Systematic Validation of Your IT Security Measures

KRITIS Regular Tests & Audits

The KRITIS regulation requires regular tests and audits for continuous validation of IT security measures.

  • 01Systematic validation of all IT security measures
  • 02Proactive identification of security gaps
  • 03Compliance-compliant documentation and reporting
  • 04Continuous improvement of security posture
11+Years of experience
120+Employees
540+Projects
ISO 27001certified

KRITIS Regular Tests & Audits

Operators of critical infrastructure in Germany must demonstrate compliance with Section 8a of the BSI Act (BSIG) every two years, proving that their IT security measures meet the state of the art. Regular tests and audits form the core of this compliance process. ADVISORI supports KRITIS operators in preparing, conducting and following up on Section 8a audits with a systematic approach that combines technical penetration testing with organisational compliance audits.

We conduct the complete Section 8a compliance procedure for KRITIS operators: from audit planning through document review, interviews and technical on-site assessment to the preparation of compliance documents (BSI Form P, audit report, deficiency list). Additionally, we provide regular penetration tests, vulnerability assessments and incident response exercises.

2 service modules

What we take on for you

Bookable individually or as an end-to-end programme.

01

Technical Security Tests

We conduct comprehensive technical tests ranging from automated vulnerability scans to manual penetration tests that validate all layers of your IT infrastructure.

  • Systematic penetration tests of all critical systems
  • Vulnerability assessments and weakness analyses
  • Red team exercises and advanced persistent threat simulations
  • Industrial Control Systems (ICS/SCADA) security tests
02

Organizational Compliance Audits

We systematically review the organizational aspects of your KRITIS compliance, from governance structures to operational processes and emergency plans.

  • Compliance audits for regulatory conformity review
  • Governance and risk management assessments
  • Business continuity and disaster recovery tests
  • Incident response simulations and crisis exercises

5 phases

Our Approach

We develop customized test and audit programs with you that systematically validate all aspects of your IT security and enable continuous improvements.

  1. Development of risk-based test and audit plans

  2. Execution of systematic technical and organizational tests

  3. Comprehensive documentation and compliance-compliant reporting

  4. Development and prioritization of improvement measures

  5. Continuous adaptation of test strategies to new threats

Sarah Richter

Your contact

Sarah Richter

Head of Information Security, Cyber Security

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Regular tests and audits are the backbone of a living KRITIS compliance. They not only create regulatory security but also enable continuous evolution of security architecture in a changing threat landscape.

Our qualifications

  • 01Auditors with special audit procedure competence for Section 8a BSIG
  • 02Experience across KRITIS sectors: energy, finance, healthcare, IT/telecoms
  • 03Certified penetration testers (OSCP, OSCE, CREST)
  • 04Knowledge of current BSI guidance and sector-specific security standards (B3S)

Key requirement

The Section 8a compliance proof must be submitted to the BSI every two years. The audit covers document review, interviews, on-site inspection and technical assessment. Begin preparation at least six months before your submission deadline.

7 QUESTIONS, BRIEFLY ANSWERED

Frequently asked questions about KRITIS Regular Tests & Audits

How does a KRITIS audit under Section 8a of the BSI Act work?

The Section 8a compliance audit is conducted in two stages. In Stage 1, the audit scope is defined, documentation is reviewed and the audit plan is prepared. In Stage 2, the actual audit procedures take place: document review, interviews with responsible personnel, on-site inspection of systems and technical assessment. At the end, the compliance documents are prepared: BSI Form P (audit evidence), Form KI (description of the critical infrastructure), the audit report and, where applicable, a deficiency list. The BSI provides guidance documents (GAiN, RUN) that describe the exact procedure.

What audit standards apply to KRITIS compliance audits?

The audit basis is either a sector-specific security standard (B3S) recognised by the BSI, or established standards such as ISO 27001 or BSI IT-Grundschutz. Auditors must hold the special audit procedure competence for Section 8a BSIG. Since the NIS2 transposition into the BSIG, the ten measure areas under Section 30 BSIG additionally serve as audit subjects, including risk analysis, incident management, business continuity, supply chain security and cryptography.

How often must KRITIS operators submit Section 8a compliance proof?

KRITIS operators must demonstrate to the BSI every two years that their IT security measures meet the state of the art. The deadline runs from the date of the last submission. Since the NIS2 transposition in 2026, transitional provisions apply: operators may submit the next proof under the previous BSI requirements or already apply the NIS2-compliant requirements. The subsequent proof must then follow the updated procedure.

What role do penetration tests play in KRITIS compliance?

Penetration tests are a central component of the technical on-site assessment in the Section 8a procedure. The BSI recommends annual penetration tests for KRITIS operators, even though formal proof is only required every two years. Tests should follow recognised methodologies such as OWASP, the BSI penetration testing guide or PTES, and should cover IT/OT segmentation, firewall configurations, privileged accounts and, where applicable, physical access security. The pentest report serves as key evidence in the Section 8a audit.

What changes does NIS2 bring for KRITIS tests and audits?

With the transposition of the NIS2 Directive into the BSIG, extended requirements apply. KRITIS operators are classified as particularly important entities and must demonstrate compliance with the ten measure areas under Section 30 BSIG. New requirements include supply chain security, use of cryptography and attack detection systems (SzA). The compliance procedure is being gradually adapted to NIS2 requirements, with transitional periods in effect.

What compliance documents must be submitted to the BSI?

After completing the audit, the following documents must be submitted to the BSI: the audit evidence document (Form P), the critical infrastructure description (Form KI), the audit plan, the audit report with findings from the document review and on-site assessment, and where applicable a deficiency list with remediation deadlines. The BSI provides the forms and guidance documents (GAiN, RUN) that specify the exact scope and requirements for the compliance documents.

How does ADVISORI support preparation for the Section 8a audit?

ADVISORI supports KRITIS operators throughout the entire audit cycle: in the preparation phase, we conduct a gap analysis to identify deviations from BSI requirements early. We assist with preparing the required documentation, conduct internal pre-audits and prepare responsible personnel for the interviews. Additionally, we provide regular penetration tests and vulnerability assessments between audit cycles to ensure security measures are continuously validated.

Certificates, partners and more

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance