KRITIS Readiness Assessment: How Ready Is Your Organization?
As a KRITIS operator, you must demonstrate to the BSI that your critical infrastructure is adequately protected. Our KRITIS Readiness Assessment systematically determines your current maturity level, identifies compliance gaps, and delivers a prioritized roadmap for implementing all requirements under the BSI Act, IT Security Act 2.0, and the KRITIS Umbrella Act.
- ✓Structured maturity assessment against BSI standards
- ✓Gap analysis for organizational and technical requirements
- ✓Prioritized compliance roadmap with concrete measures
- ✓Preparation for section 8a audits and regulatory inspections
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
- Your strategic goals and objectives
- Desired business outcomes and ROI
- Steps already taken
Or contact us directly:
Certifications, Partners and more...










What Does a KRITIS Readiness Assessment Cover?
Why Choose ADVISORI for Your KRITIS Readiness Assessment?
- Experience across all nine KRITIS sectors and sector-specific requirements
- Proven assessment methodology based on BSI IT-Grundschutz and ISO 27001
- End-to-end support from assessment through demonstrated compliance
- Interdisciplinary team of information security, regulatory, and technical experts
Why Act Now?
The KRITIS Umbrella Act and NIS2 significantly expand both requirements and the scope of affected organizations. An early readiness assessment gives you the necessary lead time to implement measures before regulatory inspections.
ADVISORI in Numbers
11+
Years of Experience
120+
Employees
520+
Projects
Our assessment follows a structured five-phase approach that systematically covers all relevant areas and delivers a clear action plan upon completion.
Our Approach:
Scoping and inventory: Identification of all KRITIS-relevant facilities and processes
As-is analysis: Document and evaluate technical and organizational security measures
Gap analysis: Comparison against BSI requirements, KRITIS Umbrella Act, and sector standards
Risk assessment: Prioritization of identified gaps by risk and effort
Roadmap: Prioritized action plan with timeline, responsibilities, and budget
"With our KRITIS Readiness Assessment, we create clarity for our clients about their current compliance status – structured, traceable, and practical. The concrete recommendations for action enable focused further development of the KRITIS strategy and help deploy resources specifically where the greatest need for action exists."

Sarah Richter
Head of Information Security, Cyber Security
Expertise & Experience:
10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security
Our Services
We offer you tailored solutions for your digital transformation
Vulnerability Analysis & Risk Assessment
Systematic identification and assessment of vulnerabilities in your critical infrastructures with comprehensive risk analysis.
- Technical vulnerability analysis
- Organizational risk assessment
- Threat analysis and scenario assessment
- Prioritized risk matrix
Gap Analysis Organization & Technology
Comprehensive assessment of gaps between your current status and KRITIS requirements in organizational and technical areas.
- Organizational structure analysis
- Technical system analysis
- Compliance gap identification
- Action recommendations
Business Continuity Planning
Development of comprehensive business continuity plans for critical infrastructures with focus on supply security.
- Business Impact Analysis (BIA) of critical processes
- Scenario-based continuity planning
- Recovery Time/Point Objectives (RTO/RPO) definition
- Alternative operating concepts and workarounds
Incident Response & Crisis Management
Structured Incident Response processes and professional crisis management for critical disruption situations.
- Incident Response Team (IRT) structures
- Escalation and decision processes
- Communication strategies and stakeholder management
- Post-Incident Review and Lessons Learned
Strategic Resource Planning
Systematic planning and procurement of critical resources for emergency and crisis scenarios.
- Resource requirements analysis for critical scenarios
- Strategic procurement and warehousing concepts
- Supplier and partnership management
- Emergency budgeting and cost planning
Our Competencies
Choose the area that fits your requirements
Where does your critical infrastructure stand on KRITIS compliance? Our gap analysis systematically compares your current state against section 8a BSIG, BSI-KritisV and NIS2 requirements. You receive a prioritized action plan covering organization and technology.
A systematic vulnerability assessment and risk analysis forms the foundation for effective protective measures in critical infrastructures. We identify technical and organisational vulnerabilities, assess their risks according to BSI and ISO 27005 standards, and derive prioritised recommendations for action.
More Services in Regulatory Compliance Management
Frequently Asked Questions about KRITIS Readiness
What is a KRITIS Readiness Assessment and when is it needed?
A KRITIS Readiness Assessment systematically evaluates how well your organization is prepared for the legal requirements for protecting critical infrastructures. It is particularly relevant when you have been newly identified as a KRITIS operator, are approaching a section 8a audit, when the KRITIS Umbrella Act or NIS2 introduces new requirements for your organization, or when you need to reassess your compliance status after a merger or restructuring. ADVISORI reviews technical measures, organizational processes, and documentation against BSI requirements and sector-specific standards.
Which KRITIS requirements are examined in the assessment?
