Assess maturity, identify gaps, get a compliance roadmap

KRITIS Readiness

As a KRITIS operator, you must demonstrate to the BSI that your critical infrastructure is adequately protected. Our KRITIS Readiness Assessment systematically determines your current maturity level, identifies compliance gaps, and delivers a prioritized roadmap for implementing all requirements under the BSI Act, IT Security Act 2.0, and the KRITIS Umbrella Act.

  • Structured maturity assessment against BSI standards
  • Gap analysis for organizational and technical requirements
  • Prioritized compliance roadmap with concrete measures
  • Preparation for section 8a audits and regulatory inspections

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

  • Your strategic goals and objectives
  • Desired business outcomes and ROI
  • Steps already taken

Or contact us directly:

Certifications, Partners and more...

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

What Does a KRITIS Readiness Assessment Cover?

Why Choose ADVISORI for Your KRITIS Readiness Assessment?

  • Experience across all nine KRITIS sectors and sector-specific requirements
  • Proven assessment methodology based on BSI IT-Grundschutz and ISO 27001
  • End-to-end support from assessment through demonstrated compliance
  • Interdisciplinary team of information security, regulatory, and technical experts

Why Act Now?

The KRITIS Umbrella Act and NIS2 significantly expand both requirements and the scope of affected organizations. An early readiness assessment gives you the necessary lead time to implement measures before regulatory inspections.

ADVISORI in Numbers

11+

Years of Experience

120+

Employees

520+

Projects

Our assessment follows a structured five-phase approach that systematically covers all relevant areas and delivers a clear action plan upon completion.

Our Approach:

Scoping and inventory: Identification of all KRITIS-relevant facilities and processes

As-is analysis: Document and evaluate technical and organizational security measures

Gap analysis: Comparison against BSI requirements, KRITIS Umbrella Act, and sector standards

Risk assessment: Prioritization of identified gaps by risk and effort

Roadmap: Prioritized action plan with timeline, responsibilities, and budget

"With our KRITIS Readiness Assessment, we create clarity for our clients about their current compliance status – structured, traceable, and practical. The concrete recommendations for action enable focused further development of the KRITIS strategy and help deploy resources specifically where the greatest need for action exists."
Sarah Richter

Sarah Richter

Head of Information Security, Cyber Security

Expertise & Experience:

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Our Services

We offer you tailored solutions for your digital transformation

Vulnerability Analysis & Risk Assessment

Systematic identification and assessment of vulnerabilities in your critical infrastructures with comprehensive risk analysis.

  • Technical vulnerability analysis
  • Organizational risk assessment
  • Threat analysis and scenario assessment
  • Prioritized risk matrix

Gap Analysis Organization & Technology

Comprehensive assessment of gaps between your current status and KRITIS requirements in organizational and technical areas.

  • Organizational structure analysis
  • Technical system analysis
  • Compliance gap identification
  • Action recommendations

Emergency Concepts & Resource Planning

Development of comprehensive emergency concepts and strategic resource planning for critical scenarios.

  • Business Continuity Planning
  • Incident Response Concepts
  • Resource requirements analysis
  • Escalation and communication plans

Our Competencies in KRITIS

Choose the area that fits your requirements

CRITIS Implementation

As a KRITIS operator, you must fully implement BSI Act requirements and the new KRITIS Umbrella Act. We guide you from protection needs analysis through ISMS implementation to BSI compliance certification.

KRITIS Ongoing Compliance

KRITIS compliance does not end with initial implementation. Operators must continuously maintain their ISMS, provide evidence to the BSI every two years, and report incidents within 24 hours. We ensure your sustained compliance.

Frequently Asked Questions about KRITIS Readiness

What is a KRITIS Readiness Assessment and when is it needed?

A KRITIS Readiness Assessment systematically evaluates how well your organization is prepared for the legal requirements for protecting critical infrastructures. It is particularly relevant when you have been newly identified as a KRITIS operator, are approaching a section 8a audit, when the KRITIS Umbrella Act or NIS 2 introduces new requirements for your organization, or when you need to reassess your compliance status after a merger or restructuring. ADVISORI reviews technical measures, organizational processes, and documentation against BSI requirements and sector-specific standards.

Which KRITIS requirements are examined in the assessment?

The assessment reviews your compliance against all relevant regulatory requirements: the BSI Act (section 8a BSIG) and IT Security Act 2.0, the KRITIS Umbrella Act (CER Directive), sector-specific requirements such as the Energy Industry Act, DORA, or the Telecommunications Act, sector-specific security standards (B3S), BSI IT-Grundschutz and ISO 27001/27002, and the requirements for attack detection systems (SzA). We also evaluate physical security measures, which are regulated for the first time under the KRITIS Umbrella Act.

How does a readiness assessment differ from a section 8a audit?

A readiness assessment is a preparatory evaluation that determines your current maturity level and identifies gaps before a formal audit is due. The section 8a audit, by contrast, is the legally required examination by qualified auditors whose results are submitted to the BSI. The readiness assessment gives you the opportunity to address weaknesses early and prepare specifically for the audit, rather than being confronted with deficiencies during the examination.

How long does a KRITIS Readiness Assessment take?

The duration depends on the size and complexity of your organization. For a single facility or manageable infrastructure, we estimate four to six weeks. For complex organizations with multiple sites, interconnected OT systems, or multiple KRITIS sectors, the assessment may take eight to twelve weeks. We coordinate interview schedules and document requests closely with your teams to minimize disruption to your day-to-day operations.

What does the KRITIS Umbrella Act change compared to previous regulations?

The KRITIS Umbrella Act transposes the European CER Directive (2022/2557) into German law and significantly broadens the focus beyond IT security: Physical security such as access controls and sabotage prevention is regulated for the first time, the scope of affected sectors and operators is expanded, risk analyses must be conducted and documented more comprehensively, and resilience plans including recovery measures become mandatory. Existing KRITIS operators must supplement their security concepts accordingly.

Does ADVISORI also support implementation after the assessment?

Yes, we provide end-to-end support from assessment through demonstrated compliance. After the assessment, we assist with implementing prioritized measures, introducing or extending an ISMS in accordance with ISO 27001, developing emergency and business continuity concepts, preparing for section 8a audits and regulatory inspections, and training your staff on KRITIS-relevant topics.

Success Stories

Discover how we support companies in their digital transformation

Digitalization in Steel Trading

Klöckner & Co

Digital Transformation in Steel Trading

Case Study
Digitalisierung im Stahlhandel - Klöckner & Co

Results

Over 2 billion euros in annual revenue through digital channels
Goal to achieve 60% of revenue online by 2022
Improved customer satisfaction through automated processes

AI-Powered Manufacturing Optimization

Siemens

Smart Manufacturing Solutions for Maximum Value Creation

Case Study
Case study image for AI-Powered Manufacturing Optimization

Results

Significant increase in production performance
Reduction of downtime and production costs
Improved sustainability through more efficient resource utilization

AI Automation in Production

Festo

Intelligent Networking for Future-Proof Production Systems

Case Study
FESTO AI Case Study

Results

Improved production speed and flexibility
Reduced manufacturing costs through more efficient resource utilization
Increased customer satisfaction through personalized products

Generative AI in Manufacturing

Bosch

AI Process Optimization for Improved Production Efficiency

Case Study
BOSCH KI-Prozessoptimierung für bessere Produktionseffizienz

Results

Reduction of AI application implementation time to just a few weeks
Improvement in product quality through early defect detection
Increased manufacturing efficiency through reduced downtime

Let's

Work Together!

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance