Questions that KRITIS companies should be asking themselves now
Am I affected?
- Does my company meet the criteria for a KRITIS operator according to the KRITIS umbrella law?
- Is my service systemically important or critical to the general public?
- Am I already covered by other regulations such as the IT Security Act?
How resilient is my company currently?
- Do we have a robust emergency and crisis management system?
- Are we prepared for power outages, cyberattacks, or supply bottlenecks?
- Are risk analyses and vulnerability assessments carried out regularly?
What protective measures are already in place—and where are the gaps?
- What about the physical security of our locations (access control, protection against sabotage)?
- What IT security standards are implemented?
- Are there organizational measures in place to maintain critical processes even in the event of a crisis?
Are our internal structures KRITIS-compatible?
- Do we have a responsible body for resilience and KRITIS compliance?
- How is our reporting system organized—internally and vis-à-vis authorities?
- Which employees need to be trained or newly integrated?
What specific legal obligations apply to us?
- Does our company need to be entered in the KRITIS register?
- What reporting obligations apply to security incidents?
- What deadlines and documentation requirements do we have to comply with?
How do we approach implementation in concrete terms?
- Who will take on project responsibility internally?
- Which external partners (e.g., consultants, auditors, IT service providers) do we need?
- How do we integrate the requirements into ongoing operations – without compromising productivity?