KRITIS implementation rarely fails on the big duties. It fails at the interfaces: where the BSIG on the IT-security side meets the KRITIS-Dachgesetz on the resilience side, and where a shortcut that saved a week in March costs a failed evidence review three years later. The most expensive KRITIS mistakes happen at the interfaces: a missed 31 March threshold check, a forgotten second registration, and a security concept without the personnel-security section that § 30(2) No. 9 BSIG requires.
Two regimes, one implementation project
Since 17 March 2026, registered operators answer to two regimes. The BSIG, recast as the NIS-2 transposition, demands registration under § 33, risk-management measures under § 30, attack detection under § 31, incident reporting under § 32 and evidence under § 39. The KRITIS-Dachgesetz adds registration at the BBK, a risk analysis, a resilience plan and its own audits, with fines of up to one million euros under § 24. Which sectors and thresholds define KRITIS is covered in What is KRITIS? Sectors, thresholds and duties.
The eight mistakes
1. Registering in only one of the two channels
The mistake: treating registration as a single filing with the BSI. The MIP confirmation feels final, yet the BSI side is itself twofold: the critical-plant registration via the Melde- und Informationsportal MIP plus the registration as a besonders wichtige Einrichtung in the BSI-Portal. Once the Identifizierungsverordnung is in force, a further registration at the BBK follows under § 8(1) KRITISDachG, due within three months. The cost: fines under § 24 KRITISDachG reach 200,000 euros for registration violations. Details in KRITIS registration: from self-assessment to BSI audit.
2. Skipping the annual threshold self-assessment
The mistake: treating criticality as a question answered once. The shortcut: the plant has run for years, so the classification feels settled. In law it is not: operators must check annually, by 31 March, whether a plant crossed its BSI-KritisV threshold; criticality then applies retroactively from 1 April of the following year. The cost arrives before the fine does: the facility was a KRITIS operator in fact while nobody treated it as one, so registration, security measures and evidence duties were all missed.
3. Missing the evidence and re-screening cycle
The mistake: filing the § 39 BSIG evidence once and the concept away. The assumption: an audited security concept stays valid. Until December 2025 the evidence rhythm was two years; since the recast BSIG, the first evidence is due at the earliest three years after becoming an operator, then every three years, and the examination must end no more than twelve months before submission. The same applies to people: a hiring check is a snapshot, so re-screening needs defined cycles and triggers such as role changes. The cost: a lapsed cycle is an audit failure before any technical question is asked.
4. Confusing BSIG and DachG duties
The mistake: assuming one registration or one audit covers both regimes. The shortcut: map every duty onto the authority you already know. The BSIG governs IT security, §§ 30 to 39, evidence every three years. The DachG governs physical and organisational resilience: risk analysis within nine months of registration, resilience plan and incident duties within ten months, audits by the zuständige Behörde under § 16, which can request parts of the § 39 evidence via the BBK. The cost: whichever catalogue was mapped onto the wrong regime stays unaddressed, and it surfaces in exactly the audit nobody prepared for. The duty cascade is summarised in KRITIS-Dachgesetz 2026: obligations, deadlines and sectors.
5. Treating personnel security as a footnote
The mistake: reducing personnel security to a password policy and an NDA. It happens because the statutory wording sounds abstract while technical controls feel concrete. The statutes are explicit: § 30(2) No. 9 BSIG requires concepts for the security of personnel and access control, § 13(3) No. 5 KRITISDachG requires security management for staff including external service-provider personnel, and the Commission guidelines on Art. 13(5) CER call for a reliability-check system: identity verification, criminal-record check, employment history. The cost: personnel security sits inside the § 39 evidence, where weak records are an audit failure. Employee background verification is the auditable fulfilment of both anchors; the implementation guide for background checks shows the operational structure.
6. Running a weak incident-reporting chain
The mistake: leaving incident reporting to whoever is on shift, with no rehearsed path to the reporting contact. The shortcut: assume the channel can be figured out under pressure. Under § 32 BSIG the deadlines are fixed: initial notification within 24 hours, a detailed notification within 72 hours, a final report within one month, filed via MIP. Once the DachG regime is running, § 18 adds a separate 24-hour report to the joint Meldestelle of BSI and BBK. The cost: an unrehearsed chain misses the first deadline, and BSIG fines follow the NIS-2 turnover-linked scheme.
7. Leaving supply-chain duties undocumented
The mistake: relying on provider certificates and contract clauses while keeping no documentation of your own. It happens because outsourcing feels like transferring the duty with the task. The statutes say otherwise: § 30(2) BSIG names supply-chain security as a mandatory measure category, the scope documentation must depict third-party-operated parts of the critical service, and § 13(3) No. 5 KRITISDachG pulls external service-provider personnel into the same security grid as your staff.
8. Leaving management accountability implicit
The mistake: delegating KRITIS implementation to the security officer without a documented management decision. The shortcut: leadership assumes that delegation covers the duty. § 38 BSIG says otherwise: senior management must approve the risk-management measures, oversee their implementation and ensure training, as a personal duty that cannot be fully delegated. The cost appears late: when an incident comes from inside and a check never took place, the question is what management approved and documented. An approval that exists only as a conversation is hard to reconstruct.
Which mistakes do auditors flag first?
Documentation failures surface before technical ones. A scope description that does not fully depict the critical service fails the GAiN criteria before any control is tested. Attack detection is mandatory under § 31 BSIG and must be visible in the Netzstrukturplan. A Prüfende Stelle with questionable independence fails at the threshold, certificates count as components only, and the previous defect list must be carried into the follow-up audit.
Where personnel verification fits in
The statutes treat people as a risk vector because most damaging incidents at critical facilities involve someone who was authorised to be there. Operationally, that means verification before access is granted, documented per trigger: hiring, role changes, and repeat cycles for key roles. A reviewable check covers identity and employment history, sanctions and watch lists, adverse media with dated sources, and economic entanglements, with human final review. Indicium delivers such reports as structured, reviewable verification of key personnel.
What to fix first
Work the list in order of reversibility. Confirm registration status in both channels and calendar the BBK registration for the day the Identifizierungsverordnung enters into force. Verify your last § 39 examination against the twelve-month rule. Rehearse the § 32 reporting chain end to end. Then put the personnel-security work package in front of senior management for documented approval under § 38 BSIG.
Frequently asked questions
Which KRITIS mistakes do auditors flag most often?
Documentation failures lead: incomplete scope descriptions, attack detection missing from the Netzstrukturplan, defect lists not carried forward, personnel-security concepts without records. Technical gaps surface later; file gaps surface first.
How high are the fines for KRITIS operators?
Under § 24 KRITISDachG: up to 200,000 euros for registration and information-duty violations, up to 500,000 euros for violations around submitting audit results, one million euros for defying enforceable orders. Under the BSIG, fines follow the NIS-2 turnover-linked scheme under § 65 BSIG.
Does a company automatically become a KRITIS operator?
No. Criticality attaches to a plant, not to the company, and only when the BSI-KritisV threshold is crossed. That is why the annual check by 31 March matters.
Is senior management liable for KRITIS violations?
§ 38 BSIG makes approving and overseeing the risk-management measures a personal duty of senior management that cannot be fully delegated. Undocumented approval is treated as absent approval.
This article provides general information and does not constitute legal advice.