Product Understanding

KRITIS Compliance for Energy Infrastructure: What Operators Need to Know

Key Takeaways

KRITIS is the German regulatory framework for critical infrastructure, and the energy sector is one of its core sectors
Aggregators – platforms that pool and dispatch multiple assets to provide system services – are a defined KRITIS category (“Digitaler Energiedienst”), with the same thresholds as power plants
For aggregators that enable primary control reserve (Primärregelleistung / FCR), the threshold is 36 MW of aggregated capacity
EBX operates above this threshold: KRITIS-grade security is therefore a structural property of the platform, not an optional feature

What Is KRITIS?

KRITIS (Kritische Infrastrukturen) is the German regulatory framework for protecting critical infrastructure - systems and facilities whose failure would have significant consequences for public safety, supply, or order. The energy sector is one of the core KRITIS sectors. KRITIS compliance is overseen by the Bundesamt für Sicherheit in der Informationstechnik (BSI). For the energy sector, the Bundesnetzagentur sets the specific IT security requirements together with the BSI.

For energy infrastructure operators, KRITIS compliance means meeting elevated standards for IT security, operational resilience, and incident reporting.

The 36 MW Threshold

KRITIS defines three thresholds for both generation plants and aggregators of electrical capacity:

  • 104 MW of net rated capacity (the standard threshold, corresponding to the capacity required to supply approximately 500,000 people)

  • 0 MW for plants with black start capability (any size)

  • 36 MW for plants or systems providing primary control reserve (Primärregelleistung / FCR)

The 36 MW threshold sits significantly below the standard 104 MW because primary frequency response is the fastest and most time-critical layer of grid balancing. A failure in this layer has system-wide consequences within seconds.

What Compliance actually requires

Operators of critical energy infrastructure must protect the availability, integrity, authenticity, and confidentiality of their IT systems. In practice this means: an information security management system (ISMS) certified to ISO/IEC 27001, systems for detecting attacks, regular audits, and reporting significant security incidents to the BSI.

The Layered Framework: KRITIS, NIS2 and the Sector Laws

KRITIS does not exist in isolation. Since December 2025, Germany’s NIS2 implementation act has extended cybersecurity obligations to a much broader set of companies – including many energy companies that fall below the KRITIS thresholds. KRITIS operators sit at the top of this framework: they carry the strictest obligations and are automatically classified as “particularly important entities” under NIS2. In parallel, the "KRITIS-Dachgesetz" adds requirements for physical resilience. Together, these rules form a layered compliance framework that energy infrastructure operators must navigate.

What This Means for Asset Owners and Optimizers

Battery energy storage systems that participate in balancing markets are increasingly subject to KRITIS-adjacent requirements - particularly when aggregated into pools or operating at scale. The infrastructure that connects these assets to TSOs and markets must be designed with compliance in mind from day one.

For asset owners and optimizers, working with an infrastructure provider that absorbs KRITIS, NIS2, and BSI compliance means one less regulatory burden to manage - and one fewer risk to the operational integrity of their assets.


Sources: BSI-KritisV, BSI-Kritische Infrastrukturen, Bundesnetzagentur

© 2026 EBX Technologies GmbH. All rights reserved.

© 2026 EBX Technologies GmbH. All rights reserved.

© 2026 EBX Technologies GmbH. All rights reserved.

© 2026 EBX Technologies GmbH. All rights reserved.