{"id":13838,"date":"2026-09-03T13:06:19","date_gmt":"2026-09-03T03:06:19","guid":{"rendered":"https:\/\/stagingapp20309.cloudwayssites.com\/?p=13838"},"modified":"2026-09-21T17:36:46","modified_gmt":"2026-09-21T07:36:46","slug":"kritis-dachgesetz-key-management","status":"publish","type":"post","link":"https:\/\/stagingapp20309.cloudwayssites.com\/fr\/kritis-dachgesetz-key-management\/","title":{"rendered":"What the KRITIS-Dachgesetz Requires of Key Management"},"content":{"rendered":"<p><em>Operators of critical infrastructure have to prove that physical access to their sites is controlled and documented. In Germany, the NIS-2-Umsetzungsgesetz has applied since 6 December 2025, and the KRITIS-Dachgesetz since 17 March 2026. The KRITIS-Dachgesetz requires appropriate physical protection of critical installations, and a resilience plan that is applied rather than filed; the NIS-2-Umsetzungsgesetz adds information-security obligations. Neither prescribes a technology. In practice, an operator who can show every issue, return and transfer of a key is the one who can answer an inspection without a search. An inventory on its own does not carry that.<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading has-large-font-size\">Key takeaways<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Responsibility for the legal obligations stays with the operator. Good key management does not take it off their hands, it makes it provable.<\/li>\n\n\n\n<li>Key management that holds up records every key movement without gaps and keeps access rights provable at any time. That is practice, not a requirement written into the act.<\/li>\n\n\n\n<li>The KRITIS-Dachgesetz and the NIS-2-Umsetzungsgesetz require demonstrable physical protection, not just technical measures on paper.<\/li>\n\n\n\n<li>\u00a7 13 of the KRITIS-Dachgesetz lists access controls among the measures that may count towards physical protection, and names security management for staff including the personnel of external service providers.<\/li>\n\n\n\n<li>portier Vision 5 records every key movement, produces signed handover receipts and keeps the history available for years.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large is-resized\" style=\"margin-top:var(--wp--preset--spacing--50);margin-bottom:var(--wp--preset--spacing--50)\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"771\" src=\"https:\/\/stagingapp20309.cloudwayssites.com\/wp-content\/uploads\/2026\/09\/illustration-1024x771.jpg\" alt=\"Office corridor, one person unlocking a door with a mechanical key, another walking down the corridor with a laptop, both wearing ID badges on lanyards.\" class=\"wp-image-13855\" style=\"width:400px\" srcset=\"https:\/\/stagingapp20309.cloudwayssites.com\/wp-content\/uploads\/2026\/09\/illustration-1024x771.jpg 1024w, https:\/\/stagingapp20309.cloudwayssites.com\/wp-content\/uploads\/2026\/09\/illustration-300x226.jpg 300w, https:\/\/stagingapp20309.cloudwayssites.com\/wp-content\/uploads\/2026\/09\/illustration-768x578.jpg 768w, https:\/\/stagingapp20309.cloudwayssites.com\/wp-content\/uploads\/2026\/09\/illustration-1536x1157.jpg 1536w, https:\/\/stagingapp20309.cloudwayssites.com\/wp-content\/uploads\/2026\/09\/illustration-16x12.jpg 16w, https:\/\/stagingapp20309.cloudwayssites.com\/wp-content\/uploads\/2026\/09\/illustration.jpg 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\"><em>Access happens in daily work. Who takes which key is recorded as it happens, not on audit day.<\/em><\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading has-large-font-size\">Is there such a thing as key management software that satisfies KRITIS on its own?<\/h2>\n\n\n\n<p>No. The KRITIS-Dachgesetz and the NIS-2-Umsetzungsgesetz place their duties on operators of critical installations, not on software vendors. There is no product certification behind the phrase, and no stamp a program can carry. What the phrase describes is how an operator runs key management.<\/p>\n\n\n\n<p>Responsibility for meeting the legal obligations stays with the operator, and it cannot be delegated to a program. What good key management does is make that responsibility provable, supplying the evidence on demand.<\/p>\n\n\n\n<p>In practice that means recording every issue, return and transfer of a key. The record shows who holds which key, which doors it opens and who approved the issue. An inventory on its own shows none of that.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading has-large-font-size\">Which legal requirements apply to physical access protection?