For energy providers, KRITIS is no longer a peripheral strategic issue that is merely mentioned in the annual report. As soon as an application is classified as KRITIS-relevant, the operational reality changes. Audits are scheduled, evidence must be robust, and decisions must be documented and justified.
An audit verifies whether responsibilities are clearly defined, processes are documented, and contracts comply with regulatory requirements. This is precisely where the true resilience of established structures becomes apparent.
This raises a very concrete question: How can regulatory requirements be implemented when existing contracts, service providers, and processes were never originally designed for this framework?
Regulation requires clear decisions
In one of our projects with an energy provider, an existing application was classified by the regulator as KRITIS-relevant. With this classification, it was clear that a corresponding audit would take place within six months. This deadline was non-negotiable.
This meant that a body of contracts that had grown over decades had to be adapted within six months to withstand a KRITIS audit. At the same time, processes had to be defined, responsibilities clearly assigned, and the necessary documentation created.
This was not just a matter of legal requirements. In addition, internal corporate guidelines on contract and process design had to be taken into account, and at the same time, there was a clear directive that the necessary adjustments should not lead to higher operating costs.
Six months under these conditions mean: There is no time for parallel structures or unclear responsibilities—decisions must be made quickly and with finality.
When established structures come under pressure
Contracts that have evolved over the years typically reflect genuine collaboration. They include amendments, addenda, and customized provisions that have proven effective in day-to-day operations. Under audit conditions, however, it becomes crucial to determine whether this structure is logically consistent, fully documented, and compliant with regulatory requirements.
The project therefore began by systematically examining which components of the existing contractual framework are actually relevant for the KRITIS classification. Instead of rewriting the entire contractual framework from scratch, the key content was transferred into proven contract templates, structurally streamlined, and brought into a verifiable form.
In parallel, processes were implemented that are based on ITIL and cover both legal and internal corporate requirements. The primary focus was always on determining which solution is sufficient from a regulatory standpoint without creating additional complexity. The goal was not to reinvent the wheel, but to create a consolidated structure that meets regulatory requirements while remaining operationally viable.
Management remains the responsibility of the company
Even when external service providers perform operational services, the responsibility for regulatory compliance remains with the company itself. This responsibility cannot be delegated. The audit examines whether the company has fulfilled its management function.
In this case, switching to a different service provider made no sense from either an economic or organizational standpoint. The solution, therefore, lay not in replacing the provider but in more clearly managing the existing partnership.
In practical terms, this meant clearly defining decision-making processes and documenting responsibilities in a binding manner. It was clearly established who grants approvals, who prioritizes adjustments, and what documentation must be maintained. These regulations were not only described but also integrated into daily collaboration.
At the time of the audit, not only were revised contract documents in place, but also implemented processes that were already being applied in day-to-day operations. At the same time, collaboration with the software vendor improved, as roles, expectations, and procedures were transparently defined, preventing misunderstandings from arising in the first place.
Prioritization over knee-jerk reactions
Regulatory pressure often leads to additional documentation, new approval cycles, and expanded oversight bodies. In the short term, this creates the impression of security; in the long term, decision-making processes become longer and coordination more cumbersome.
The project took a different approach. First, the mandatory regulatory requirements were identified. Next, the team examined how these could be integrated into existing processes with as little structural disruption as possible.
This resulted in contract documents and processes that remained audit-ready while also being viable for day-to-day operations. The structures developed have since been consolidated to the point where they can serve as a template for other service providers, even outside the immediate KRITIS context.
What companies can take away from this
Under audit conditions, regulatory requirements clearly reveal whether responsibilities are clearly defined and decisions have been documented in a transparent manner.
Anyone seeking to become audit-ready should therefore start with their own governance framework.
This includes:
- consolidated and transparent contractual foundations
- clearly defined responsibilities
- implemented and documented processes
- a pragmatic implementation of regulatory requirements
- Prioritization with regard to effort and impact
Regulation very quickly reveals when responsibilities are not clearly defined. Those who take responsibility and consistently organize structures lay the groundwork for audits to be experienced as confirmation of effective governance.
We support energy suppliers precisely in such situations, when regulatory pressure meets established structures and robust results are required within a clearly defined timeframe.
In our white paper on IT architecture, we demonstrate how transparent processes, clearly documented decision-making procedures, and consolidated contract structures help ensure reliable management of service providers in the KRITIS environment and enable the predictable implementation of regulatory requirements.
Image source: Stock-Foto „Worried Businesswoman Looking At Folders Stack“ | Adobe Stock
Our motto: Establish IT in everyday business as a solution, not as a source of problems.

