{"id":15636,"date":"2026-05-24T19:55:12","date_gmt":"2026-05-24T19:55:12","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/05\/25\/zero-trust-at-the-energy-supplier-what-the-nis2-audits-are-now-revealing\/"},"modified":"2026-05-25T15:56:45","modified_gmt":"2026-05-25T15:56:45","slug":"zero-trust-at-the-energy-supplier-what-the-nis2-audits-are-now-revealing","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/05\/24\/zero-trust-at-the-energy-supplier-what-the-nis2-audits-are-now-revealing\/","title":{"rendered":"Zero Trust at the energy supplier: What the NIS2 audits are now revealing"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">8 min read<\/p>\n<p><strong>On 29 April 2026, CISA, the US Department of Energy and four other agencies issued a joint recommendation on applying Zero Trust principles to Operational Technology. Three weeks later, Germany\u2019s first BSI audits under the NIS2 Implementation Act-effective since 6 December 2025-kick off. Energy suppliers now face double pressure. Operators running flat networks with shared identities across IT and OT no longer meet the state of the art under the BNetzA\u2019s new IT security catalogue. Last year\u2019s Volt Typhoon campaign showed exactly what that looks like in practice.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">NIS2 in energy went live in December 2025.<\/strong> BSI and BNetzA obligations apply; audits go live in summer 2026. Registration with the BBK under the KRITIS umbrella law must be completed by 17 July 2026.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Zero Trust for OT isn\u2019t copied from IT.<\/strong> The 29 April 2026 CISA guidance makes clear: segmentation, identity boundaries and asset visibility must be engineered for SCADA, protection systems and control centres-not retrofitted.<\/li>\n<li style=\"color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">The most common gap sits at the IT-OT boundary.<\/strong> Shared service accounts, overlapping domain structures and unsegmented maintenance access are the 2026 route by which IT compromises reach the control room.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#666;margin:20px 0 32px 0;border-top:1px solid #e5e5e5;border-bottom:1px solid #e5e5e5;padding:10px 0;\"><span style=\"color:#004a59;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/07\/adaptive-mfa-nis2-pressure-as-a-zero-trust\/\" style=\"color:#333;text-decoration:underline;\">Adaptive MFA as a Zero-Trust lever<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was\/\" style=\"color:#333;text-decoration:underline;\">NIS2 enforcement hits 29,500 firms<\/a><\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">How a DACH energy supplier kicked off Zero Trust in 2026<\/h2>\n<p>The graphic below distils a typical programme from several publicly discussed utility initiatives-not a single company. Real names are omitted because verifiable public sources are scarce. If you\u2019re hunting for a vendor success story, look elsewhere. If you need an anchor for your own roadmap, here\u2019s a realistic approach.<\/p>\n<p>Baseline: a mid-size distribution grid operator (mid-hundreds of MW), multiple substations, its own control room, a Microsoft-centric IT estate and a historically grown ICS network. In 2025 the BNetzA listed the utility as KRITIS; with the NIS2 Implementation Act taking effect in December 2025, the compliance pressure doubled. The audit squeeze now comes from both the BNetzA IT security catalogue and the upcoming ISO 27019 re-certification.<\/p>\n<p>The first hard audit finding from the internal pre-assessment was uncomfortable: 41 service accounts with privileges spanning both worlds, five maintenance VPNs reaching OT segments without MFA, and an Active Directory structure that would have propagated a domain-admin compromise straight into the control room. Exactly the pattern the CISA guidance explicitly warns against.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Five steps that actually drove the program forward<\/h2>\n<p>Rather than designing a zero-trust architecture on paper, the team worked in five prioritized steps. Each produced an audit artifact the auditor can understand without further explanation.<\/p>\n<div style=\"margin:28px 0;border:1px solid #d0d4d9;border-radius:6px;overflow:hidden;\">\n<div style=\"background:#003340;color:#fff;padding:12px 18px;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.14em;\">Five prioritized steps for zero trust at an energy utility<\/div>\n<div style=\"padding:8px 0;\">\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:80px;font-weight:700;color:#0070a8;\">Step 1<\/div>\n<div style=\"color:#333;line-height:1.55;\"><strong>Unified asset inventory across IT and OT.<\/strong> Every policy begins with a definitive list of devices, protocols, firmware versions, and owners. Without this inventory, segmentation remains theoretical. In practice: passive listening on the OT mirror port, cross-checked against the CMDB baseline.<\/div>\n<\/p><\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:80px;font-weight:700;color:#0070a8;\">Step 2<\/div>\n<div style=\"color:#333;line-height:1.55;\"><strong>Identity separation at the IT-OT boundary.