Expanded critical infrastructure requirements through the NIS2 Directive
The transposition of the NIS2 Directive into national law has dramatically widened the circle of affected organisations. While the term critical infrastructure was long associated with large power stations, central water utilities or rail transport hubs, that view has been obsolete since 2026. As a result of recent amendments to the BSI Act, mid-sized companies in the transport, logistics, healthcare and waste management sectors as well as public authorities and agencies now also fall under the strict reporting obligations and security requirements.
Anyone who ignores the new standards risks not only devastating operational outages but also faces significant personal liability risks and sanctions. Vulnerability is not limited to the digital elements of an infrastructure - as the mechanical attacks on Berlin's power supply in September 2025 demonstrated.
Connectivity creates new attack surfaces
Modern building automation today is almost without exception networked. Whether via Wi-Fi, radio or wired bus systems: every automated door, every smart window and every smoke and heat extraction (SHE) system is a potential endpoint on a network. That makes each of these systems a possible gateway for cyberattacks if protection does not reflect the current state of the art.
The interface between IT and physical security is particularly problematic in this respect. A classic real-world example illustrates the risk: if an automatic door system develops a fault during operation, in the rush of everyday work it is often mechanically blocked out of convenience or ignorance - it is "propped open". In a critical infrastructure context this is no trivial matter but a security gap that removes the physical separation which is meant to guarantee protection against unauthorised access.
Physical and digital security as a single entity
The integrity of a critical infrastructure facility stands or falls with the physical protection of the building envelope as well as the internal interfaces between sensitive critical areas and publicly accessible zones. Genuine KRITIS compliance therefore calls for a rethink: digital protection and mechanical reliability must be planned and operated as an inseparable unit.
Integrated planning approaches for KRITIS compliance
The new statutory requirements are shifting planning priorities considerably. What can be observed today is an increase in so-called functional conflicts. High security barriers and restrictive access controls inevitably collide, in the case of doors and other elements of the building envelope, with the desire for maximum ease of use, comprehensive accessibility and the lowest possible maintenance effort.
To avoid expensive remedial work or even complete replanning, those responsible for construction and buildings must seek expert advice earlier than ever. An integrated planning approach views the building not as the sum of individual trades but as an overall system.
Challenges when modernising existing buildings
Modernising existing buildings is particularly challenging. Many buildings relevant to critical infrastructure have systems that have grown historically and often operate as isolated solutions. The pressing question is: how can outdated components be retrofitted in a KRITIS-compliant manner without having to replace the entire infrastructure?
A well-founded inventory assessment is the first step towards identifying interfaces that are viable for the future both in security terms and functionally. The aim must be to find a solution that meets stringent protection requirements without paralysing building operations through excessive complexity.
Technical standards for secure interoperability
Interoperability is a decisive technical lever for implementing KRITIS-compliant solutions. Automated door and window solutions today have to handle complex tasks simultaneously: fire protection requirements must be met, escape and rescue routes guaranteed at all times and accessibility maintained. At the same time, the system must be fully integrated into the higher-level building management system in order to deliver status messages in real time.
Experts consistently rely on open and secure communication standards to ensure the necessary transparency and security. At present, OPC UA forms the basis for platform-independent and secure data exchange. Looking ahead, and given the rising demands on network security, BACnetSC (Secure Connect) will also play a central role.
Encryption as a basic prerequisite
These standards make it possible not only to control security functions but to communicate them in encrypted form and monitor them seamlessly. In a KRITIS-compliant architecture, this protocol-level encryption is a basic prerequisite for preventing man-in-the-middle attacks on building services technology.
Practical recommendations for KRITIS-compliant building automation
The new requirements translate into concrete recommendations for practical implementation:
- Involve security experts early in the planning phase
- View the building as an overall system rather than isolated trades
- Carry out a well-founded inventory assessment before modernisation measures
- Use open and secure communication standards
- Implement end-to-end encryption at protocol level
- Review and adjust security measures regularly
With access control systems in particular, care must be taken to ensure that mechanical security measures are not undermined by operational stopgaps. Faults must be rectified systematically rather than establishing improvised workarounds.
Outlook: security as an ongoing task
KRITIS compliance is not a one-off project but an ongoing task throughout a building's lifecycle. In the face of a constantly changing threat situation and dynamic legislation, forward-looking planning is the only route to resilience.
The integration of IT security and physical building security will become even more important in future. Companies that invest in future-proof solutions today can use security as a competitive advantage rather than experiencing it as an obstacle. With the right partners and intelligently networked building automation, security becomes a guarantor of stable, future-proof operations.
The expansion of critical infrastructure requirements makes one thing clear: protecting critical infrastructures begins at the building envelope and requires a rethink across the entire planning and operating phase of properties.