What is IT-Sicherheitskatalog (§ 11 Absatz 1b EnWG) compliance?

If you operate a German energy installation classified as critical infrastructure, the IT-Sicherheitskatalog issued by the Bundesnetzagentur sets the cybersecurity baselines you have to meet to keep your telecommunications and data processing systems safe.

Banner thumbnail
On this page  
  • Introduction
  • Applicability and scope
  • Protection goals
  • Scope and zone classification
  • Security requirements
  • Implementation rules
  • Special rules for nuclear facilities
  • Challenges of implementing the IT-Sicherheitskatalog
  • Benefits of implementing the IT-Sicherheitskatalog
  • Best practices
  • Conclusion
 

Introduction

If your organization runs an energy installation that the German authorities have designated as critical infrastructure, you operate systems on which the rest of the country quietly depends. The IT-Sicherheitskatalog issued under § 11 Absatz 1b of the Energiewirtschaftsgesetz (EnWG) defines how you protect the telecommunications and electronic data processing systems needed for safe installation operations. IT-Sicherheitskatalog compliance means proving, through a certified management system, that those systems are adequately shielded against threats.

The catalog exists because the energy supply now depends on information and communications technology, and that dependence carries risk. The Bundesnetzagentur had already published a 2015 catalog under § 11 Absatz 1a for grid operators; the legislature then added paragraph 1b to cover the operators of energy installations connected to the public supply network. The driving concern is clear : A serious cyberattack at the installation level tends to hit several plants at once, so a damaged plant cannot simply be swapped for another. Each installation has to carry a high level of protection on its own.

Applicability and scope

The catalog applies to operators of energy installations classified as critical infrastructure under the BSI-Kritisverordnung and connected to an energy supply network. In practice, that covers electricity generation and storage installations along with gas production and gas storage facilities, as defined in the relevant annex of that ordinance. If your installation's applications, systems, or components are run by a third party (for example under an outsourcing arrangement), you stay fully responsible for compliance and have to secure it through the contract.

Compliance levels and requirements

The catalog runs in sequence, from principles to practices. Operators in the scope work through the protection goals, then the scope and zone classification that decides which systems are covered, then the security requirements built around a management system, and finally the implementation rules that establish certification and reporting deadlines. Nuclear facilities follow a separate track. Working through this in order, your organization moves from defining what it protects to proving the protection is real.

The catalog's main divisions cover the following:

  • Protection goals: The information security objectives, general and installation-specific, that every measure has to serve
  • Scope and zone classification: A method for sorting every system into one of six zones by its importance to safe operations
  • Security requirements: A certified information security management system (ISMS), security categories, proper operation, risk assessments, risk treatments, and a named security contact
  • Implementation rules: Certification through an accredited body and the deadlines for proof
  • Special rules for nuclear facilities: An alternative path for plants already governed by the SEWD-Richtlinie IT

Protection goals

This division defines what adequate protection actually means. The general protection goals are the three classic pillars of information security, and every measure an operator picks has to serve at least one of them.The catalog helps operators decide the right level of protection for each installation based on the individual needs of its systems, weighing both the risks to plant operations and the risks at the interfaces with connected supply networks. The responsibility for meeting the goals stays with the operator, even when third parties do the work.

Beyond the general goals, the catalog adds installation-specific protection goals for each category. Generation and storage installations, for instance, have to supply electrical power in line with communicated schedules, transmission and distribution operator instructions, and load dispatcher orders covering vital electricity demand, and they have to provide a black start capability where it is technically possible and contractually agreed upon. Gas production and storage facilities carry parallel goals around the injection and withdrawal capacity.

Scope and zone classification

This division sets the practical boundary of compliance: which applications, systems, and components an operator actually has to protect. You sort every telecommunications and data processing system used in the installation into one of six zones, covering both process control and control room systems and ordinary office and administrative systems. A zone is not a network segment. It is a ranking of how much a system matters to safe operations, and when a system could fit several zones, it goes in the one with the highest importance.

The split matters because the catalog's hardest obligations attach to the top zones. The mandatory management system has to cover at least Zones 1 through 3, and those are the same zones where risk treatment is compulsory.

Security requirements

This is the substantive heart of the catalog and where most of the work comes from. It rejects the idea that installing antivirus software, firewalls, and similar single-purpose measures is enough. Operators instead have to run a holistic management system that is reviewed continuously and adjusted when it falls short. The catalog requires this critical infrastructure energy ISMS to meet DIN EN ISO/IEC 27001 requirements, to take its control guidance from ISO/IEC 27002 and the energy-sector-specific ISO/IEC 27019 standard, and to cover at least the systems in Zones 1 through 3.

The catalog sets out several connected obligations for inside the management system:

  • Proper operation of affected systems: Operators have to keep the telecommunications and data processing systems (and the processes built on them) under control at all times, and they must be able to spot and fix technical faults.
  • Risk assessments: Operators have to implement a defined process for identifying the information security risk to in-scope systems using the four damage categories and a fixed set of impact criteria.
  • Risk treatments: Operators must apply appropriate measures to systems in Zones 1 through 3, with Zone 1 risks never simply accepted and a medium residual risk level as the worst case.
  • An IT security contact: For coordination with the Bundesnetzagentur, operators must name a contact who can report promptly on implementation status, incidents, and their causes.

The risk assessment is worth a closer look because the catalog fixes the starting point for you. Systems needed for safe operation are presumed to fall into the high damage category by default. You then check whether critical is warranted, and any downgrade to moderate or low has to be documented in detail and justified.