<\/strong> Shared service accounts are eliminated; OT accounts move into a dedicated identity domain with its own lifecycle. Phishing-resistant factors such as FIDO2 for administrative access are no longer optional.<\/div>\n<\/p><\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:80px;font-weight:700;color:#0070a8;\">Step 3<\/div>\n<div style=\"color:#333;line-height:1.55;\"><strong>Micro-segmentation from Purdue Level 3 onward.<\/strong> The hard line runs between Manufacturing Operations (Level 3) and Process Control (Level 2). Every crossing passes through an explainable gateway; every rule has an owner. Default is deny, not allow.<\/div>\n<\/p><\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:80px;font-weight:700;color:#0070a8;\">Step 4<\/div>\n<div style=\"color:#333;line-height:1.55;\"><strong>OT-specific threat detection with its own use-case catalog.<\/strong> The BSI-compliant system detects OT patterns-Modbus, IEC 60870-5-104, DNP3-not just IT logic. Anomalies trigger dedicated detectors and escalation paths into the SOC.<\/div>\n<\/p><\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;\">\n<div style=\"min-width:80px;font-weight:700;color:#0070a8;\">Step 5<\/div>\n<div style=\"color:#333;line-height:1.55;\"><strong>Incident response with BBK pathway and 24-hour notification.<\/strong> NIS2 mandates initial reporting to the BSI within 24 hours and final reporting within 72 hours. Parallel drills follow the BBK pathway from the KRITIS umbrella law. Playbooks distinguish between IT and OT incidents.<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<p>The sequence is not a matter of preference. Starting with step three without knowing your asset and identity posture means segmenting on assumptions-an approach that collapses under real pressure.<\/p>\n<div style=\"background:#003340;color:#fff;text-align:center;padding:40px 24px;margin:32px 0;border-radius:8px;\">\n<div style=\"font-size:3.4em;font-weight:800;color:#69d8ed;letter-spacing:-0.03em;line-height:1;\">29,500<\/div>\n<div style=\"font-size:1em;color:rgba(255,255,255,0.88);margin-top:12px;max-width:560px;margin-left:auto;margin-right:auto;line-height:1.5;\">German entities fall under the NIS2 regime-six times more than under the previous KRITIS ordinance. Fines reach up to 10 million euros, and the initial reporting deadline is 24 hours.<\/div>\n<div style=\"font-size:0.78em;color:rgba(255,255,255,0.5);margin-top:12px;\">Source: BSI \/ OpenKRITIS, March 2026<\/div>\n<\/div>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What the CISA recommendation means for DACH utilities<\/h2>\n<p>The joint advisory dated 29 April 2026 is not just for U.S. readers. It highlights four points every DACH utility audit will spotlight. First, identities must not be shared between IT and OT. Second, visibility at asset and protocol level is a prerequisite for segmentation. Third, default-deny must work in OT without disrupting operations. Fourth, incident response in OT requires its own playbooks and exercises.<\/p>\n<p>Volt Typhoon is explicitly named in the advisory. The pattern of compromising IT credentials to pivot into OT is now standard. A utility that does not separate OT identities is banking on the protection of its IT domain-protection that has failed in multiple public incidents.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Where suppliers will still fail in 2026<\/h2>\n<p>Three mistakes crop up most often in practice. The first is organisational. OT security sits with operations, IT security with the CIO. Without shared responsibility anchored at board level, every zero-trust strategy falls apart at the seam. NIS2 makes management explicitly liable, rendering the split politically untenable.<\/p>\n<p>The second mistake is technical. Maintenance VPNs for plant manufacturers are treated as exceptions and thus excluded from micro-segmentation. Exactly this vector has been cited in several public energy incidents over the past two years. Any blanket exemption here undermines the entire concept.<\/p>\n<p>The third mistake is procedural. The 24-hour NIS2 initial-reporting deadline is rarely rehearsed. In reality it means an on-call team must be able to authorise the report without waking the executive board. Without test reports and a documented escalation chain, the deadline will be missed when it matters.<\/p>\n<p>The utility in the case study above tackled precisely these three gaps before rolling out the technical programme-three months before the first BSI audit. That is the pragmatic window in which open issues can actually be closed. Starting in June, you will only have slides by September.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<h3>When does the first BSI audit start under the NIS2 Implementation Act?<\/h3>\n<p>The NIS2 Implementation Act entered into force on 6 December 2025; the registration obligation is live. BSI supervision moved into the operational phase in May 2026, with first audits at critical-infrastructure energy suppliers expected for summer 2026. If you cannot document the risk-management measures required by Article 21 NIS2, you will face a problem.<\/p>\n<h3>How does zero-trust in OT differ from zero-trust in IT?