The assessment reviews your compliance against all relevant regulatory requirements: the BSI Act (section 8a BSIG) and IT Security Act 2.0, the KRITIS Umbrella Act (CER Directive), sector-specific requirements such as the Energy Industry Act, DORA, or the Telecommunications Act, sector-specific security standards (B3S), BSI IT-Grundschutz and ISO 27001/27002, and the requirements for attack detection systems (SzA). We also evaluate physical security measures, which are regulated for the first time under the KRITIS Umbrella Act.
How does a readiness assessment differ from a section 8a audit?
A readiness assessment is a preparatory evaluation that determines your current maturity level and identifies gaps before a formal audit is due. The section 8a audit, by contrast, is the legally required examination by qualified auditors whose results are submitted to the BSI. The readiness assessment gives you the opportunity to address weaknesses early and prepare specifically for the audit, rather than being confronted with deficiencies during the examination.
How long does a KRITIS Readiness Assessment take?
The duration depends on the size and complexity of your organization. For a single facility or manageable infrastructure, we estimate four to six weeks. For complex organizations with multiple sites, interconnected OT systems, or multiple KRITIS sectors, the assessment may take eight to twelve weeks. We coordinate interview schedules and document requests closely with your teams to minimize disruption to your day-to-day operations.
What does the KRITIS Umbrella Act change compared to previous regulations?
The KRITIS Umbrella Act transposes the European CER Directive (2022/2557) into German law and significantly broadens the focus beyond IT security: Physical security such as access controls and sabotage prevention is regulated for the first time, the scope of affected sectors and operators is expanded, risk analyses must be conducted and documented more comprehensively, and resilience plans including recovery measures become mandatory. Existing KRITIS operators must supplement their security concepts accordingly.
Does ADVISORI also support implementation after the assessment?
Yes, we provide end-to-end support from assessment through demonstrated compliance. After the assessment, we assist with implementing prioritized measures, introducing or extending an ISMS in accordance with ISO 27001, developing emergency and business continuity concepts, preparing for section 8a audits and regulatory inspections, and training your staff on KRITIS-relevant topics.
What must a KRITIS emergency concept contain according to BSI 200-4?
A KRITIS emergency concept under BSI Standard 200‑4 comprises several core components: a Business Impact Analysis (BIA) to identify critical business processes, a risk analysis of relevant threat scenarios, documented recovery plans with defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO), crisis communication plans for internal and external stakeholders, and an exercise programme with regular tests. BSI Standard 200‑4 provides a three-tier model: Reactive BCMS, Build-up BCMS, and Standard BCMS, enabling organisations to incrementally develop a complete Business Continuity Management system.
What are the deadlines for emergency planning under the KRITIS Umbrella Act?
The KRITIS Umbrella Act sets the following timelines: Registration as a critical facility must be completed by July 2026. Operators then have approximately 9 months to conduct a full risk analysis and a further 10 months to implement the resulting measures, including emergency concepts. Resilience plans must be regularly updated and revised when the threat landscape changes significantly. ADVISORI recommends starting early, as developing robust emergency concepts typically takes 6 to 12 months.
How does BCM resource planning differ from standard budget planning?
Resource planning in Business Continuity Management goes beyond standard budgeting: it systematically captures all resources needed to maintain critical services during an emergency. This includes personnel with key competencies and their deputies, technical fallback capacities and redundancies, crisis communication infrastructure, contracts with emergency service providers and suppliers, and stockpiles of critical spare parts. The challenge lies in finding the right balance between holding costs and recovery speed. ADVISORI uses data-driven models to optimise this trade-off individually for each KRITIS sector.
What role does the NIS2 Directive play in KRITIS emergency management?
The NIS2 Directive significantly expands emergency management requirements for KRITIS operators. It mandates measures for security incident handling, Business Continuity Management including backup management and disaster recovery, and crisis management procedures. NIS2 also tightens reporting obligations: significant security incidents must be reported to the BSI within 24 hours as an early warning and within 72 hours with a full notification. ADVISORI seamlessly integrates NIS2 requirements into existing emergency concepts, ensuring both regulatory frameworks are satisfied in parallel.
How often must KRITIS emergency concepts be tested and updated?
BSI Standard 200‑4 and the KRITIS Umbrella Act require regular reviews and exercises. In practice this means: at least annual emergency exercises with varying scenarios (tabletop exercises, functional tests, and full-scale exercises in rotation), event-driven revisions following organisational changes, new threats, or actual incidents, and a formal review of all emergency documentation at least every two years. ADVISORI supports the design and execution of exercises and assists with systematic evaluation so that identified weaknesses feed directly into improved emergency concepts.
Let's
Work Together!
Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
Ready for the next step?
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
Prefer direct contact?
Direct hotline for decision-makers
Strategic inquiries via email
Detailed Project Inquiry
For complex inquiries or if you want to provide specific information in advance