Perimeter protection in transition: KRITIS and NIS2 shape new requirements
The security industry is at a turning point. With the planned German KRITIS umbrella act, the NIS2 Directive and the CER Directive, the requirements for operators of critical infrastructure are being tightened considerably. Perimeter protection – long a classic discipline of physical security – is being redefined. Protection alone is no longer sufficient; what is required is a documentable, audit- and inspection-proof integration of physical security and cybersecurity. These are precisely the topics of the first Perimeter Protection Congress, which takes place from 22 to 23 April 2026 at the Nuremberg Exhibition Centre.
What is a KRITIS operator and why is compliance decisive?
KRITIS stands for "critical infrastructure" – organisations whose failure or impairment would have considerable effects on security of supply and public welfare. Operators of energy supply installations, transport systems, healthcare facilities and other essential services will in future have to meet strict compliance requirements. What is special about this: they must be able to prove that they meet them – with documented processes, certified systems and verifiable evidence.
The new regulations require that physical and digital security are not considered separately. Perimeter protection is only resilient if it protects against physical intruders as well as being secured against cyberattacks. This means that video surveillance systems, access control and sensors must form networked, secure infrastructures and be fully documentable in the process.
The new requirements for perimeter protection systems
Technological change meets regulatory obligations
Perimeter protection is currently undergoing a technological leap. Cloud technologies, 3D analytics, BIM (Building Information Modeling) and biometric methods are fundamentally extending classic security concepts. These innovations enable more precise monitoring and faster responses to security incidents.
At the same time, regulatory requirements are increasing exponentially. For KRITIS operators this creates a central dilemma: solutions must not only be technically sound, but must also work in a comprehensible way. Every component, every interface, every data processing operation must be documented in an audit-proof manner. Anyone investing in security technology today must already meet tomorrow's requirements – a considerable planning effort.
Classic security technology is no longer sufficient
Effective perimeter protection classically begins at the fence – with physical barriers and visual surveillance. This first line of defence remains important. But without integration with IT security measures, protection today remains incomplete. Separate systems for physical and cyber security lead to gaps that can be exploited by attackers.
The requirement is therefore: network video systems, access control solutions and sensor technology must work together as an integral whole. Only then does the necessary resilience emerge – the ability to detect threats, respond and recover.
Certification as a critical success factor
BSI label as proof of compliance
A central element in meeting the new requirements is certification by independent bodies. The German Federal Office for Information Security (BSI) issues an IT security label certifying that products and systems demonstrably meet security-relevant standards. For KRITIS operators this becomes a decisive advantage: they can not only claim compliance, but document it.
Manufacturers whose entire portfolio carries such certification therefore offer not only technology, but also the administrative evidence for audits and inspections. This considerably reduces the compliance effort and strengthens verifiability towards regulators and inspection authorities.
Concrete solutions for perimeter protection in 2026
Integral systems instead of isolated solutions
The industry is already developing concrete solutions that meet these new requirements. At the Perimeter Protection Congress, the following systems will be presented, for example:
- Radar-video fusion camera Axis Q1686-DLE: Combines radar detection with video analytics for precise perimeter detection – even in difficult weather conditions and at night. This considerably increases the reliability of perimeter surveillance.
- Axis Object Analytics: Analytics software that recognises movement patterns and classifies suspicious activity. The software runs directly on the cameras or in the network and supplies structured data for audits and evaluations.
- Axis Trust Center: A central information platform providing consolidated data on product security, data protection and certifications. This addresses a growing practical need: operators save research effort and gain confidence in audits because all relevant evidence is available centrally.
Best practices from various sectors
Requirements differ from sector to sector. Operators of energy supply installations have different priorities from hospitals or transport companies. The congress will present best practices from the energy, transport, healthcare and also retail sectors – an important transfer of knowledge for the industry.
Why 2026 is the turning point
Regulatory pressure is rising noticeably
The timing of the first Perimeter Protection Congress is no coincidence. With the planned KRITIS umbrella act, the NIS2 Directive (Directive on network and information security) and the CER Directive (Directive on the resilience of critical entities), a regulatory framework is emerging that fundamentally changes the requirements placed on KRITIS operators.
These directives and laws are no longer purely technical in nature – they are governance requirements. Operators must design their security infrastructure not only to a high technical standard, but also in an organisational, documentable and verifiable way. This calls for investment in new systems, but also in processes and know-how.
Integrating physical and cyber resilience as a strategic necessity
The central insight of the new requirements is that physical and cyber resilience cannot be separated. Modern perimeter protection is only effective if both dimensions work together. In concrete terms, this means:
- Video surveillance systems must be IT-secure and centrally manageable.
- Access control systems must be protected against manipulation and unauthorised access.
- Sensors and alarm systems must be integrated into secure communication infrastructures.
- All of these systems must supply data that is verifiable, traceable and audit-proof.
Practical implications for operators
Investments must be future-proof
Operators of critical infrastructure currently face a strategic decision: how do you invest in security technology when the regulatory requirements may still change? The answer lies in choosing systems and manufacturers that already meet the foreseeable requirements today or make them achievable. Certifications, modular architectures and cooperation with experienced suppliers reduce the risk of expensive retrofitting.
Documentation becomes the main task
In the past, the focus was on the technical implementation of security. In future, complete documentation will be equally important – the ability to prove that systems work as planned, that vulnerabilities are known and remediated, and that certifications are up to date. This requires new workflows and often additional staff with IT security expertise.
Outlook: the Perimeter Protection Congress 2026
The first Perimeter Protection Congress, held from 22 to 23 April 2026 in Nuremberg, will be an important meeting point for the security industry. Organised by the Verband für Sicherheitstechnik e.V. in cooperation with Messe Nürnberg, it offers a specialist conference, an exhibition and networking opportunities.
For KRITIS operators the congress is likely to be indispensable: this is where the solutions are presented that will enable them to meet the new requirements. For manufacturers and integrators it is an opportunity to demonstrate their expertise and enter into direct dialogue with operators.
The industry recognises that perimeter protection is no longer exclusively a task for security engineers, but a cross-cutting task uniting IT security, process management, compliance and physical security. On this new foundation, the industry will shape the years ahead.