KRITIS Ongoing Compliance: Continuous Obligations for Critical Infrastructure Operators
KRITIS compliance does not end with initial implementation. Operators must continuously maintain their ISMS, provide evidence to the BSI every two years, and report incidents within 24 hours. We ensure your sustained compliance.
- ✓Continuous monitoring of compliance status
- ✓Proactive identification and remediation of deviations
- ✓Automated monitoring and reporting systems
- ✓Timely adaptation to new regulatory requirements
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
- Your strategic goals and objectives
- Desired business outcomes and ROI
- Steps already taken
Or contact us directly:
Certifications, Partners and more...










What Does Ongoing KRITIS Compliance Require From Operators?
Our Strengths
- Deep expertise in KRITIS regulation and continuous compliance management
- Years of experience supporting critical infrastructure across various sectors
- Effective technology solutions for automated compliance monitoring
- Proactive approach with continuous adaptation to new requirements
Important for KRITIS Operators
Since 2026, KRITIS operators must register with both the BSI and the BBK. The deadline for BBK registration is July 17, 2026. Failure to comply can result in fines of up to 2 million euros.
ADVISORI in Numbers
11+
Years of Experience
120+
Employees
520+
Projects
We work with you to develop a systematic Ongoing Compliance Management that combines continuous monitoring with proactive risk management.
Our Approach:
Establishing continuous monitoring and assessment processes
Implementing automated compliance monitoring systems
Regular risk assessments and adjustment of protective measures
Proactive identification and treatment of compliance deviations
Continuous optimization and adaptation to new requirements
"KRITIS compliance is a continuous process that requires proactive monitoring and timely adjustments. Our Ongoing Compliance approach ensures that critical infrastructure remains permanently protected and compliant, even in the face of evolving threat landscapes."

Sarah Richter
Head of Information Security, Cyber Security
Expertise & Experience:
10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security
Our Services
We offer you tailored solutions for your digital transformation
Continuous Compliance Monitoring
We establish comprehensive monitoring systems that continuously monitor the compliance status of your critical infrastructure and provide early warning of deviations.
- Automated monitoring of all relevant IT security measures
- Real-time alerting for critical security events
- Regular compliance dashboards and status reports
- Integration with existing monitoring and SIEM systems
Proactive Risk and Gap Analyses
We conduct regular risk assessments and proactively identify potential compliance gaps before they become critical problems.
- Quarterly risk assessments and threat analyses
- Identification and prioritization of compliance gaps
- Development and implementation of action plans
- Continuous adaptation to new threat situations
Threat Intelligence and Threat Analysis
We establish continuous threat intelligence processes that identify new threats early and assess their relevance for your specific infrastructure.
- Integration of external and internal Threat Intelligence sources
- Automated threat correlation and assessment
- Specific risk assessment for critical infrastructures
- Regular Threat Briefings and Executive Reports
Agile Process Adaptation and Optimization
We implement agile methods for fast and effective adaptation of your KRITIS processes to new threat situations and changed requirements.
- Agile process modeling and optimization
- Rapid prototyping of new security measures
- Iterative implementation and testing
- Continuous feedback integration and improvement
Role-specific KRITIS Training Programs
We develop customized training programs for different roles and responsibilities in critical infrastructures, from management to operational employees.
- Executive training on strategic KRITIS security aspects
- IT administrator training on technical protective measures
- Operator training on security-relevant operational processes
- General employee awareness on basic security principles
Continuous Awareness Campaigns
We implement permanent awareness programs that continuously maintain security awareness and address current threats.
- Regular threat intelligence updates and warnings
- Phishing simulations and social engineering tests
- Interactive e-learning modules and microlearning units
- Gamification approaches to increase learning motivation
Our Competencies
Choose the area that fits your requirements
The KRITIS regulation requires regular tests and audits for continuous validation of IT security measures. We conduct systematic reviews that not only meet regulatory requirements but also provide valuable insights for continuous improvement of your security architecture.
More Services in Regulatory Compliance Management
Frequently Asked Questions about KRITIS Ongoing Compliance
How often must KRITIS operators provide compliance evidence under §8a BSIG?
KRITIS operators must demonstrate to the BSI every two years that they have implemented appropriate organizational and technical measures to prevent disruptions. Evidence is provided through security audits, assessments or certifications — such as ISO 27001 or BSI IT-Grundschutz. ADVISORI supports the preparation, execution and follow-up of these compliance audits.
What are the incident reporting obligations for KRITIS operators?
Significant disruptions to IT systems must be reported to the BSI immediately, no later than within 24 hours. A detailed report is required within 72 hours. With NIS2 and the KRITIS Umbrella Act, additional reporting obligations to the BBK for physical security incidents apply. We help you establish clear reporting processes and meet all deadlines.
What changes for KRITIS operators under NIS2 and the KRITIS Umbrella Act?
NIS2 significantly expands the scope of affected organizations and tightens requirements: executives are personally liable for cybersecurity oversight, reporting obligations become stricter, and higher fines apply (up to EUR 10 million or 2% of global annual turnover). The KRITIS Umbrella Act adds physical security requirements and mandates registration with the BBK by July 2026.
How does ongoing KRITIS compliance differ from initial implementation?
