Grid operators and KRITIS energy plants must prove they are critical infrastructure, which NIS2 category applies, and that their ISMS meets the IT-security catalogue (§ 11 EnWG, ISO 27001 + 27019) — with a conformity attestation every two years. Deriving and evidencing that by hand from the BSI-KritisV, the EnWG and NIS2 takes months.
Load the grid profile
You provide the grid profile — supplied GWh, metering points, control centre/SCADA and RTUs in the field.
Classify and score maturity
The advisor confirms KRITIS and the NIS2 category, maps § 11 EnWG and the ISMS controls (ISO 27001 + 27019) with legal basis, and scores control maturity.
Generate the § 8a conformity dossier
The audit-ready ISMS / § 8a-BSIG conformity dossier is generated as a PDF — with a maturity chart and the open gaps.
Grounded in § 11 Abs. 1a/1b EnWG (the BNetzA IT-Sicherheitskatalog), the BSI-Kritisverordnung with § 8a/§ 8b BSIG, ISO/IEC 27001 + ISO/IEC 27019 and the NIS2 Directive (EU) 2022/2555 (German transposition NIS2UmsuCG). GRC support, not a certification; maturity scores and evidence are supplied by the operator.
See it on your own use case.
30 minutes, scoped to your industry, frameworks and integrations. You leave with a concrete scenario — not a sales loop.