KRITIS-Consulting

Security and compliance for critical infrastructure under the current BSIG

Do you operate critical services? If so, you are subject to the stricter requirements of the NIS2 implementation and the BSIG.

Compliance with these regulations is not only mandatory – it is crucial for your authorization as a service provider, your market position, and avoiding fines.

We help you efficiently implement all legal requirements and provide reliable evidence of compliance to authorities and auditors.

Are you one of the affected organizations?

Affected companies include those in sectors such as:

  • Energy (electricity, gas, petroleum)
  • Water (drinking water supply, wastewater disposal)
  • Food (food production and retail)
  • Healthcare (medical care, laboratories, pharmaceuticals)
  • Information Technology and Telecommunications
  • Finance and Insurance
  • Transportation and traffic
  • Municipal waste management
  • Space infrastructure 

The key factor is whether you exceed defined thresholds and provide critical services. We help you assess your compliance status quickly and reliably.

Your obligations as a KRITIS operator under the BSIG

As an operator of critical infrastructure, you are required to implement appropriate technical and organizational measures (ToMs) to prevent disruptions to the availability, integrity, and confidentiality of your information technology systems, components, and processes.
In addition:

  • You must provide evidence of the implementation of these measures at least every two years.
  • Proof is provided to the BSI via defined documents (e.g., Form KI, Form P).
  • Comply with the reporting requirements of the BSIG.

Our KRITIS consulting: structured for a successful audit

We guide you from the initial analysis through to successful verification:

  • Impact analysis in accordance with the current BSIG (including the NIS-2 context)
  • Threshold assessment and classification as a particularly important or important facility
  • Gap analysis against the BSIG, BSI-KritisV, and industry-specific security standards (B3S)
  • Establishment or optimization of an ISMS (ISO 27001, IT-Grundschutz) as the basis for compliance requirements
  • Risk analyses and assessments of protection requirements
  • Implementation of the required technical and organizational measures
  • Preparation for the KRITIS audit, including documentation for the BSI
  • Support throughout the entire compliance process in accordance with the BSIG

Our focus: a pragmatic, audit-ready implementation that is both regulatory-compliant and operationally viable.

Typical areas of focus in the KRITIS context

We provide targeted support in key security areas:

  • Governance and security organization
  • Risk management and emergency management
  • Detection and response to security incidents
  • Securing IT and OT systems
  • Service provider and supply chain management
  • Security Awareness and Training for Your Employees
  • Documentation and Reporting for Regulatory Authorities

Why abat?

With abat, you can rely on in-depth experience in the KRITIS environment:

  • ISO 27001 auditors
  • Proven additional expertise in audit procedures in accordance with the BSIG
  • Many years of experience in regulated and KRITIS-related industries
  • A practical approach focused on audit readiness and efficiency

We understand the requirements of the BSI, the certification bodies, and current legislation – and know how you can reliably meet them.

Get started now

Quickly and reliably determine whether and to what extent your company falls under the current BSIG and KRITIS regulations – and efficiently implement the requirements.

TISAX® is a registered trademark of the ENX Association. The mention of the TISAX® trademark does not imply any statement by the trademark owner regarding the suitability of the services advertised here. The exclusive responsibility for the content of the website and the services presented here lies with abat.

Our customers in the area protect

Saskia

ISMS Consultant
Bremen

For me, abat is: fun, exciting projects - great customers and colleagues packed into a respectful and trusting atmosphere with plenty of room for continuous development!

Melissa

ISMS Senior Consultant
Bremen

At abat, I have the freedom to approach my work independently and with a focus on finding solutions.

Hans

ISMS Senior Consultant
Bremen

For me, abat is synonymous with limitless opportunities and a sustainable corporate culture

Our memberships

abat is a member of

Our experts are committed to

Quick Link

You might also be interested in

Information material

on the topic Information security

download PDF now 

Contact our abat protect expert

Free initial consultation to analyze your needs

In the first meeting, you define your initial situation with us, and we clarify initial questions.

This appointment is free of charge and without obligation for you.