NIS2 has applied since December 2025 without a transition period, the KRITIS umbrella act since March 2026, and the IT security catalogue under §5c EnWG requires attack detection right into the control system. That makes cybersecurity a documented duty of the management board rather than a pure IT task. The rulebooks overlap in many places. Implement them separately and you do the same work three times.
NIS2 has applied since December 2025 without a transition period, the KRITIS umbrella act since March 2026, and the IT security catalogue under §5c EnWG requires attack detection in control systems. We translate the obligations into architecture and programme requirements: who registers, who reports, which systems are affected and in which order the grid becomes secure.
innobu works at programme level in this field: requirements, architecture and steering, not hands-on delivery.
Services for this field
Tools and frameworks
Articles in this field (11)
Counter-drone defense at energy facilities: what Germany's KRITIS umbrella law now requires
Since March 2026 the KRITIS umbrella law requires physical protection of energy facilities. What is legal against drones, and how detection works.
Read →Attack Detection in OT Networks: Audit and Proof
Energy operators must run an attack detection system in the OT network and prove it to the BSI every two years. What the maturity audit requires.
Read →Ransomware Resilience for Municipal Utilities: Reporting and Evidence Duties under NIS2
Since 6 December 2025 NIS2 binds municipal utilities too: a reporting cascade of 24 hours, 72 hours and one month after ransomware, plus an evidence duty.
Read →Post-quantum cryptography for critical energy infrastructure
The BSI is ending classical encryption. Migration to post-quantum cryptography for critical energy infrastructure by 2030, 2031 and 2035.
Read →DynoWiper and Sandworm: Wiper Malware Against Energy Plants
In late 2025 the Sandworm group hit Poland's power supply with the DynoWiper malware, threatening 500,000 customers. What the failed attack means for Europe.
Read →Chinese PV Inverters as a Security Risk
About 80% of Europe's inverters are Chinese. What the EU high-risk vendor list, the 2026 funding ban and the BSI warning mean for grid operators.
Read →OT Security for Energy Plants: IEC 62443 and the CRA
From 11 September 2026 the first CRA duties hit energy plants. How IEC 62443, with security levels and zones, turns OT security into a mandatory framework.
Read →NCCS: Cybersecurity Code for TSOs and DSOs
The network code on cybersecurity (EU) 2024/1366 obliges grid operators to CSMS, audits and reporting. The deadlines to 2028 and what to do in 2026.
Read →IT Security Catalogue under §5c EnWG 2026
Germany's IT security catalogue under §5c EnWG replaces the §11 catalogues. What grid and facility operators need to know in 2026: ISMS, ISO 27001, reporting.
Read →NIS2 & KRITIS Umbrella Law 2026: Deadlines & Liability
Two German cyber laws in force in 2026: NIS2 (BSI, fines to 10M euros, management liability) and the KRITIS Umbrella Act (BBK, register from 17 July).
Read →Project Glasswing: ENISA and NATO Join AI Security Program
ENISA joins Project Glasswing: first EU institution with Claude Mythos access. 23,000 vulnerabilities in critical infrastructure. NIS2 implications.
Read →