<\/h2>\n\n\n\n<p>The KRITIS-Dachgesetz makes appropriate physical protection of critical installations mandatory. What \u00a7 13 requires is the outcome. It then lists measures that may count towards it, access controls among them, and names appropriate security management for staff including the personnel of external service providers. \u00a7 12 requires the operator to carry out a risk analysis and assessment as needed and at least every four years. No particular technology is prescribed. The wording is in the official version on <a href=\"https:\/\/www.gesetze-im-internet.de\/kritisdachg\/\" target=\"_blank\" rel=\"noopener\">gesetze-im-internet.de<\/a>.<\/p>\n\n\n\n<p>The NIS-2-Umsetzungsgesetz adds information-security obligations that also cover physical components.<\/p>\n\n\n\n<p>Timing matters here. The act is in force, but its duties attach to an operator on registration, and no registration duty has started yet. The ordinance that sets which installations count has not been issued.<\/p>\n\n\n\n<p>Evidence is what counts. \u00a7 16 of the KRITIS-Dachgesetz governs evidence and official orders. The authority can ask an operator to produce the resilience plan and further evidence, and it chooses who to check on a risk basis. An operator who issues and takes back keys should be able to show that record when it is asked for. Not claim it, show it.<\/p>\n\n\n\n<p>For the law itself and why the record is what carries it, see <a href=\"https:\/\/stagingapp20309.cloudwayssites.com\/fr\/kritis-umbrella-act-evidence\/\">the KRITIS umbrella act and the evidence it demands<\/a>.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading has-large-font-size\">What key management has to do in practice<\/h2>\n\n\n\n<p>None of the five below is prescribed by the act. They are what operators who get through an inspection without a scramble tend to have in place, and they are how portier builds.<\/p>\n\n\n\n<p><strong>A complete issue-and-return history.<\/strong> Every key movement is recorded with a timestamp, a responsible person and an approval, including issues, returns, losses and transfers. The record stays available for years.<\/p>\n\n\n\n<p><strong>Rule-based issuing with approval steps.<\/strong> Keys are issued only under defined rules: role-based permissions, time-limited issues and approval procedures for security-critical areas.<\/p>\n\n\n\n<p><strong>Control of overdue returns.<\/strong> When a contract ends or a role changes, someone has to reclaim the key. Overdue returns are visible without anyone checking by hand.<\/p>\n\n\n\n<p><strong>Traceable approval chains.<\/strong> An inspection asks who approved an issue, on what basis and when. The record answers it.<\/p>\n\n\n\n<p><strong>A link to the locking plan.<\/strong> The system has to know which key opens which cylinders, so that after an incident you can narrow down which areas are affected rather than questioning the whole system.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading has-large-font-size\">What happens when a service provider leaves?<\/h2>\n\n\n\n<p>A maintenance contract ends, an outside firm leaves the site, a role changes. That is the moment the documentation is tested. An inspection asks three questions, and each has to be answerable without anyone digging through folders.<\/p>\n\n\n\n<p>Did every issued key come back? The issue-and-return history shows it per person and per key, with the date and the responsible person.<\/p>\n\n\n\n<p>If a key is missing, which cylinders does it open? The link to the locking plan narrows the affected area instead of putting the whole site in doubt. That is the difference between a documented incident and an expensive re-core on suspicion.<\/p>\n\n\n\n<p>And does today&#8217;s access reflect today&#8217;s roles? Whoever has left the site should hold no valid permission. \u00a7 13 names security management for staff, including the personnel of external service providers.<\/p>\n\n\n\n<p>portier Vision 5 is built to answer these questions out of daily operation. Every movement is recorded, every transfer receipted, every loss documented. The evidence builds as the work happens, not the evening before the inspection.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading has-large-font-size\">Why audit readiness is more than documentation<\/h2>\n\n\n\n<p>Many organisations document their key inventory. At an inspection under \u00a7 16 of the KRITIS-Dachgesetz, or during an ISO 27001 certification, that alone is not enough. The auditor does not ask whether you keep an inventory. She asks whether you can prove who held the key, when it was issued and returned, and under which rule.