Germany NIS2 energy sector compliance: KRITIS thresholds and BSI BNetzA oversight

104 MW, Not 420: Germany’s Real NIS2 KRITIS Threshold for Energy — and the BSI/BNetzA Overlap Most Guides Miss

Search for Germany’s KRITIS electricity-generation threshold and a meaningful share of results — including some paid compliance guides — still say 420 MW. That figure was retired in March 2023 and replaced with a lower 104 MW line that pulls more mid-sized generation assets, battery storage systems, and municipal utilities into critical-infrastructure scope than most checklists still assume. Energy is also the one NIS2 Annex I sector in Germany regulated twice over: alongside BSI’s NIS2/BSIG framework, grid operators answer separately to Bundesnetzagentur (BNetzA) under the Energiewirtschaftsgesetz (EnWG), and cross-border-relevant assets face a third layer under the EU’s Network Code on Cybersecurity.

This guide sets out the classification test that actually applies today, corrects the outdated threshold still circulating, explains the KRITIS-specific attack-detection duty, and maps where BSI and BNetzA obligations overlap and where they run on entirely separate tracks.

Who This Applies To: Germany’s Three-Tier Energy Classification

In plain terms: if your organisation generates, transmits, distributes, or trades electricity — or supplies gas, oil, hydrogen, or district heat — you are almost certainly in NIS2 scope in Germany. The open question is which of three tiers you fall into, because that determines whether BSI can examine your controls at will or only after something goes wrong.

Category Energy Subsector Example Qualifying Threshold BSI Supervision
KRITIS (Betreiber kritischer Anlagen) Electricity generation, CHP, storage ≥104 MW installed net rated power [1] Ex ante + mandatory §39 evidence every 3 years
KRITIS Transmission / distribution network ≥3,700 GWh/year throughput [1] Same as above
KRITIS Gas network ≥5,190 GWh/year [3] Same as above
KRITIS Oil / heating oil ≥420,000 t/year (4.4M t crude) [3] Same as above
KRITIS District heating ≥2,300 GWh/year [3] Same as above
Particularly important entity (non-KRITIS) Any Annex I energy entity below KRITIS thresholds ≥250 employees OR turnover >€50M and balance sheet >€43M Ex ante, Article 32 [7]
Important entity Any Annex I energy entity ≥50 employees OR turnover/balance sheet >€10M Ex post, Article 33 [8]

Germany’s four transmission system operators — 50Hertz, Amprion, TenneT Germany, and TransnetBW — each clear the 3,700 GWh/year network threshold by a wide margin, so TSO status in Germany functions as automatic KRITIS status, not a borderline calculation. Distribution system operators are the tier where the arithmetic actually matters: a regional Stadtwerke grid operator can sit just above or below the line depending on annual throughput, and that line determines whether §31 BSIG’s attack-detection duty applies at all.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Annex I of the NIS2 Directive names transmission system operators, distribution system operators, electricity supply undertakings, and aggregation/demand-response/storage operators for electricity; transmission, distribution, storage, and LNG system operators for gas; transmission and stockholding operators for oil; and production, storage, and transmission operators for hydrogen — a subsector new to NIS2 and absent from the prior NIS1 framework [9]. For the complete entity list across every Annex I and Annex II sector, see who must comply with NIS2.

The 104 MW Threshold: Why Most Guides Still Cite the Wrong Number

From 2017 until the Dritte Verordnung zur Änderung der BSI-Kritisverordnung took effect on 1 March 2023, 420 MW of installed capacity was the line for classifying a generation, CHP, or storage facility as KRITIS [2]. That amendment lowered the standard generation threshold to 104 MW, with two further variants: 0 MW for grid-frequency-stabilising facilities — meaning virtually any size can qualify — and 36 MW for primary control reserve providers [1][2].

The practical effect is a scope expansion that predates NIS2 itself but compounds with it. A mid-sized combined-heat-and-power plant or a utility-scale battery storage system that would have sat comfortably below 420 MW, and therefore outside KRITIS, can now clear 104 MW and land inside it. Facilities that self-assessed as out of scope before 2023 need to re-run the calculation against the current figure, not the one still printed in older consultant decks and blog posts. The same 2023 amendment removed decentralised generation and storage facilities as a standalone KRITIS category and added LNG-Anlage to the gas sector’s threshold list [2] — details that rarely make it into a general NIS2 overview, and that a threshold recalculation should account for alongside the headline MW figure.

