more effective than separate risk analyses for each standard.
Automation and Tool Support
Modern GRC platforms (Governance, Risk & Compliance) allow managing various regulatory requirements in a unified system, automatically identifying and utilizing overlaps. Monitoring systems can simultaneously oversee compliance with KRITIS minimum standards, ISO 27001 controls, and GDPR measures, while automated reporting functions efficiently fulfill the various reporting obligations to BSI, data protection authorities, and specialist supervisory authorities. The integration of incident response processes into these platforms ensures that in the event of security incidents, all relevant reporting paths are automatically triggered, and different reporting deadlines are met, significantly reducing the risk of compliance violations.
Conclusion
The compliance landscape for KRITIS companies is becoming increasingly complex due to the multitude of overlapping laws, directives, and standards, but it also offers significant efficiency potentials through intelligent integration. While the BSI Act, IT Security Act, NIS2, and GDPR form the overarching regulatory framework, industry-specific requirements such as EnWG, KHZG, and LuftSiG complement this with sectoral specifics. The key to successfully managing this complexity lies in establishing integrated ISMS structures that unite all requirements under one roof and are supported by automation and modern GRC tools. Companies that adopt these holistic approaches early can not only minimize compliance risks and reduce costs but also optimally prepare for future regulatory developments.

Srdan Manasijevic
CEO
Expert in information security, data protection and risk management with extensive experience advising enterprises and public-sector organizations. Specialized in ISO 27001, BSI and advanced risk methodologies.


