KRITIS · Critical Infrastructure · BSI

KRITIS pentest: Security for critical infrastructure

Operators of critical infrastructure are in the crosshairs of professional, often state-sponsored attackers. The BSI Act, as amended by the NIS2UmsuCG, requires regular security reviews to the state of the art, and since March 2026 the new KRITIS-Dachgesetz additionally requires evidence of physical resilience. We conduct the penetration tests needed for both: structured, documented, and tailored to the specific requirements of KRITIS environments.

  • BSI-compliant documentation
  • Experience in critical environments
  • Free initial consultation
What you get
Audit evidence to the state of the art
Our report documents compliance with the requirements of Sections 30 and 31 BSIG (until December 2025: Section 8a BSIG), directly usable for the evidence submission under Section 39 BSIG as well as internal and external audits.
IT and OT security covered
KRITIS environments combine classical IT with industrial control systems. We understand both worlds and test with appropriate care.
No operational disruption
Clear scope boundaries, complete logging, immediate stop if unexpected impacts occur. Your operations stay protected at all times.
Prioritised remediation plan
Every finding with a concrete recommendation, prioritised by risk and feasibility in your operational context.

Our final report is suitable for BSI audits, internal compliance obligations, and board-level reporting.

3 years New BSI evidence interval (previously 2 years)
9 Critical sectors in Germany
1,231 KRITIS operators nationwide (as of 06/2026)
EUR 10m Maximum fine under Section 28(1) BSIG

Legal status 2026

What is KRITIS?

Since late 2025, the legal basis for KRITIS operators has changed fundamentally. Two reforms interlock and bring tougher requirements. Both are already reflected on this page.

Two laws, one goal: cyber and physical security for KRITIS

Cybersecurity

The BSI Act as amended by the NIS2UmsuCG

Germany's NIS2 implementation act (NIS2UmsuCG) took effect on 6 December 2025 and fundamentally restructured and renumbered the BSI Act. Since then, operators of critical facilities are always classed as 'especially important entities' under Section 28 BSIG and must fulfil every NIS2 baseline obligation: risk management measures to the state of the art (Sections 30 and 31 BSIG), tiered reporting duties for significant security incidents (Section 32 BSIG), and regular evidence submission to the BSI (Section 39 BSIG).

Physical resilience

The KRITIS-Dachgesetz

While the BSI Act addresses IT and OT security, the new KRITIS-Dachgesetz (Critical Infrastructure Umbrella Act) regulates the physical protection of critical facilities nationwide for the first time. The Bundestag passed the law on 29 January 2026, the Bundesrat approved it on 6 March 2026, and it has been in force ever since. At its core is an all-hazards approach: operators must submit resilience plans covering sabotage, natural disasters, and supply chain failures alike, including emergency response teams, site protection, and backup supply arrangements.

  1. since 12/2025 NIS2UmsuCG in force: BSI Act renumbered, fines of up to EUR 10m activated
  2. 29 Jan 2026 Bundestag passes the KRITIS-Dachgesetz
  3. 6 Mar 2026 Bundesrat approves, law is promulgated
  4. since 03/2026 KRITIS-Dachgesetz in force: resilience plans become mandatory for operators of critical facilities

Affected KRITIS sectors

Does KRITIS apply to your organisation?

The BSI Act defines nine critical sectors. Whether a specific facility counts as critical depends on facility-specific thresholds, all derived from the same baseline threshold: 500,000 persons supplied. For each facility type, the estimated average annual per-capita demand is calculated and multiplied by that factor; the exact figures per sector are set out in Annex 2 of the BSI-KritisV. As of June 2026, 1,231 operators with 2,180 critical facilities are registered with the BSI. One operator often runs several facilities, sometimes across different sectors.

Standard threshold 500,000 people supplied
derived threshold per facility type
  1. Energy (power, gas, oil, district heating)
  2. Water & Wastewater
  3. Health (hospitals, laboratories)
  4. Food (production, retail)
  5. Finance & Insurance
  6. Transport & Traffic
  7. Digital infrastructure & ICT
  8. Government & Public administration
  9. Media & Culture

Why KRITIS is a particularly high-value target

  • Attacks on critical infrastructure pursue geopolitical goals: state-sponsored actors are more active here than in other sectors
  • OT systems (SCADA, ICS) are often decades old and were never designed for network connectivity, so classical IT security concepts do not apply
  • A successful attack can endanger data and the physical supply of essential services to the population alike
  • Ransomware groups have explicitly identified KRITIS operators as lucrative targets

Legal framework

What does the BSI Act require of KRITIS operators?

Sections 30 and 31 BSIG (until December 2025: Section 8a BSIG) require operators of critical facilities to implement appropriate technical and organisational measures to the state of the art. A penetration test is the recognised instrument for providing this evidence under Section 39 BSIG.

§ 30/31 BSIG

Appropriate protective measures

Operators of critical facilities must secure their systems to the state of the art (Section 30(1), Section 31 BSIG). A pentest demonstrates that this requirement is taken seriously.

Infra, physical, AD pentest

§ 39 BSIG

Regular verification

Since the NIS2UmsuCG took effect, security measures must be demonstrated to the BSI every three years instead of the previous two (Section 39 BSIG). A pentest report is a central piece of evidence for this.

All pentest modules

§ 32 BSIG

Incident reporting obligation

Section 32 BSIG requires tiered reporting of significant security incidents: an early warning within 24 hours, an incident report within 72 hours, and a final report within one month at the latest. Correctly classifying incidents requires knowing your own attack surface. A pentest creates this transparency.