Mandatory Attack Detection: What §31 BSIG Requires

KRITIS status carries an obligation that particularly important and important entities outside KRITIS do not share: deploying Systeme zur Angriffserkennung (SzA) — attack detection systems — under §31 BSIG. The provision is written narrowly to operators of critical facilities specifically, not to the broader NIS2-regulated population [4].

In plain terms: if your facility clears the 104 MW, 3,700 GWh, or sector-equivalent threshold, you need continuous monitoring of your operational environment, not a periodic scan. §31 requires the system to continuously and automatically capture and evaluate parameters and characteristics from ongoing IT operations, identify threats on an ongoing basis, and support remedial action once an incident is detected — held to a state-of-the-art standard [4]. The underlying obligation traces back to the original attack-detection requirement that took effect for existing KRITIS operators in 2023 and now continues, restructured, under the post-NIS2UmsuCG BSIG [4].

Evidence of §31 measures, alongside the broader §30 risk-management measures, feeds into the same three-year §39 BSIG audit cycle covered in our Germany competent authority guide, with first submissions under the revised framework due around 2028. §31’s proportionality clause matters for smaller KRITIS operators specifically: cost must not be disproportionate to the consequences of a facility outage or compromise, so a 104 MW-threshold municipal generator is not held to the same monitoring budget as a multi-gigawatt transmission operator [4].

The BSI/BNetzA Overlap: EnWG §11 and the Network Code on Cybersecurity

Energy is the only NIS2 Annex I sector in Germany with two cyber-specific regulators issuing binding technical requirements on the same operators. BSI enforces NIS2/BSIG. Bundesnetzagentur separately issues IT-Sicherheitskataloge (IT security catalogues) under §11 EnWG, currently in two versions covering different obligations — §11 Abs.1a from August 2015 and §11 Abs.1b from December 2018 — with updated versions expected to align to NIS2 [3]. Neither authority’s requirements substitute for the other’s.

For a compliance officer, this means an energy operator’s NIS2 gap analysis and its EnWG §11 IT-Sicherheitskatalog certification cover overlapping but not identical ground. The two need separate evidence trails, not one folded into the other.

A third layer applies specifically to electricity. The Network Code on Cybersecurity — Commission Delegated Regulation (EU) 2024/1366, in force since 13 June 2024 — governs cybersecurity for cross-border electricity flows and supplements Regulation (EU) 2019/943 [5]. It applies to transmission and distribution system operators and to “significant” generation assets classified as high-impact or critical-impact under the EU’s Electricity Cybersecurity Impact Index. Germany’s provisional thresholds sit at 1,500 MW for high-impact classification and 3,000 MW for critical-impact [5] — figures with no equivalent in the BSI-KritisV table and well above the 104 MW KRITIS line, so a facility can be KRITIS under BSIG without being NCCS-classified, or the reverse, depending on cross-border relevance. Once BNetzA classifies an entity under NCCS, that entity has twelve months to submit a cybersecurity risk report — covering selected controls, implementation status, and residual-risk estimates against the EU risk-impact matrix — updated every three years thereafter [5].

For a board or compliance function building a single evidence calendar, this produces three parallel clocks rather than one: BSI’s three-year §39 BSIG KRITIS evidence cycle, BNetzA’s EnWG §11 catalogue certification, and — where applicable — the NCCS twelve-month/three-year reporting rhythm to BNetzA. Meeting one does not excuse the others; each authority enforces its own instrument independently.

Registration, Audits, and Penalties

Registration follows the same BSI portal process — via Mein Unternehmenskonto and your organisation’s ELSTER certificate — that applies to every German NIS2 entity, covered in full in our Germany competent authority guide. Energy-sector KRITIS operators carry the same dual BSI/BBK registration duty as every other KRITIS sector, plus critical-component disclosure for grid control systems and their version numbers.

