<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Nis2 on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/nis2/</link><description>Recent content in Nis2 on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/nis2/index.xml" rel="self" type="application/rss+xml"/><item><title>KRITIS (German Critical Infrastructure)</title><link>https://lesitedefrancois.be/en/compliance/kritis/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/kritis/</guid><description>&lt;p&gt;&lt;strong&gt;KRITIS&lt;/strong&gt; (Kritische Infrastrukturen) is Germany&amp;rsquo;s national regulatory framework for the security and resilience of critical infrastructure. It is enforced by the &lt;strong&gt;BSI&lt;/strong&gt; (Bundesamt für Sicherheit in der Informationstechnik — Federal Office for Information Security) and, for physical resilience, by the &lt;strong&gt;BBK&lt;/strong&gt; (Bundesamt für Bevölkerungsschutz und Katastrophenhilfe — Federal Office of Civil Protection). The framework is now governed by two primary laws: the &lt;strong&gt;NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG)&lt;/strong&gt;, which rewrote the BSI-Gesetz and entered into force on 6 December 2025, and the &lt;strong&gt;KRITIS-Dachgesetz (KRITISDachG)&lt;/strong&gt; for physical resilience, in force since 17 March 2026. Together they transpose the EU NIS2 Directive and CER Directive into German law. The scope expanded dramatically: from approximately 4,000 regulated entities under the previous IT-Sicherheitsgesetz 2.0 to around &lt;strong&gt;30,000 entities&lt;/strong&gt; now classified as either &amp;ldquo;besonders wichtige Einrichtungen&amp;rdquo; (particularly important, equivalent to NIS2 essential) or &amp;ldquo;wichtige Einrichtungen&amp;rdquo; (important). KRITIS applies to organizations in 18 sectors (energy, water, health, finance, transport, digital infrastructure, space, public administration, manufacturing, etc.) meeting defined size thresholds. Compliance is &lt;strong&gt;mandatory&lt;/strong&gt; with no transitional period: entities must register with the BSI, implement risk management (§30 BSIG), report security incidents within 24 hours (§32), and management is &lt;strong&gt;personally liable&lt;/strong&gt; (§38) for overseeing cybersecurity measures. Penalties reach up to €10M or 2 % of global turnover for particularly important entities.&lt;/p&gt;</description></item></channel></rss>