Physical Security 2026: Securing KRITIS & NIS-2 Sites
Physical security for KRITIS and NIS-2: protection goals, measures, state of the art and proof. What operators must implement at their sites in 2026 — and how to document it.
Physical security: the definition that counts in an audit
Physical security covers all structural, technical and organisational measures that protect people, assets and information against unauthorised access, sabotage, theft and outage. In the KRITIS and NIS-2 context it is not optional — it is a legal duty, and it must be provable.
The three classic protection goals: detection (spotting), delay (holding up), response (intervening). Every physical measure maps to one of these. An audit checks that all three are covered without gaps and documented.
The four layers of physical security
| Layer | Function | Typical measures |
|---|---|---|
| Perimeter | secure the outer boundary | fence, monitoring, patrol, sensors |
| Grounds | open area between boundary and building | lighting, motion detection, camera |
| Building envelope | control access | access control, locking, alarm |
| Interior / core zone | protect critical assets | zoning, video, sabotage protection |
The perimeter is the first and most economical line of defence: detect early there and you win the time that makes any response effective at all.
What KRITIS and NIS-2 actually require
The legal frame is split, and the mapping decides how cleanly you can justify a measure:
| Frame | physical focus |
|---|---|
| KRITIS-Dachgesetz / CER | explicit mandate: object protection, surveillance, access control |
| NIS-2 (Art. 21) | physical protection of IT/OT assets, continuous monitoring |
| § 7 KRITIS-DG "state of the art" | proven, documented technology |
For pure physical site protection, the KRITIS-Dachgesetz is the clearer legal ground — it names object protection and surveillance expressly. NIS-2 adds the duty to continuously monitor critical assets. Details: KRITIS requirements, NIS-2.
"State of the art" in physical security
§ 7 KRITIS-DG requires measures at the upper edge of the proven — plus documented proof of how that level is reached. For perimeter and grounds monitoring in 2026 that means continuous, sensor-based detection instead of occasional rounds, with gapless, audit-ready documentation.
This is exactly where the technology has shifted. Autonomous patrol robotics combines mobile sensing (RGB, thermal, LiDAR) with gapless logging, delivering both current state of the art and verifiable proof — even when guard posts cannot be staffed (78% staffing shortfalls in the German security market).
From duty to deployment
Physical security rarely fails at the concept stage — it fails at continuity: the best perimeter is useless if the night shift is unstaffed. A blend of reduced human presence and robotic continuous monitoring closes that gap, provided on the RaaS model, pilotable within 48 hours.
On cost: a continuously staffed guard post runs €20,000–23,000/month; an autonomous unit from €3,200/month — full comparison in robot vs. guard cost.
Frequently asked questions
What belongs to physical security? Perimeter, grounds, building envelope and core zone — covered by the goals detection, delay, response. Structural, technical and organisational measures together.
Does NIS-2 require physical security? Yes, for protecting critical IT/OT assets. The more explicit mandate for site protection sits in the KRITIS-Dachgesetz.
What is "state of the art" in physical security? Proven, market-available technology at the upper edge of the usual — in 2026 increasingly continuous sensor-based monitoring with audit-ready documentation.
Basis: Dr. Raphael Nagel (LL.M.) / Marcus Köhnlein, "KRITIS – Die verborgene Macht Europas" (2026), chapters 4, 10, 16.
Translations