A practical checklist for energy compliance officers:

  • Confirm your threshold class against the current 104 MW / 3,700 GWh / sector-equivalent figures, not an older published number — effort: Low
  • Register with BSI (all tiers) — effort: Medium
  • KRITIS operators: register with BBK separately and deploy §31 BSIG attack detection — effort: High
  • Confirm EnWG §11 IT-Sicherheitskatalog certification status with your existing BNetzA contact — effort: Medium
  • TSOs, DSOs, and significant generation assets: confirm NCCS classification status with BNetzA and prepare the 12-month risk report if classified — effort: High

Penalty exposure follows the standard BSIG structure: particularly important entities, including all KRITIS operators, face up to €10 million or 2% of global turnover, whichever is higher; important entities face up to €7 million or 1.4% [6]. KRITIS-specific violations — critical-component reporting failures and audit-evidence procedure failures — carry their own separate ceilings, and registration or notification failures are capped lower. See our Germany NIS2 penalties guide for the full violation-by-violation table. NCCS and EnWG §11 non-compliance sit on separate enforcement tracks under BNetzA’s own regulatory powers, independent of BSIG fines.

Key Takeaways

  • Germany’s KRITIS electricity-generation threshold is 104 MW, not the 420 MW figure still widely cited — lowered by regulation effective 1 March 2023.
  • Network throughput thresholds (3,700 GWh/year for electricity transmission/distribution, 5,190 GWh/year for gas, 2,300 GWh/year for district heating) determine KRITIS status for grid and network operators; Germany’s four TSOs clear these automatically.
  • Only KRITIS energy operators must deploy §31 BSIG attack detection systems — particularly important and important entities outside KRITIS do not share this specific duty.
  • Energy operators face three independent compliance tracks: BSI/BSIG (NIS2), BNetzA/EnWG §11 (IT security catalogues), and — for TSOs, DSOs, and significant generation assets — the Network Code on Cybersecurity, each with its own evidence cycle.
  • NCCS classification (1,500 MW high-impact / 3,000 MW critical-impact, provisional German thresholds) is independent of KRITIS classification — an entity can meet one without the other.

Frequently Asked Questions

Is Germany’s KRITIS energy threshold really 104 MW, not 420 MW?

Yes, for standard electricity generation, CHP, and storage facilities. 420 MW applied from 2017 until a March 2023 amendment to the BSI-Kritisverordnung lowered it to 104 MW, alongside a 0 MW threshold for grid-frequency-stabilising facilities and 36 MW for primary control reserve providers [1][2]. Any assessment still using 420 MW is working from a superseded figure.

Does every energy company need attack detection systems (SzA)?

No. §31 BSIG’s attack-detection obligation applies specifically to operators of critical facilities — the KRITIS tier. Particularly important and important entities in the energy sector that do not meet a KRITIS threshold are not subject to this specific provision, though they remain subject to the general NIS2/BSIG risk-management measures [4].

Do NIS2/BSIG obligations replace BNetzA’s EnWG §11 requirements?

No. BSI’s NIS2/BSIG framework and BNetzA’s EnWG §11 IT-Sicherheitskatalog are separate legal instruments enforced by separate authorities. Compliance with one does not automatically satisfy the other, and both need independent evidence trails [3].

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. Anhang 1 BSI-KritisV — Anlagenkategorien und Schwellenwerte im Sektor Energie — gesetze-im-internet.de
  2. Neue KRITIS-Anlagen und Schwellenwerte im IT-SiG 2.0 — OpenKRITIS
  3. Sektor Energie in NIS2 und KRITIS — OpenKRITIS
  4. § 31 BSIG — Einsatz von Systemen zur Angriffserkennung — gesetze-im-internet.de
  5. EU Network Code on Cybersecurity (NCCS) — OpenKRITIS
  6. NIS 2 Directive, Article 34 — General conditions for imposing administrative fines — nis-2-directive.com
  7. NIS 2 Directive, Article 32 — Supervisory measures for essential entities — nis-2-directive.com
  8. NIS 2 Directive, Article 33 — Supervisory measures for important entities — nis-2-directive.com
  9. Directive (EU) 2022/2555, Annex I — Sectors of high criticality (Energy) — EUR-Lex; see also NIS2 scope: who must comply
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: