Operators of critical infrastructure have to prove that physical access to their sites is controlled and documented. In Germany, the NIS-2-Umsetzungsgesetz has applied since 6 December 2025, and the KRITIS-Dachgesetz since 17 March 2026. The KRITIS-Dachgesetz requires appropriate physical protection of critical installations, and a resilience plan that is applied rather than filed; the NIS-2-Umsetzungsgesetz adds information-security obligations. Neither prescribes a technology. In practice, an operator who can show every issue, return and transfer of a key is the one who can answer an inspection without a search. An inventory on its own does not carry that.
Key takeaways
- Responsibility for the legal obligations stays with the operator. Good key management does not take it off their hands, it makes it provable.
- Key management that holds up records every key movement without gaps and keeps access rights provable at any time. That is practice, not a requirement written into the act.
- The KRITIS-Dachgesetz and the NIS-2-Umsetzungsgesetz require demonstrable physical protection, not just technical measures on paper.
- § 13 of the KRITIS-Dachgesetz lists access controls among the measures that may count towards physical protection, and names security management for staff including the personnel of external service providers.
- portier Vision 5 records every key movement, produces signed handover receipts and keeps the history available for years.
Is there such a thing as key management software that satisfies KRITIS on its own?
No. The KRITIS-Dachgesetz and the NIS-2-Umsetzungsgesetz place their duties on operators of critical installations, not on software vendors. There is no product certification behind the phrase, and no stamp a program can carry. What the phrase describes is how an operator runs key management.
Responsibility for meeting the legal obligations stays with the operator, and it cannot be delegated to a program. What good key management does is make that responsibility provable, supplying the evidence on demand.
In practice that means recording every issue, return and transfer of a key. The record shows who holds which key, which doors it opens and who approved the issue. An inventory on its own shows none of that.
Which legal requirements apply to physical access protection?
The KRITIS-Dachgesetz makes appropriate physical protection of critical installations mandatory. What § 13 requires is the outcome. It then lists measures that may count towards it, access controls among them, and names appropriate security management for staff including the personnel of external service providers. § 12 requires the operator to carry out a risk analysis and assessment as needed and at least every four years. No particular technology is prescribed. The wording is in the official version on gesetze-im-internet.de.
The NIS-2-Umsetzungsgesetz adds information-security obligations that also cover physical components.
Timing matters here. The act is in force, but its duties attach to an operator on registration, and no registration duty has started yet. The ordinance that sets which installations count has not been issued.
Evidence is what counts. § 16 of the KRITIS-Dachgesetz governs evidence and official orders. The authority can ask an operator to produce the resilience plan and further evidence, and it chooses who to check on a risk basis. An operator who issues and takes back keys should be able to show that record when it is asked for. Not claim it, show it.
For the law itself and why the record is what carries it, see the KRITIS umbrella act and the evidence it demands.
What key management has to do in practice
None of the five below is prescribed by the act. They are what operators who get through an inspection without a scramble tend to have in place, and they are how portier builds.
A complete issue-and-return history. Every key movement is recorded with a timestamp, a responsible person and an approval, including issues, returns, losses and transfers. The record stays available for years.
Rule-based issuing with approval steps. Keys are issued only under defined rules: role-based permissions, time-limited issues and approval procedures for security-critical areas.
Control of overdue returns. When a contract ends or a role changes, someone has to reclaim the key. Overdue returns are visible without anyone checking by hand.
Traceable approval chains. An inspection asks who approved an issue, on what basis and when. The record answers it.
A link to the locking plan. The system has to know which key opens which cylinders, so that after an incident you can narrow down which areas are affected rather than questioning the whole system.
What happens when a service provider leaves?
A maintenance contract ends, an outside firm leaves the site, a role changes. That is the moment the documentation is tested. An inspection asks three questions, and each has to be answerable without anyone digging through folders.
Did every issued key come back? The issue-and-return history shows it per person and per key, with the date and the responsible person.