<\/p>\n\n\n\n<p>Audit readiness comes when the daily work produces the evidence as a by-product, not as an extra chore. <a href=\"https:\/\/stagingapp20309.cloudwayssites.com\/fr\/solutions-2\/vision-portier-5\/\">portier Vision 5<\/a> is built for exactly that. It records every key movement, produces signed handover receipts and keeps the history available for years.<\/p>\n\n\n\n<p>Whoever keeps a clean record anyway has the evidence in hand when the inspection comes.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading has-large-font-size\">How does portier Vision 5 support KRITIS operators?<\/h2>\n\n\n\n<p>portier Vision 5 manages locking plans, cylinders and keys in one structured system. Every movement is recorded, issue and return with a receipt, handovers with a digital signature on the signature pad.<\/p>\n\n\n\n<p>The system works with the existing locking hardware. There is no need to replace cylinders or keys; portier Vision 5 brings structure and evidence to what is already installed.<\/p>\n\n\n\n<p>portier is certified to ISO\/IEC 27001 as an organisation, the certificate covering how the company is run and how it develops its software. The certificate is in portier&#8217;s <a href=\"https:\/\/trust.stagingapp20309.cloudwayssites.com\/\">Trust Center<\/a>. portier Vision 5 is available on-premise, so the data stays in your own environment.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\" style=\"margin-top:var(--wp--preset--spacing--50);margin-bottom:var(--wp--preset--spacing--50)\"><img loading=\"lazy\" decoding=\"async\" width=\"737\" height=\"400\" src=\"https:\/\/stagingapp20309.cloudwayssites.com\/wp-content\/uploads\/2026\/08\/5.7.1-homepage-2.png\" alt=\"The portier Vision 5.7 dashboard with the Issues tile selected, where keys are issued and the handover recorded.\" class=\"wp-image-13846\" style=\"width:auto;height:340px\" srcset=\"https:\/\/stagingapp20309.cloudwayssites.com\/wp-content\/uploads\/2026\/08\/5.7.1-homepage-2.png 737w, https:\/\/stagingapp20309.cloudwayssites.com\/wp-content\/uploads\/2026\/08\/5.7.1-homepage-2-300x163.png 300w, https:\/\/stagingapp20309.cloudwayssites.com\/wp-content\/uploads\/2026\/08\/5.7.1-homepage-2-18x10.png 18w\" sizes=\"auto, (max-width: 737px) 100vw, 737px\"><figcaption class=\"wp-element-caption\"><em>In portier Vision 5, every key movement, issue, return and loss, is on record with a timestamp and a responsible person, so the evidence a KRITIS inspection asks for is ready without a search.<\/em><\/figcaption><\/figure>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading has-large-font-size\">The difference between control and tracking<\/h2>\n\n\n\n<p>Tracking describes the past. It shows who had a key. Control decides what is allowed, applies the rule at the moment of issue and makes overdue returns visible.<\/p>\n\n\n\n<p>For KRITIS operators that difference matters. An inspection does not only ask whether keys were recorded, but whether a rule was applied at issue, whether the return actually happened, and whether today&#8217;s access reflects today&#8217;s roles.<\/p>\n\n\n\n<p>portier Vision 5 works on the principle of control first, automation second. For critical infrastructure that means a system that enforces the rules and produces the evidence as a by-product of daily work.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading has-large-font-size\">Summary: what this means for key management now<\/h2>\n\n\n\n<p>The KRITIS-Dachgesetz and the NIS-2-Umsetzungsgesetz make physical protection of critical installations mandatory. An operator who cannot show what happened to a key has nothing to put in front of an inspection.<\/p>\n\n\n\n<p>The responsibility stays with the operator. Key management that holds up replaces informal processes with clear rules and complete records. It captures every movement, enforces approvals and holds the evidence ready before the authority asks for it. For how that differs from a key list in Excel, see <a href=\"https:\/\/stagingapp20309.cloudwayssites.com\/fr\/gestion-mecanique-des-cles-au-dela-dexcel\/\">Mechanical key management beyond Excel<\/a>.<\/p>\n\n\n\n<div style=\"height:80px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading has-text-align-center has-large-font-size\" style=\"padding-top:var(--wp--preset--spacing--30);padding-bottom:0\">Common Questions About KRITIS and Key Management<\/h2>\n\n\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list\">\n<div id=\"faq-question-1693000000000\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question\">Can software on its own satisfy the KRITIS-Dachgesetz?<\/h3>\n<div class=\"rank-math-answer\">\n\n<p>No. Responsibility for meeting the legal obligations stays with the operator and cannot be delegated to a program. Software can make that responsibility provable, by recording every key movement and holding the evidence ready on demand. The obligation itself stays with the operator.