Essential entity with proactive supervision
Annex I means the highest sanction tier, active BSI supervision and faster intervention rights. On findings, the BSI does not just send a notice; it arrives on site.
Annex I of the German NIS-2 implementation act covers energy (electricity, district heating, oil, gas, hydrogen) as an essential entity. From 250 employees or 50 million euros revenue, the obligations apply. For KRITIS operators, the German threshold regulation and BSIG obligations add up. The Cybervize platform covers ISMS, OT assessment and KRITIS reporting in one solution.
Book the NIS-2 risk check
Electricity, gas, heat and hydrogen utilities generally fall under NIS-2 Annex I as „essential entity"; additionally, the KRITIS regulation typically applies once asset-related thresholds are exceeded. Four consequences of this classification for a typical energy provider. Sector alone is not enough: KRITIS status and NIS-2 classification additionally depend on size thresholds and concrete supply scope. The legally binding evaluation remains a matter for counsel.
Annex I means the highest sanction tier, active BSI supervision and faster intervention rights. On findings, the BSI does not just send a notice; it arrives on site.
Whoever exceeds KRITIS thresholds (e.g. 500,000 supplied persons for electricity) becomes additionally a KRITIS operator. Obligations overlap but are not identical. NIS-2 is broader in sector scope, KRITIS is deeper on plant requirements.
For essential entities, some reaction deadlines tighten and the content of reports is more regulated. Initial report 24 hours, follow-up 72 hours, final report within one month, plus potential customer notification obligations.
Operational technology is the dominant attack surface in the energy sector. Control rooms, SCADA connections, smart-meter-gateway infrastructure and maintenance access need segmented architecture and continuous monitoring.
Five of the ten minimum measures per §30, translated into energy practice.
OT and IT risks assessed jointly, covering smart grid connections, control rooms and generation assets. Smart metering and market communication form their own risk landscape.
BSI-compliant crypto concepts for smart-meter gateways, control communication and remote-maintenance tunnels. Key management central and audit-ready.
Supplier audits for SCADA vendors and maintenance service providers. Remote-maintenance access documented, patch management for controllers aligned with maintenance windows.
MFA for control-room access, privileged accounts separated, role model for OT distinct from office IT RBAC. Emergency access documented.
BCM plans for generation outages, grid restoration exercises, black-start capability. Plus crisis communication to regulators and end customers.
The Cybervize platform covers ISMS, BCM, Assessment and supplier risk in one solution. For energy providers, KRITIS reporting and OT modules are additionally relevant.
Free 30-minute initial call with an indicative NIS-2 classification, top-5 gaps and a path recommendation.
Learn more Service 02ISMS, compliance and evidence from a single platform. Multi-entity, multi-country, AI-supported.
Learn more Service 03Platform plus permanent CISO function. For organisations without an in-house CISO.
Learn more Service 04Gap assessment, roadmap, implementation via the platform. Fixed price from 4,500 euros.
Learn moreSelf-check available
Free, no signup, around 5 minutes. Detailed evaluation by email if desired.
Industry experience in energy and KRITIS from 25 years of ISMS practice at PwC, Deloitte and KPMG. ISO 27001 Lead Auditor since 2006, BSI IT-Grundschutz auditor. Methodology built for audit-ready evidence towards the BSI.
Free risk check with indicative NIS-2 classification, KRITIS threshold indicator, top-5 gaps and path recommendation. Ideally with CISO or IT security leadership plus management board present.
Book the NIS-2 risk checkStructured NIS-2 compliance: gap assessment, roadmap, and implementation in 12 weeks.
Learn moreFree self-check: where do you stand on the ten §30 BSIG measures? 30 questions, instant traffic light.
Learn moreThe ten regulated sectors the Cybervize platform runs in.
Learn moreMany companies treat NIS2 as a tick-box exercise. But compliance is not the same as resilience. The Cross-Border Cybersecurity Tour #2 in Saarbrücken made it clear: a functioning security operation outweighs any tool collection.
Most security programs do not fail at launch. They fail when initiative must become routine. Five binding routines for sustainable governance.
Organizations that treat AI agents as magic will never control them. What an AI agent actually is and why that changes everything.