If a key is missing, which cylinders does it open? The link to the locking plan narrows the affected area instead of putting the whole site in doubt. That is the difference between a documented incident and an expensive re-core on suspicion.
And does today’s access reflect today’s roles? Whoever has left the site should hold no valid permission. § 13 names security management for staff, including the personnel of external service providers.
portier Vision 5 is built to answer these questions out of daily operation. Every movement is recorded, every transfer receipted, every loss documented. The evidence builds as the work happens, not the evening before the inspection.
Why audit readiness is more than documentation
Many organisations document their key inventory. At an inspection under § 16 of the KRITIS-Dachgesetz, or during an ISO 27001 certification, that alone is not enough. The auditor does not ask whether you keep an inventory. She asks whether you can prove who held the key, when it was issued and returned, and under which rule.
Audit readiness comes when the daily work produces the evidence as a by-product, not as an extra chore. portier Vision 5 is built for exactly that. It records every key movement, produces signed handover receipts and keeps the history available for years.
Whoever keeps a clean record anyway has the evidence in hand when the inspection comes.
How does portier Vision 5 support KRITIS operators?
portier Vision 5 manages locking plans, cylinders and keys in one structured system. Every movement is recorded, issue and return with a receipt, handovers with a digital signature on the signature pad.
The system works with the existing locking hardware. There is no need to replace cylinders or keys; portier Vision 5 brings structure and evidence to what is already installed.
portier is certified to ISO/IEC 27001 as an organisation, the certificate covering how the company is run and how it develops its software. The certificate is in portier’s Trust Center. portier Vision 5 is available on-premise, so the data stays in your own environment.
The difference between control and tracking
Tracking describes the past. It shows who had a key. Control decides what is allowed, applies the rule at the moment of issue and makes overdue returns visible.
For KRITIS operators that difference matters. An inspection does not only ask whether keys were recorded, but whether a rule was applied at issue, whether the return actually happened, and whether today’s access reflects today’s roles.
portier Vision 5 works on the principle of control first, automation second. For critical infrastructure that means a system that enforces the rules and produces the evidence as a by-product of daily work.
Summary: what this means for key management now
The KRITIS-Dachgesetz and the NIS-2-Umsetzungsgesetz make physical protection of critical installations mandatory. An operator who cannot show what happened to a key has nothing to put in front of an inspection.
The responsibility stays with the operator. Key management that holds up replaces informal processes with clear rules and complete records. It captures every movement, enforces approvals and holds the evidence ready before the authority asks for it. For how that differs from a key list in Excel, see Mechanical key management beyond Excel.
Common Questions About KRITIS and Key Management
Can software on its own satisfy the KRITIS-Dachgesetz?
No. Responsibility for meeting the legal obligations stays with the operator and cannot be delegated to a program. Software can make that responsibility provable, by recording every key movement and holding the evidence ready on demand. The obligation itself stays with the operator.
What is the difference between the KRITIS-Dachgesetz and NIS-2?
The KRITIS-Dachgesetz governs the physical protection of critical facilities. The NIS-2-Umsetzungsgesetz focuses on information security but includes physical components. Both can apply at the same time and each requires its own evidence.
Do I have to replace my locking hardware to meet the requirements?
No. The KRITIS-Dachgesetz does not prescribe a specific technology. portier Vision 5 works with the existing locking system and adds the documentation and the rules without replacing hardware.
How does portier Vision 5 support audit readiness?
portier Vision 5 records every key movement with a timestamp, a responsible person and a digital signature. The history stays available for years, so the evidence is ready at an inspection.
What evidence does an inspection under the KRITIS-Dachgesetz require?
Section 16 of the KRITIS-Dachgesetz governs evidence and official orders. The authority can ask for the resilience plan and further evidence, and chooses which operators to check on a risk basis. In practice, being able to show who held a key, which rule applied at issue and who approved it is what answers the question.
Is a spreadsheet enough as evidence?
A list shows the inventory, not the history. Evidence that holds up records issue, return and approval with a timestamp and a responsible person, and stays available for years. portier Vision 5 produces that history in the course of daily operation.