  1. Incident
  2. 24 h
  3. 72 h
  4. 1 month

OSINT, infra pentest

§ 31 BSIG

Access and entry control

Physical access to server rooms, control rooms, and technical areas requires special protection under Section 31 BSIG, and since March 2026 is also part of the resilience plans required by the KRITIS-Dachgesetz. We test whether your access controls hold up.

Physical pentest

§ 30 BSIG

Network and system security

IT/OT segmentation, firewall configurations, privileged accounts: we test whether your network is the real barrier that Section 30 BSIG requires.

Infrastructure pentest

§ 30 BSIG

Employee awareness

Social engineering is one of the most common entry points. We test how well your staff recognise and deflect manipulation attempts (also part of the risk management measures under Section 30 BSIG).

Social engineering

Our approach

How does a KRITIS pentest work?

KRITIS pentests require special care: clear scope definitions, close coordination with operations, and complete documentation for BSI evidence.

  1. Scoping & risk alignment

    Joint definition of the test scope with explicit consideration of operationally critical systems. Exclusion zones and no-go areas are binding.

  2. Reconnaissance & attack planning

    Information gathering from public sources, network footprinting, and planning of realistic attack paths against your environment.

  3. Controlled test execution

    Manual testing within the agreed scope. We work closely with your operations team and communicate critical findings immediately.

  4. Analysis & risk assessment

    Assessment of each finding by technical severity and operational business impact, with focus on the specific characteristics of your KRITIS environment.

  5. BSI-compliant final report

    Complete documentation of all findings with recommendations, management summary, and BSI evidence documentation per Section 39 BSIG.

KRITIS pentest report · sample excerpt Sample
  • Control room: direct access without badge controlSection 31 BSIG
  • OT network directly reachable from ITSection 30 BSIG
  • Phishing: large share of staff susceptible (example figure)Section 30 BSIG
  • SCADA system: default password activeSection 30 BSIG
  • VPN: no MFA for remote accessSection 30 BSIG
5 findings: remediation plan included Evidence per Section 39 BSIG

Illustrative example – no real customer data.

Relevant pentest modules

Which tests do KRITIS operators need?

KRITIS environments have special requirements. These three modules cover the most critical attack vectors and deliver the strongest BSI evidence.

Access

Physical pentest

Control rooms, server rooms, technical areas: physical access is often the underestimated attack vector for KRITIS operators, and since the KRITIS-Dachgesetz it is explicitly part of the required resilience plans. We test whether your access controls hold up.

Energy (power, gas, oil, district heating)

Learn more
OT

Infrastructure & OT security

IT/OT segmentation, SCADA access, firewall configurations, privileged accounts: we test the network holistically with particular care for operationally critical systems.

Learn more
IT

Active Directory & access management

Privilege escalation, lateral movement, weak accounts: a compromised AD in a KRITIS environment can have catastrophic consequences.

Learn more

Frequently asked questions

KRITIS & penetration testing: your questions

Sections 30 and 31 BSIG (until the NIS2UmsuCG took effect in December 2025: Section 8a BSIG) require operators of critical facilities to demonstrate to the BSI that they have implemented appropriate technical and organisational measures, since the reform every three years instead of the previous two (Section 39 BSIG). A penetration test is the recognised instrument for this evidence.
Technically many methods are identical: the differences lie in preparation, the sensitivity of execution, and reporting. For KRITIS operators, operationally critical systems must be carefully scoped out. OT systems require a different approach to classical IT, and since the KRITIS-Dachgesetz, physical resilience also plays a bigger role in the reporting.
Yes, but with particular care. OT systems are often more sensitive than classical IT and must not be destabilised by aggressive test methods. We jointly define clear boundaries and coordinate the test closely with your operations staff.
There is no one-size-fits-all answer. KRITIS environments vary considerably depending on sector, facility size, IT/OT ratio, and desired scope. After a free initial consultation we will understand your environment and you will receive a transparent fixed-price offer.
The BSI now requires evidence every three years (Section 39 BSIG). Before the NIS2UmsuCG reform it was two years. We also recommend testing after significant changes to your IT or OT infrastructure and after security-relevant incidents.
The BSIG defines nine critical sectors: energy, water, food, ICT, health, finance and insurance, transport and traffic, government and public administration, and media and culture. As of June 2026, 1,231 operators with 2,180 facilities are registered with the BSI; whether an operator is specifically subject to KRITIS obligations depends on facility-specific thresholds, all based on the baseline threshold of 500,000 persons supplied (Annex 2 BSI-KritisV).
The Bundestag passed the KRITIS-Dachgesetz on 29 January 2026, the Bundesrat approved it on 6 March 2026, and it has been in force since March 2026. Unlike the BSI Act/NIS2UmsuCG, which governs IT and OT security, the Dachgesetz takes an all-hazards approach to physical resilience: sabotage, natural disasters, supply chain failures. Operators of critical facilities must now submit resilience plans covering, among other things, emergency response teams, site protection, and backup supply arrangements. For our pentests, this means physical access controls to control rooms, server rooms, and technical areas move even further into focus, since they now have to satisfy two laws at once.
With the NIS2UmsuCG, the BSI Act was restructured and renumbered as of 6 December 2025. Section 8a BSIG (measures) became Sections 30 and 31 BSIG; Section 8a(3) BSIG (evidence) became Section 39 BSIG; Section 8b BSIG (reporting duty) became Section 32 BSIG. The new sections build on the previous structure but were tightened: the evidence interval was extended from two to three years, the reporting deadlines (24-hour early warning, 72-hour incident report) were made more precise, and the maximum fines were raised to up to EUR 10 million. If your documentation still references Section 8a BSIG, you should update it at the next opportunity.

Ready for your KRITIS pentest?

In 30 minutes we discuss your KRITIS environment, clarify the scope, and you receive a no-obligation quote, free of charge.