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1693000000001\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question\">What is the difference between the KRITIS-Dachgesetz and NIS-2?<\/h3>\n<div class=\"rank-math-answer\">\n\n<p>The KRITIS-Dachgesetz governs the physical protection of critical facilities. The NIS-2-Umsetzungsgesetz focuses on information security but includes physical components. Both can apply at the same time and each requires its own evidence.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1693000000002\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question\">Do I have to replace my locking hardware to meet the requirements?<\/h3>\n<div class=\"rank-math-answer\">\n\n<p>No. The KRITIS-Dachgesetz does not prescribe a specific technology. portier Vision 5 works with the existing locking system and adds the documentation and the rules without replacing hardware.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1693000000003\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question\">How does portier Vision 5 support audit readiness?<\/h3>\n<div class=\"rank-math-answer\">\n\n<p>portier Vision 5 records every key movement with a timestamp, a responsible person and a digital signature. The history stays available for years, so the evidence is ready at an inspection.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1693000000004\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question\">What evidence does an inspection under the KRITIS-Dachgesetz require?<\/h3>\n<div class=\"rank-math-answer\">\n\n<p>Section 16 of the KRITIS-Dachgesetz governs evidence and official orders. The authority can ask for the resilience plan and further evidence, and chooses which operators to check on a risk basis. In practice, being able to show who held a key, which rule applied at issue and who approved it is what answers the question.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1693000000005\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question\">Is a spreadsheet enough as evidence?<\/h3>\n<div class=\"rank-math-answer\">\n\n<p>A list shows the inventory, not the history. Evidence that holds up records issue, return and approval with a timestamp and a responsible person, and stays available for years. portier Vision 5 produces that history in the course of daily operation.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n\n\n<div style=\"height:80px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>","protected":false},"excerpt":{"rendered":"<p>What the KRITIS-Dachgesetz asks of physical protection, what \u00a7 13 and \u00a7 16 actually say, and what a key record has to show when an inspection asks for it.<\/p>","protected":false},"author":3,"featured_media":13856,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"rank_math_focus_keyword":"KRITIS key management","rank_math_title":"What the KRITIS-Dachgesetz Requires of Key Management | portier","rank_math_description":"What the KRITIS-Dachgesetz asks of physical protection, what \u00a7 13 and \u00a7 16 actually say, and how portier Vision 5 records every key movement so the evidence is ready for an inspection.","rank_math_robots":"","footnotes":""},"categories":[100],"tags":[],"class_list":["post-13838","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-resources"],"acf":[],"_links":{"self":[{"href":"https:\/\/stagingapp20309.cloudwayssites.com\/fr\/wp-json\/wp\/v2\/posts\/13838","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stagingapp20309.cloudwayssites.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/stagingapp20309.cloudwayssites.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/stagingapp20309.cloudwayssites.com\/fr\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/stagingapp20309.cloudwayssites.com\/fr\/wp-json\/wp\/v2\/comments?post=13838"}],"version-history":[{"count":15,"href":"https:\/\/stagingapp20309.cloudwayssites.com\/fr\/wp-json\/wp\/v2\/posts\/13838\/revisions"}],"predecessor-version":[{"id":13975,"href":"https:\/\/stagingapp20309.cloudwayssites.com\/fr\/wp-json\/wp\/v2\/posts\/13838\/revisions\/13975"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/stagingapp20309.cloudwayssites.com\/fr\/wp-json\/wp\/v2\/media\/13856"}],"wp:attachment":[{"href":"https:\/\/stagingapp20309.cloudwayssites.com\/fr\/wp-json\/wp\/v2\/media?parent=13838"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/stagingapp20309.cloudwayssites.com\/fr\/wp-json\/wp\/v2\/categories?post=13838"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/stagingapp20309.cloudwayssites.com\/fr\/wp-json\/wp\/v2\/tags?post=13838"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}