Skip to content
REF · KRITIS · BSIG + KRITIS UMBRELLA ACT

Critical is not an opinion, it is a threshold. We get you ready.

Meet a BSI-KritisV threshold and you operate a critical facility, carrying two duty stacks at once: the full top NIS2 tier under the BSIG and, since 17.03.2026, the physical resilience duties of the KRITIS umbrella act. Add the recurring evidence duty under §39 BSIG (§8a Abs. 3 old version), every three years, which only a qualified examining body may perform. awedit scans both stacks, closes gaps, and escorts you to the handover. The examining body attests.

The KRITIS check lives inside the NIS2 self-check: one facility metric is enough. Orientation, not evidence. Not legal advice.

TIMELINE

Two clocks are running. One has been for years.

Since 01.05.2023

Attack-detection systems (§31 BSIG) are mandatory for operators of critical facilities and part of what the §39 evidence must show.

Since 17.03.2026

The KRITIS umbrella act is in force: physical resilience, personnel security, business continuity and crisis management, supervised by BBK and BSI.

2026 to 2028

§39 evidence dates roll continuously: roughly three years after your last §8a submission the BSI sets the next one. Submitted in 2023 means due in 2026.

METHOD

Experts lead the review. AI accelerates it. The examining body attests.

KRITIS is the C5 pattern in a second regime: readiness and gap work are our field, the evidence belongs to the examining body. We prepare the dossier so the handover is a step, not a project. For you that means one provider to manage, a handover-ready dossier at the end.

  1. STEP · 01
    Classification

    One facility metric against the BSI-KritisV: meet the threshold and you are a critical facility, automatically the top NIS2 tier plus the KRITIS umbrella act. The self-check shows both stacks with deadlines.

  2. STEP · 02
    Scan

    Our experts assess the cyber stack (§30 measures plus §31 attack detection) against a real control catalog and physical resilience against the umbrella-act duty set. AI tooling accelerates every pass; experts decide every finding.

  3. STEP · 03
    Handover

    An evidence-ready §39 dossier and the escort to a qualified examining body. On the physical side we arm you for BBK and BSI supervision.

Experts lead the review, highly specialized AI tooling accelerates it, the examining body attests. No tool alone achieves readiness, and a KRITIS certificate does not exist.

THE SHORT GUIDE

What KRITIS means in 2026.

The points most operators get stuck on in the first pass.

One trigger, two duty stacks

The term critical facility comes from the BSI-KritisV. Meet a threshold and you are automatically a besonders wichtige Einrichtung under the BSIG (§28 (1) sentence 1 no. 1) and an operator under the KRITIS umbrella act. Two authorities, two stacks, one classification event.

The thresholds are quantitative

The base threshold is 500,000 people supplied, refined per sector: for hospitals, 30,000 inpatient cases per year. A new KRITIS ordinance is in the works for 2026 and may shift individual thresholds. Our self-check runs on the current state.

§31: attack detection, since 2023

Attack-detection systems have been mandatory since 01.05.2023: logging, detection, response. For NIS2 entities without KRITIS status this is not a standalone hard duty; for operators of critical facilities it is.

§39: the evidence, every three years

The evidence under §39 BSIG (§8a Abs. 3 old version) is this lane's reserved act: only a qualified examining body may perform it, on a 3-year cycle. For existing operators the BSI sets the date from the last §8a submission. The dates are already running.

The umbrella act: physical, with a deadline chain

Registration on the joint BBK/BSI platform from 17.07.2026, within three months of identification. Then: risk analysis within 9 months, resilience measures within 10. That means access control, personnel security, business continuity and crisis management, not just IT.

No certificate, watch the claims

There is no KRITIS certificate. The §39 output is evidence, attested by an examining body, or nothing. A self-check result is orientation, not evidence.

From classification to steady: four steps.

  1. 01
    Self-Check

    Free, instant. Buys you clarity: which duties apply, how urgent, where the first gaps are.

  2. 02
    Scanner + Report

    Buys you the map: an expert-reviewed scan of your real product, a prioritized report the next step can use as-is.

  3. 03
    Remediation

    Buys you the shortest path: we close the gaps with you until handover or signature holds.

  4. 04
    Annual cycle

    Buys you steadiness: the §39 evidence returns by law every three years, the new KritisV shifts thresholds. The cycle keeps your dossier handover-ready, date after date.

READY?

One metric to your classification.

The KRITIS check is part of the NIS2 self-check: pick your sector, enter one facility metric, see both duty stacks with deadlines. No account, no sales call.

A self-check result is orientation, not evidence. The §39 evidence is performed exclusively by the qualified examining body.

Healthcare cloud services alongside? C5 belongs in the same stack →