<\/h3>\n<p>OT environments have hard availability and latency demands, legacy protocols without encryption, and devices that cannot be patched. An IT logic that relies on continuous verification for every request cannot simply be applied to a control system. The CISA recommendation of 29 April 2026 therefore sets out a dedicated OT interpretation: segmentation, identity boundaries and asset visibility come first; continuous verification is phased in.<\/p>\n<h3>What role does ISO 27019 play in NIS2 audit practice?<\/h3>\n<p>ISO 27019 is the energy-specific extension of ISO 27001. It covers OT-specific controls that the plain 27001 catalogue does not address. In the BNetzA IT security catalogue, certification to ISO 27001 plus 27019 is mandatory. NIS2 risk-management and ISO 27019 requirements overlap, so audits can be combined if documentation is clean.<\/p>\n<h3>Do maintenance VPNs have to be fully integrated into micro-segmentation?<\/h3>\n<p>Yes-with dedicated, time-limited identities and in-line detection. Blanket exemptions for plant manufacturers are no longer defensible under CISA guidance and audit practice. Just-in-time access combined with session recording replaces the permanent site-to-site tunnel.<\/p>\n<h3>How can the BBK under the KRITIS umbrella be used alongside the BSI?<\/h3>\n<p>The KRITIS umbrella law addresses physical resilience, sabotage and hybrid threats, while NIS2 covers IT security. Both tracks run in parallel, with separate registrations. Suppliers must also register with the BBK by 17 July 2026. Operationally, it makes sense to structure incident reports, exercises and contingency plans so that a single report serves whichever track is relevant, avoiding duplication.<\/p>\n<h3>Editor\u2019s Reading Picks<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was\/\">NIS2 enforcement targets 29,500 German firms<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/13\/zero-trust-network-segmentation-why-flat-networks-are-the-biggest-security-risk\/\">Zero-Trust network segmentation: why flat networks are the biggest security risk<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/23\/when-manufacturing-stops-why-german-engineering-is-targeted-by-ot-attacks\/\">When production halts: OT attacks in German mechanical engineering<\/a><\/li>\n<\/ul>\n<div style=\"margin:40px 0 24px 0;\">\n<p style=\"margin:0 0 12px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.18em;color:#666;\">More from the MBF Media Network<\/p>\n<div style=\"padding:14px 18px;border-left:3px solid #0bb7fd;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#0bb7fd;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">cloudmagazin<\/div>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/2026\/05\/24\/platform-engineering-compliance-idp-nis2-dora-2026\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Platform engineering for compliance: IDPs enforce NIS2 and DORA<\/a><\/p>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #202528;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#202528;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">mybusinessfuture<\/div>\n<p><a href=\"https:\/\/mybusinessfuture.com\/krisenplan-statt-krisen-pr-mittelstand-vier-entscheidungen\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Crisis plan instead of crisis PR: four decisions for SMEs<\/a><\/p>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #d65663;background:#fafafa;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#d65663;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">digital-chiefs<\/div>\n<p><a href=\"https:\/\/www.digital-chiefs.de\/tech-mandate-aufsichtsrat-nis2-eu-ai-act-governance-2026\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Tech mandates on supervisory boards: NIS2, EU AI Act and the skills gap<\/a><\/p>\n<\/div>\n<\/div>\n<p style=\"text-align:right;color:#868e96;font-size:0.85em;margin-top:48px;\"><em>Source of title image: Pexels<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"The BSI will launch the first NIS2 audits for KRITIS energy suppliers in summer 2026. What OT Zero Trust really needs to deliver &#8211; beyond identity logic.","protected":false},"author":55,"featured_media":14101,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"","_yoast_wpseo_title":"Zero Trust at the energy supplier: What the NIS2 audits are now revealing","_yoast_wpseo_metadesc":"BSI launches first NIS2 audits for critical energy suppliers in summer 2026. Discover what OT-Zero-Trust truly needs beyond identity logic.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_wp_old_slug":[],"footnotes":""},"categories":[3,5,215,251],"tags":[],"class_list":{"0":"post-15636","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","6":"hentry","7":"category-aktuelles","8":"category-case-studies","10":"category-news"},"wpml_language":"en","wpml_translation_of":15576,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/15636","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=15636"}],"version-history":[{"count":1,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/15636\/revisions"}],"predecessor-version":[{"id":15640,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/15636\/revisions\/15640"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/14101"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=15636"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=15636"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=15636"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}