Security starts at access

NIS-2, CRITIS and Cyber Resilience Act

Get advice now!

Due to regulatory pressure, controllable security

NIS-2, KRITIS, and the Cyber Resilience Act significantly increase the requirements for security and risk management. Not only technical protective measures are required, but a holistic approach that includes processes, responsibilities, and physical security.

We support companies in effectively connecting physical and digital security – for compliance, protection, and future viability. Access control, traceability, and secure processes become an integral part of your security strategy.

✓ Access control as part of your security architecture
✓ Traceable permissions and secure processes
✓ Future-proof and flexible foundation for regulatory requirements
Get a non-binding consultation now!

What do NIS-2, KRITIS, and CRA mean?

To protect critical infrastructures and security-relevant facilities, various regulatory requirements apply in Germany that interlink and complement each other. While the existing KRITIS regulations affect several thousand operators of critical infrastructures, NIS-2 significantly expands the circle of affected companies and organizations.

A key component of the requirements is the secure management and traceability of physical access to sensitive areas and critical facilities. Companies that do not adequately implement regulatory requirements risk substantial fines as well as personal liability risks.

NIS-2

 

New EU directive for more cybersecurity in companies and organizations. Focus on risk management, reporting obligations, and security measures.

KRITIS

 

Requirements for operators of critical infrastructures such as energy, industry, or healthcare to protect sensitive processes and facilities.

CRA

 

The Cyber Resilience Act requires manufacturers and distributors to provide secure connected products throughout their entire lifecycle.

Who is affected by the regulations?

NIS-2

 

NIS-2 applies to companies and organizations of particular importance for the economy, supply, and infrastructure. Relevant are particularly medium and large companies in critical or particularly important sectors.

Important entities: at least 50 employees OR annual revenue over 10 million EUR.

Especially important entities: at least 250 employees AND annual revenue over 50 million EUR AND balance sheet total over 43 million EUR.
Typical affected industries
Energy
Digital Infrastructure & IT
Industry & Production
Public Administration
Healthcare
Transport & Logistics
Food & Trade
Water & Environment
Finance and Insurance

KRITIS

 

KRITIS applies to operators of critical infrastructures, whose failure would have significant impacts on supply security, the economy, or public life. Defined thresholds and the criticality of the services are crucial.

Companies are considered KRITIS-relevant if certain thresholds are exceeded – sector-specific, e.g., supply of over 500,000 people in the energy supply sector.
Typical KRITIS sectors
Energy Supply
Water Supply
Healthcare
Transport & Traffic
Nutrition
State & Administration
Information and Communication Technology
Finance and Insurance

CRA

 

The Cyber Resilience Act concerns manufacturers, importers, and dealers of products with digital elements. The aim is to make connected products safer throughout their entire lifecycle – from development to deployment to updates and vulnerability management.

Relevant for products with digital elements: This includes hardware, software, and connected systems that can be directly or indirectly connected to a network or another device.

Manufacturers must meet security requirements, actively address vulnerabilities, and provide security updates.

This also affects us as manufacturers of digital access control systems, electronic locking technology, and connected security solutions.

If the requirements of the Cyber Resilience Act are not met, products can be withdrawn from the market or not placed on the market. This creates risks for companies along the supply chain – for example, if important products, systems, or suppliers are suddenly unavailable.
Typical affected product areas
Connected products
IoT devices
Software & Apps
Cloud and platform solutions
Digital locking systems
Update and patch management

What changes for you?

More
Responsibility

 

Companies and operators must actively assess risks and implement appropriate measures.

More Documentation Obligations

 

Security measures, processes, and decisions must be documented and verifiable.

Holistic Security Architecture

 

Physical, digital, and organizational measures interconnect and form an effective security chain.

Risks & Consequences

 

Violations can lead to fines, liability of management, and business interruptions.

 

Do you want to know what impact the new requirements will have on your organization?


Get advice now!

 

Practical examples

The often overlooked area: Physical security

Many security concepts focus on IT systems. However, effective security begins with controlled access to buildings, sensitive areas, and critical infrastructure.

  • Who has access when and where?
  • How are permissions granted and revoked?
  • Are accesses documented in a traceable manner?
  • Can security incidents be quickly contained?

Digital access organization creates transparency, control, and traceability and thus becomes a central component of modern compliance strategies.

Our solution: next-generation security technology

Intelligent access solutions for modern security requirements.
Our solutions support companies and professional partners in organizing access efficiently, transparently, and future-proof.

 

Digital access control

Secure, flexible, and scalable solutions for every requirement.

Real-time access management

Manage, change, and revoke permissions centrally.

Seamless logging

All accesses are recorded and documented in a tamper-proof manner.

Integration & interfaces

Seamless integration into existing security and IT systems.

Future-proof & compliant

Prepared for current and future requirements.

Product safety as manufacturer responsibility

The Cyber Resilience Act increases the requirements for manufacturers of connected products. Security thus becomes a responsibility throughout the entire product lifecycle – from development to operation to updates and the long-term maintenance of systems.

As a manufacturer of digital access solutions, DOM develops systems that connect physical and digital security and support companies in meeting current and future security requirements.

For DOM, this means:

  • Security-by-Design in product development
  • Continuous security updates
  • Active vulnerability management
  • Long-term product maintenance
  • Documented security processes
  • Support for regulatory requirements

Access control systems

We connect physical and digital security – modular, scalable, and tailored to your requirements.

Planning and implementation with experienced security experts

As a manufacturer of modern access control systems, we support your company together with qualified specialist partners in the planning and implementation of your individual security solutions.

We offer you:
  • Manufacturer expertise directly from the system developer
  • Support with regulatory requirements
  • Collaboration with certified specialist partners
  • Individual project and security consulting
Assess security requirements together
Every organization has individual requirements for security, compliance, and access organization.
Together with our specialist partners, we support companies in selecting suitable solutions.

Important Dates

The regulatory requirements surrounding NIS-2, KRITIS, and CRA are gradually evolving. The timeline provides an overview of the most important deadlines, registrations, and legal milestones.

06December2025

NIS-2 Implementation Act comes into force

The new cybersecurity requirements for affected companies become mandatory.

06January2026

Event-related inspections possible

The BSI can initiate evidence and inspections in case of security incidents or specific reasons.

06January2026

Start of NIS-2 registration

Affected institutions must register with the BSI.

29January2026

Adoption of the KRITIS Framework Act

The law strengthens the resilience of critical institutions and complements existing IT security requirements.

06March2026

End of the NIS-2 registration period

Registration with the BSI must occur no later than three months after being affected.

17July2026

Start of KRITIS registration

Operators of critical institutions must register according to the KRITIS Framework Act.

11September2026

CRA reporting obligations apply

Manufacturers of digital products must report actively exploited vulnerabilities and serious security incidents.

11December2027

CRA fully applicable

All requirements of the Cyber Resilience Act apply mandatorily to products with digital elements.

From
2028

Regular inspections possible

Authorities can check evidence, security measures, and processes in ongoing operations.

DOM Switzerland AG

DOM Schweiz AG

Address

Breitenstrasse 11
8852 Altendorf
Switzerland

How do I get here?