Initial implementation establishes the ISMS, technical safeguards and processes. Ongoing compliance covers continuous monitoring, regular risk assessments, adaptation to new threats and regulatory changes, staff training, and the recurring §8a audit every two years. Without systematic ongoing compliance management, gaps emerge that will surface during the next audit.
What penalties apply for non-compliance with KRITIS requirements?
Violations of KRITIS requirements can result in fines of up to EUR 2 million under the KRITIS Umbrella Act. Under NIS2, penalties increase to up to EUR 10 million or 2% of global annual turnover for essential entities. Additionally, there are reputational risks and — under NIS2 — personal liability for executives.
What role does an ISMS play in ongoing KRITIS compliance?
An Information Security Management System (ISMS) based on ISO 27001 or BSI IT-Grundschutz forms the backbone of ongoing KRITIS compliance. It structures risk assessments, documents measures, manages incident response and provides the framework for the §8a compliance audit. Continuous maintenance and development of the ISMS is essential to keep pace with new threats and requirements.
How does ADVISORI support ongoing KRITIS compliance?
ADVISORI offers a comprehensive ongoing compliance package: continuous compliance monitoring, regular gap analyses and risk assessments, preparation and support for §8a audits, assistance with reporting obligations, employee training, and adaptation of your ISMS to new requirements such as NIS2 and the KRITIS Umbrella Act.
What training obligations apply to KRITIS operators under NIS2?
The NIS2 Implementation Act (NIS2UmsuCG), effective since December 2025, requires KRITIS operators to conduct regular cybersecurity training for all employees. Management must personally participate in risk management and IT security training — this obligation cannot be delegated. Additionally, Section 8a of the BSI Act requires proof of adequate organizational measures, which explicitly includes training programs. Violations can result in fines of up to 10 million euros or 2 percent of annual turnover.
What topics must a KRITIS training program cover?
A BSI-compliant KRITIS training covers: recognition of phishing and social engineering, secure handling of credentials and access rights, incident reporting procedures, sector-specific threat scenarios for your KRITIS sector, physical security in critical areas, and NIS2 compliance fundamentals. Content is tailored to specific roles — executives receive different focus areas than operational staff or IT specialists.
How often must KRITIS employees be trained?
KRITIS operators must demonstrate adequate security measures to the BSI every two years. In practice, this means: annual mandatory training for all employees at minimum, quarterly phishing simulations for effectiveness monitoring, and ad-hoc training for new threat situations or after security incidents. Continuous awareness campaigns with monthly micro-content complement the formal training sessions.
What is the difference between an awareness campaign and KRITIS training?
KRITIS training is a structured program with defined learning objectives, attendance verification, and knowledge testing — it fulfills regulatory requirements of the BSI Act and NIS2 Directive. An awareness campaign is a complementary measure that maintains security consciousness in daily work: through posters, short videos, simulated phishing emails, or interactive quiz formats. Both elements work together and are jointly required for KRITIS operators.
How is the effectiveness of KRITIS training measured?
Effectiveness is measured through multiple KPIs: phishing simulation rates (click rates before and after training), knowledge test results, number of security incidents reported by employees, average incident response time, and BSI audit outcomes. ADVISORI provides a reporting dashboard with these metrics so you can demonstrate training progress to auditors and management.
Which KRITIS sectors have special training requirements?
All eight KRITIS sectors (energy, water, food, IT and telecommunications, healthcare, finance and insurance, transport and traffic, municipal waste disposal) have fundamental training obligations. Particularly stringent requirements apply in healthcare (patient safety), energy (OT security for control systems), and finance (BaFin requirements in addition to BSI). Our training content is adapted to each sector.
How long does it take to implement a KRITIS training program?
Implementing a KRITIS training program typically takes 4 to 8 weeks: needs analysis and concept development (1‑2 weeks), creation of role-specific content (2‑3 weeks), pilot delivery and refinement (1‑2 weeks), rollout and awareness campaign launch (1 week). Costs depend on organization size, number of sectors, and preferred training formats — contact us for a customized proposal.
How often must KRITIS operators review and adapt their security processes?
The law sets no fixed interval for ongoing adaptation — what matters is that measures reflect the state of the art. Evidence is provided to the BSI on a two-year cycle, which is currently shifting from §8a BSIG to the new §§30 and 31 BSIG under the German NIS2 implementation act. Common practice is an annual review cycle supplemented by event-driven adaptations. We anchor both levels in your ISMS.
Which events trigger an immediate adaptation of KRITIS security processes?
Event-driven adaptation applies to new BSI warnings or advisories affecting products you operate, security incidents at your organisation or within your sector, material changes to your IT architecture, new regulatory requirements such as NIS2 or the KRITIS Umbrella Act, and findings from audits and emergency exercises. Each trigger should initiate a documented review and decision step.
How do threat intelligence findings translate into concrete process adaptations?
Threat intelligence is only effective when coupled to a decision process. We assess incoming information — BSI notifications, CERT-Bund advisories, sector-specific sources — for relevance to your specific facilities and derive prioritised measures. Documentation is decisive: which advisory led to which adaptation? That traceability makes providing evidence to the BSI considerably easier.
Let's
Work Together!
Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
Ready for the next step?
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
Prefer direct contact?
Direct hotline for decision-makers
Strategic inquiries via email
Detailed Project Inquiry
For complex inquiries or if you want to provide specific information in advance