KRITIS and Why Locking System Management Matters


KRITIS and Why Locking System Management Matters

The protection of critical infrastructure, and terms like KRITIS and NIS-2, are being discussed everywhere at the moment. Attacks on rail networks and on power supply, alongside daily cyber attacks, show how exposed critical infrastructure is. Protecting it means every security measure has to work with the others. This article sets out how portier supports operators of critical infrastructure, security retailers and locking system manufacturers on that.

What KRITIS means

The German Federal Office for Information Security (BSI) defines it this way:

“Critical infrastructures (KRITIS) are organisations and institutions of major importance to the state and the community, whose failure or impairment would cause lasting supply shortages, significant disruption to public safety, or other dramatic consequences.”

The sectors in scope

Every organisation in these sectors counts as critical infrastructure, whatever its size:

  1. Energy
  2. Information technology and telecommunications
  3. Transport
  4. Health
  5. Media and culture
  6. Water
  7. Food
  8. Finance and insurance
  9. Municipal waste disposal
  10. Government and public administration

The legal basis

The legal basis for critical infrastructure and its operators is the Act on the Federal Office for Information Security (BSIG). At the end of 2022 the European Union published the second directive on network and information security, NIS-2. Germany transposed it through the NIS-2 implementation act, which has applied since 6 December 2025.

That brings far wider cybersecurity requirements and extensive continuity obligations to thousands of companies, both newly in scope and already operating.

Holger Berens, voorzitter van de raad van bestuur van de Federatie voor de Bescherming van Kritieke Infrastructuren Foto: BSKI

“The current situation is tense. Our infrastructure, including state institutions, is attacked daily. The war in Ukraine has made that worse. Organised crime attacks daily as well. We all know the consequences from the news. Implementing the NIS 2.0 directive in Germany will newly identify around 30,000 to 40,000 companies as critical infrastructure, which will be legally required to put appropriate security measures in place. This is the first step in the right direction.”

Holger Berens,
Chairman of the Board, German Federal Association for the Protection of Critical Infrastructure
Photo: BSKI

What that has to do with locking system management

The measures an operator has to implement carry numerous security requirements and the organisational arrangements that go with them.

Alongside secure key management, which in that context means the security measures around digital access authorisations, they also cover personnel and organisational security, and structural and physical security such as perimeter protection and physical entry control.

From the catalogue of measures:

“Physical access protection. Entry to premises or buildings housing sensitive or critical information, information systems or other network infrastructure belonging to the operator of a critical service is secured and monitored by physical access controls, in order to prevent unauthorised entry.”

So secure mechanical and electronic locking systems and access control are part of what is asked for. Preventing unauthorised entry also takes professional locking system management. Even the best locking system is close to worthless in security terms if there is no accurate record of key management and of who was authorised to enter. That is where portier fits.

For operators of critical infrastructure

portier improves the management of the mechanical locking systems that critical infrastructure relies on. With portier Vision 5, operators keep track of key issues, entry authorisations and cylinder records efficiently. That improves security and makes compliance requirements easier to meet.

For security retailers

For security retailers, portier is a complete software solution that extends what they can offer around installing and managing mechanical locking systems. It supports the move to digital documentation and keeps an accurate key history, which helps retailers deliver a more precise and more trustworthy service.

For locking system manufacturers

Locking system manufacturers benefit by positioning their products as compatible with leading management software. That makes their mechanical locking systems more attractive for modern security programmes in organisations that need efficient management and documentation.

Working towards KRITIS compliance

portier makes KRITIS compliance easier through detailed tracking and documentation of every key movement and entry authorisation. The information needed for audits and security reviews stays quick and simple to reach, which makes meeting the requirements more straightforward.

In closing

KRITIS and NIS-2 will affect many companies, and close to all of them in some sectors. Even a company outside the legal scope is often a supplier to one inside it, and those operators select their suppliers carefully, sometimes audit them. The requirements are already biting, so it is worth understanding the topic properly and taking the measures it calls for.

portier works at the front of mechanical locking system management and builds for what critical infrastructure actually needs. By improving security measures and simplifying compliance, portier is a strong partner for operators of critical infrastructure, security retailers and locking system manufacturers.

Sources and further information: German Federal Office for Information Security (BSI), German Federal Association for the Protection of Critical Infrastructure (BSKI), OpenKRITIS.


Abonneren