NIS2 · KRITIS
The waste management industry is critical infrastructure. With the NIS2 Implementation Act, binding IT security obligations have been in effect since the end of 2025 for most medium-sized recycling and waste management companies — regardless of whether they are private or municipal.
Overview
Classification
If waste disposal fails, hygienic and logistical problems arise for millions of people within a few days. Therefore, in 2021, the legislator included municipal waste disposal in the group of critical infrastructure sectors—on par with energy, water, health, and telecommunications.
Since January 1, 2024, the revised BSI-KritisV specifically defines which facilities are considered critical infrastructure:
The legal form does not matter: Purely private companies are also KRITIS operators, if they operate relevant facilities above the threshold values.

NIS2 expands the circle
With NIS2, the entire company is considered at least a "significant entity" as soon as it operates in the waste management sector and exceeds one of these thresholds. Operators of critical facilities are classified as a "particularly significant entity" — with stricter obligations and more intensive BSI supervision.
50+
Employees — or
10 million €
Annual revenue and total assets
Duties
Affected institutions must register with the BSI and designate a point of contact.
Concepts for risk analysis and information security, incident management, backup and crisis management, supply chain security, secure development and maintenance of IT systems (including your website), encryption, access control, MFA, and training.
Significant security incidents are reported in stages: Initial report within 24 hours, detailed follow-up report within 72 hours, final report within one month.
The management must approve measures, monitor their implementation, and regularly participate in training sessions. Personal liability is threatened in case of breaches of duty.
The KRITIS Framework Act (Spring 2026) requires operators of critical facilities to adhere to minimum standards for physical and organizational protection: access controls, emergency plans, resilience management.
And your website?
More than many think: Website, online shop, and customer portal are part of your IT attack surface and fall under the required risk management.
Outdated CMS installations and unpatched plugins are among the most common entry points. A modern, maintained architecture structurally reduces the risk.
NIS2 requires that you also check your service providers. Your web agency must be able to demonstrate clean processes: access controls, deployment processes, incident handling, documented QA.
When customers order through the shop and prices come from the ERP, the website is part of your business continuity.
Without monitoring and logging, you cannot detect or report incidents in a timely manner.
This is how Desent supports
We are not a certification authority or legal advisors. However, we ensure that your web platform meets the requirements that NIS2 sets for secure IT systems and service providers.
We have transformed the web platform to a modern architecture with automated tests, a structured QA process, and ERP price integration. The result: traceable releases, stable availability, and a platform that meets the demands of critical infrastructure.
Yes. NIS2 and KRITIS are linked to activity, size, and facilities, not to the ownership structure. Private, municipal, or mixed makes no difference.
Free Analysis
You receive a clear report on the current state with a prioritized list of actions — no sales pitch as a prerequisite, no obligation. You decide how to proceed.
Note: This article is for general information purposes and does not replace legal advice. For the legal classification of your company, we recommend consulting with specialized advisors.