KRITIS (Kritische Infrastrukturen) is Germany’s national regulatory framework for the security and resilience of critical infrastructure. It is enforced by the BSI (Bundesamt für Sicherheit in der Informationstechnik — Federal Office for Information Security) and, for physical resilience, by the BBK (Bundesamt für Bevölkerungsschutz und Katastrophenhilfe — Federal Office of Civil Protection). The framework is now governed by two primary laws: the NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG), which rewrote the BSI-Gesetz and entered into force on 6 December 2025, and the KRITIS-Dachgesetz (KRITISDachG) for physical resilience, in force since 17 March 2026. Together they transpose the EU NIS2 Directive and CER Directive into German law. The scope expanded dramatically: from approximately 4,000 regulated entities under the previous IT-Sicherheitsgesetz 2.0 to around 30,000 entities now classified as either “besonders wichtige Einrichtungen” (particularly important, equivalent to NIS2 essential) or “wichtige Einrichtungen” (important). KRITIS applies to organizations in 18 sectors (energy, water, health, finance, transport, digital infrastructure, space, public administration, manufacturing, etc.) meeting defined size thresholds. Compliance is mandatory with no transitional period: entities must register with the BSI, implement risk management (§30 BSIG), report security incidents within 24 hours (§32), and management is personally liable (§38) for overseeing cybersecurity measures. Penalties reach up to €10M or 2 % of global turnover for particularly important entities.
Red Hat is not a KRITIS-obligated entity itself, but German KRITIS operators — energy utilities, hospitals, banks, telecom providers, public administration — run their IT infrastructure on Red Hat software. Red Hat enables KRITIS compliance at the technology layer through several concrete capabilities. For the BSI-Gesetz §30 risk management requirements: RHEL provides system-wide cryptographic policies (including FIPS mode), SELinux mandatory access control, and integration with BSI IT-Grundschutz security modules via OpenSCAP profiles. For incident detection and reporting (§32): Red Hat Advanced Cluster Security (RHACS) delivers continuous runtime monitoring, network policy enforcement, and vulnerability management that compresses detection-to-report timelines. For supply chain security mandated across the entire NIS2 transposition: Red Hat Trusted Software Supply Chain provides signed, attested artifacts with SBOMs — evidence that KRITIS operators can present to auditors demonstrating they assessed their software suppliers’ security practices. For continuity and resilience under the KRITIS-Dachgesetz: Red Hat’s GitOps-based deployment model, Ansible Automation Platform for disaster recovery orchestration, and OpenShift’s multi-cluster management enable the operational continuity measures the law demands. The BSI’s new Grundschutz++ methodology (OSCAL/JSON-based) also aligns with Red Hat’s investment in machine-readable compliance tooling (complyctl, Compliance Operator), potentially automating evidence collection for BSI audits.
