Skip to main content
Use case

Energy-industry GRC: KRITIS, NIS2 & the § 11 EnWG IT-security catalogue — classified in seconds

The Energy GRC Advisor classifies a grid profile (supplied GWh, metering points, a control centre/SCADA with RTUs) in seconds: KRITIS under the BSI-Kritisverordnung, the NIS2 category (essential entity, Annex I energy) and the § 11 Abs. 1a EnWG duty. It maps the ISMS controls to ISO/IEC 27001 + ISO/IEC 27019, scores control maturity, names the gaps and generates the audit-ready ISMS / § 8a-BSIG conformity dossier as a PDF. Every verdict carries its legal basis, with open values marked 'TO COMPLETE'.

KRITIS · NIS2
classified with the exact statute — BSI-KritisV, Annex I energy
§ 11 EnWG
IT-Sicherheitskatalog → ISMS ISO/IEC 27001 + ISO/IEC 27019
§ 8a
audit-ready conformity dossier as a PDF — biennial evidence
Rendered illustrationSimulated scenario
Demo in German, English and Spanish
The starting point

Grid operators and KRITIS energy plants must prove they are critical infrastructure, which NIS2 category applies, and that their ISMS meets the IT-security catalogue (§ 11 EnWG, ISO 27001 + 27019) — with a conformity attestation every two years. Deriving and evidencing that by hand from the BSI-KritisV, the EnWG and NIS2 takes months.

How it works
1

Load the grid profile

You provide the grid profile — supplied GWh, metering points, control centre/SCADA and RTUs in the field.

2

Classify and score maturity

The advisor confirms KRITIS and the NIS2 category, maps § 11 EnWG and the ISMS controls (ISO 27001 + 27019) with legal basis, and scores control maturity.

3

Generate the § 8a conformity dossier

The audit-ready ISMS / § 8a-BSIG conformity dossier is generated as a PDF — with a maturity chart and the open gaps.

The outcome
KRITIS · NIS2
classified with the exact statute — BSI-KritisV, Annex I energy
§ 11 EnWG
IT-Sicherheitskatalog → ISMS ISO/IEC 27001 + ISO/IEC 27019
§ 8a
audit-ready conformity dossier as a PDF — biennial evidence
Grounded in

Grounded in § 11 Abs. 1a/1b EnWG (the BNetzA IT-Sicherheitskatalog), the BSI-Kritisverordnung with § 8a/§ 8b BSIG, ISO/IEC 27001 + ISO/IEC 27019 and the NIS2 Directive (EU) 2022/2555 (German transposition NIS2UmsuCG). GRC support, not a certification; maturity scores and evidence are supplied by the operator.

Book a demo

See it on your own use case.

30 minutes, scoped to your industry, frameworks and integrations. You leave with a concrete scenario — not a sales loop.