Implementation rules

This division covers how to prove compliance and by when. The conformity of the ISMS with the catalog has to be shown through a certificate from an independent certification body accredited for this catalog by the Deutsche Akkreditierungsstelle. The deadlines are firm. For preexisting operators, the IT security contact and their details were due to be reported to the Bundesnetzagentur by Feb. 28, 2019, and a copy of the certificate confirming completed certification was due by March 31, 2021.

Special rules for nuclear facilities

Installations operating under § 7 Absatz 1 of the Atomgesetz take a different path. Because the SEWD-Richtlinie IT already governs them with protection goals aimed at nuclear safety, they skip the full ISMS certification, though they still have to name an IT security contact. What the catalog adds is that operators also have to factor the installation-specific protection goals for generation plants into their protection needs assessment, ranked below nuclear safety. Proof comes as an annual confirmation from the competent nuclear oversight authorities plus a signed management declaration.

Challenges of implementing the IT-Sicherheitskatalog

Bringing a critical infrastructure energy installation into IT-Sicherheitskatalog compliance can be demanding, especially for operators setting up a certified management system for the first time.

Building a full ISMS rather than buying tools

The catalog rules out single-purpose solutions, so you cannot meet it by buying security products. You have to design, document, and run a complete management system aligned with ISO/IEC 27001, then keep it operating as a permanent process. For an operator with no existing ISMS, that is a program, not a purchase.

Classifying every system into the right zone

The six-zone classification is harder than it first looks, because it forces a judgment about how much each system matters to safe operations. Process control, control room, office, and administrative systems all have to be placed in a zone, and a misclassification that pushes a system out of Zones 1 through 3 can quietly drop it from the mandatory ISMS scope.

Layering on energy-specific standards

You are not working from one document. The catalog pulls in ISO/IEC 27001, ISO/IEC 27002, and the energy sector ISO/IEC 27019 standard, and it points to extras like the VGB standard and the BDEW white paper. Reconciling them and tracking their current editions adds real overhead for a compliance team.

Securing the gaps between zones

Where systems in Zones 1 through 3 exchange operationally relevant information with systems in Zones 4 through 6, operators have to keep availability, integrity, and confidentiality intact across that boundary. The protection need follows the higher zone, so lower-zone systems can inherit obligations that were not obvious when they were first classified.

Sustaining proof over time

Certification is not a one-time event. The management system has to be reviewed for effectiveness and adjusted as needed, and nuclear facility operators face an annual renewal of their confirmation. Keeping evidence current between audit cycles is an ongoing burden that many organizations underestimate.

Benefits of implementing the IT-Sicherheitskatalog

Reaching IT-Sicherheitskatalog compliance pays off well past satisfying the Bundesnetzagentur.

A genuinely resilient installation

Because the catalog assumes that attacks hit several plants at once, the controls you build raise each installation's level of protection. Operators that finish the work end up with systems that hold up against the deliberate attacks and accidental failures (from human error to a force majeure) that the risk assessment also makes them account for.

Clearer ownership of risks

ISMS certification requires a defined risk assessment and treatment process, with the damage categories and the maximum allowable residual risk levels written down. Organizations that adopt it usually get a much clearer picture of which systems carry which risks, which makes spending decisions far easier to defend.

Alignment with international standards

Building to ISO/IEC 27001, 27002, and 27019 standards means you are meeting EnWG IT security requirements and operating at recognized international benchmarks at the same time. That alignment tends to make other audits simpler, since the people running them already work to the same standards.

Faster, calmer incident response

You come out of this with a named IT security contact, defined reporting lines to the Bundesnetzagentur, and the Federal Office for Information Security (BSI) contact point registration that brings situation reports and warnings. When an incident hits, that structure turns a scramble into a process, and the reporting obligations are already mapped.

Best practices

If the goal is more than minimal compliance, a few practices pay off in the long run:

Governance and technical implementation

  • Treat the zone classification as a living inventory and revisit it whenever systems are added, retired, or repurposed so nothing drifts out of the mandatory scope unnoticed.
  • Anchor the ISMS in the PDCA cycle and schedule the review phase as a recurring commitment, not an annual fire drill before an audit.
  • Assign in-scope systems to the high damage category by default (as the catalog requires) and document every downgrade with the justification it demands.

Risk treatments and vendor oversight

  • Never accept Zone 1 risks; design treatment so that, at worst, a medium residual risk level remains for systems essential to safe operations.
  • Map every cross-zone information exchange and apply the higher zone's protection measures to it, rather than treating lower-zone systems as automatically low-risk.
  • Where systems are outsourced, write the catalog's obligations into the contract and remember that full responsibility stays with you as the operator.

Monitoring, reporting, and documentation

  • Register a contact point with the BSI early so situation reports and warnings reach you before an incident, not after.
  • Keep the IT security contact's knowledge current so they can answer the Bundesnetzagentur promptly on the implementation status, incidents, and remediation.
  • Maintain audit-ready evidence continuously so that certification renewal or the annual confirmation for nuclear facilities is a refresh rather than a rebuild.

Conclusion

What's next for firms looking to be IT-Sicherheitskatalog-compliant?

The IT-Sicherheitskatalog matters because the covered installations sit where a single coordinated attack could spread across the electricity and gas supply on which everyone else relies. Operators that treat compliance as a one-off certification project tend to watch the same gaps reopen at each review, because the catalog is designed around a management system that is meant to adapt, not sit on a shelf.

The better approach is to read the catalog as a description of a capability you are building, not a box you are ticking. If you set up a real ISMS, keep your zone classification honest, and hold your risk assessments and treatments to the standard the catalog sets, then you will clear the certification and run an installation that is harder to knock over. That is what the EnWG IT security requirements were written to produce.