Websites for recycling companies

NIS2 · KRITIS

NIS2 for recycling companies:
What waste managers need to know now

The waste management industry is critical infrastructure. With the NIS2 Implementation Act, binding IT security obligations have been in effect since the end of 2025 for most medium-sized recycling and waste management companies — regardless of whether they are private or municipal.

Overview

What?
NIS2 Implementation Act (new BSIG) plus KRITIS Umbrella Act
Since when?
NIS2: in effect since the end of 2025. KRITIS umbrella law: Spring 2026
Who is affected?
Waste management companies with 50 or more employees or 10 million euros in annual turnover and balance sheet total; Critical infrastructure operators from certain facility thresholds
Core Duties
Registration, Risk Management, Incident Reporting Obligations, Supply Chain Security, Management Responsibility
In case of violations
Severe fines, personal liability of management possible

Classification

Why is waste management important
as critical infrastructure?

If waste disposal fails, hygienic and logistical problems arise for millions of people within a few days. Therefore, in 2021, the legislator included municipal waste disposal in the group of critical infrastructure sectors—on par with energy, water, health, and telecommunications.

Since January 1, 2024, the revised BSI-KritisV specifically defines which facilities are considered critical infrastructure:

  • Management of Municipal Waste Collection and Transportation
  • Storage, interim storage, and transshipment of municipal waste
  • Thermal Treatment (Waste Incineration)
  • Mechanical-biological treatment plants and sorting plants

The legal form does not matter: Purely private companies are also KRITIS operators, if they operate relevant facilities above the threshold values.

Protective Shield for IT Infrastructure — NIS2 and KRITIS

NIS2 expands the circle

It is no longer just those who operate a critical facility who are affected

With NIS2, the entire company is considered at least a "significant entity" as soon as it operates in the waste management sector and exceeds one of these thresholds. Operators of critical facilities are classified as a "particularly significant entity" — with stricter obligations and more intensive BSI supervision.

50+

Employees — or

10 million €

Annual revenue and total assets

Duties

The specific obligations
under NIS2 and KRITIS

01 · Registration

Register with BSI

Affected institutions must register with the BSI and designate a point of contact.

02 · Risk

Implement risk management

Concepts for risk analysis and information security, incident management, backup and crisis management, supply chain security, secure development and maintenance of IT systems (including your website), encryption, access control, MFA, and training.

03 · Message

Report incidents on time

Significant security incidents are reported in stages: Initial report within 24 hours, detailed follow-up report within 72 hours, final report within one month.

04 · Management

Management in Duty

The management must approve measures, monitor their implementation, and regularly participate in training sessions. Personal liability is threatened in case of breaches of duty.

05 · KRITIS

Physical Resilience

The KRITIS Framework Act (Spring 2026) requires operators of critical facilities to adhere to minimum standards for physical and organizational protection: access controls, emergency plans, resilience management.

And your website?

What does NIS2 have
to do with your website?

More than many think: Website, online shop, and customer portal are part of your IT attack surface and fall under the required risk management.

Secure Development and Operation

Outdated CMS installations and unpatched plugins are among the most common entry points. A modern, maintained architecture structurally reduces the risk.

Supply Chain Security

NIS2 requires that you also check your service providers. Your web agency must be able to demonstrate clean processes: access controls, deployment processes, incident handling, documented QA.

Availability

When customers order through the shop and prices come from the ERP, the website is part of your business continuity.

Reportability

Without monitoring and logging, you cannot detect or report incidents in a timely manner.

This is how Desent supports

Your web platform,
Built to be NIS2-compliant

We are not a certification authority or legal advisors. However, we ensure that your web platform meets the requirements that NIS2 sets for secure IT systems and service providers.

  • Modern, secure stack instead of a patchwork of plugins: Next.js, Vercel, Headless CMS — with clearly defined update and deployment processes
  • Documented QA processes: automated tests and structured test plans (TestRail, Jira) — exactly such evidence is required by NIS2 from your supply chain
  • Monitoring and Incident Processes: Availability and Error Monitoring with Defined Response Times per SLA
  • Secure Integrations: ERP connections (e.g., AMCS/Recy) with a clean authorization concept instead of open interfaces
  • Collaboration with your security officers: We provide the technical evidence that your ISMS and audits need
Practical Example

Berlin Recycling GmbH

We have transformed the web platform to a modern architecture with automated tests, a structured QA process, and ERP price integration. The result: traceable releases, stable availability, and a platform that meets the demands of critical infrastructure.

FAQ

Any questions?
Here are answers.

Any other questions?

Write to us →

Yes. NIS2 and KRITIS are linked to activity, size, and facilities, not to the ownership structure. Private, municipal, or mixed makes no difference.

Free Analysis

Where is your website located?
We check it — free of charge.

You receive a clear report on the current state with a prioritized list of actions — no sales pitch as a prerequisite, no obligation. You decide how to proceed.

Note: This article is for general information purposes and does not replace legal advice. For the legal classification of your company, we recommend consulting with specialized advisors.

Security Basics and Attack Surface of Your Web Platform
Accessibility according to WCAG 2.1 AA and BFSG
Technical SEO and Performance
Prioritized action list as a basis for your NIS2 documentation