DevSecOps · KRITIS · BSI · NIS2

Compliance created in the pipeline — not in a binder.

KRITIS operators and companies affected by NIS2 must demonstrate state-of-the-art security. We build that evidence directly into your CI/CD: SBOM, CVE governance, SAST/DAST and complete audit trails — automated instead of manually compiled.

KRITIS § 8a BSIG
BSI IT-Grundschutz
NIS2 implementation act
SBOM: CycloneDX / SPDX
ISO 27001 Alignment

Security building blocks for your CI/CD

Each building block automatically produces the evidence auditors want to see — as a by-product of normal development work.

SBOM-Generierung

Automated software bills of materials (CycloneDX, SPDX) for every build version: your own code, open-source dependencies, container images. The basis of any supply-chain statement.

CycloneDXSPDX

CVE-Governance

Continuous matching of your SBOMs against vulnerability databases, prioritisation by reachability and criticality, documented treatment decisions.

CVE-TriagePolicies

SAST & DAST

Static and dynamic security analysis as pipeline stages: fast checks in the pull request, deep scans nightly — findings directly in the developers' workflow.

SASTDASTPR-Gates

Audit trails & evidence

Who deployed, reviewed and approved what, and when? Complete, tamper-proof change histories for BSI audits and § 8a evidence reviews.

ApprovalsTraceability

Secrets & access management

No credentials in pipelines or repos: vault integration, service connections with minimal rights, regular rotation — verifiably implemented.

VaultLeast Privilege

Compliance-Mapping

We translate BSI Grundschutz modules, KRITIS and NIS2 requirements into concrete technical measures in your toolchain — including documentation for the audit.

BSI-BausteineNIS2ISO 27001

Auditors want evidence. Developers want to ship. A good pipeline delivers both.

The classic approach — spreadsheets, manually maintained evidence documents, security reviews right before the audit — doesn't scale and is always outdated. Our approach: every merge, every build, every deployment produces its own compliance artifacts. The audit becomes a query instead of archaeology. And your developers barely notice — except that findings arrive earlier, when they're still cheap to fix.

Frequently asked questions about DevSecOps & KRITIS

What does KRITIS mean for our software development in concrete terms?

As a KRITIS operator you must demonstrate appropriate organisational and technical measures in line with the state of the art under § 8a BSIG. For software development this means: traceable build and deployment processes, controlled software supply chains (SBOM), vulnerability management (CVE) and auditable change histories. These are exactly the artifacts we generate directly in your CI/CD pipeline.

What does NIS2 change compared to existing KRITIS obligations?

NIS2 significantly widens the circle of affected companies and tightens requirements for risk management, supply chain security and reporting obligations. Companies that previously did not fall under KRITIS will also have to demonstrate security measures in their software supply chain. A pipeline with SBOM generation and CVE governance is a solid technical foundation for that.

Does DevSecOps slow our developers down?

Not if it's built right. Our security checks run parallelised and incrementally: fast checks in the pull request, deep scans nightly. Developers get findings where they work — in the PR, not in a PDF report weeks later. In practice teams get faster, because security issues are fixed earlier and more cheaply.

What is an SBOM and why do we need one?

An SBOM (Software Bill of Materials) is a machine-readable parts list of all components of your software — your own code, open-source packages, container base images. It's the prerequisite for knowing immediately whether and where you are affected when new vulnerabilities (CVEs) appear. We generate SBOMs automatically in the build (CycloneDX/SPDX) and link them to continuous CVE matching.

Does this also work in environments without internet access?

Yes — that's one of our specialities. SBOM generation, CVE databases and scanning tools can be operated in air-gapped networks using controlled offline replication paths. Details on the page air-gapped & VLAN environments.

Where does your pipeline stand today?

In a free initial call we assess which KRITIS/NIS2 requirements your toolchain already meets — and where the critical gaps are.

info@xeam-solutions.com
Request a consultation