KRITIS security standards
Sector-specific requirements (e.g. energy, IT, transport) for protection of critical components and proof of effective security measures.
Operators of energy, water, transport, healthcare, and other essential facilities carry obligations under KRITIS and NIS2. VORNAC validates the OT/IT boundary and production systems with exploit-proven findings, audit-ready for BSI and sector regulators.
Germany’s KRITIS umbrella and the NIS2 Directive set concrete security and incident obligations for operators of essential services.
Sector-specific requirements (e.g. energy, IT, transport) for protection of critical components and proof of effective security measures.
Risk management, incident handling, supply chain security, and testing of cybersecurity defenses for essential and important entities.
Timely detection, response, and notification. Regulators expect evidence that controls work under real attack conditions.
Increasing connectivity between operational technology and corporate IT expands the attack surface. Both must be validated.
KRITIS audits fail when the “representative scope” misses exactly the segment an attacker moves through. VORNAC tests the full attack surface, every cycle.
Attack surface coverage per cycle.
Findings structured for KRITIS and NIS2 supervisory dialogue. Not generic scanner output.
Validate after every infrastructure change and release. Not once per audit cycle.
Data and operations stay in German jurisdiction. Required for operators of national infrastructure.