Intralogistics forms the backbone of modern value chains and, at the same time, offers significant potential for optimization within every individual company. It encompasses all internal material and goods flows as well as the associated information processes. However, with increasing digitalization—such as through automated warehouse systems, networked conveyor technology, and intelligent control software—dependence on stable and secure IT systems is also growing. This is precisely where standards and regulatory requirements are becoming increasingly important: NIS2 is the EU directive that was transposed into German law and implemented in Germany through the BSI Act of December 6, 2025. Included and defined therein is the BSI Critical Infrastructure Regulation (BSI-KritisV); this regulation specifies the scope by defining sectors and thresholds above which facilities are classified as “KRITIS.” ISO 27001, in turn, is a type of certification that allows organizations to demonstrate they have implemented the necessary measures, which will be audited accordingly.
Why is this topic so relevant?
A company’s intralogistics operations are highly digitized areas of the organization. Systems such as warehouse management systems (WMS), transport management software, and IoT-based sensor technology are essential for operations. A failure or compromise of these systems can have massive consequences—ranging from delivery delays and production shutdowns to significant financial losses.
In addition, more and more companies are coming under the scrutiny of regulatory requirements. The BSI-KritisV significantly expands the scope of affected companies and, for the first time, requires many organizations to implement comprehensive cybersecurity measures. At the same time, the KRITIS Regulation tightens the reporting requirements for companies classified as part of critical infrastructure—for example, in the energy, healthcare, or transportation sectors. Suppliers and service providers to such critical facilities may also be indirectly affected.
An ISO 27001-certified Information Security Management System (ISMS), in turn, is internationally recognized, which strengthens trust among customers and partners.
ISO 27001 in Intralogistics
Implementing an ISMS in accordance with ISO 27001 helps companies systematically identify risks and implement appropriate protective measures. In intralogistics, this specifically means:
- Securing individual components or the entire IT infrastructure (e.g., for conveyor systems or automated warehouse systems)
- Protecting sensitive data such as shipping information or customer data; the main objectives of information security are also illustrated by the CIA model: Confidentiality, Integrity, and Availability
- Regular risk analyses and audits
- Establishing clear processes for handling security incidents
A major advantage: ISO 27001 is scalable and can be implemented by both medium-sized companies and large corporations; and as already mentioned, entire systems or just parts of them can be certified.
NIS2 – New Cybersecurity Requirements Under the BSI Act
With NIS2, the EU is significantly tightening its IT security requirements. Among other things, companies must:
- Implement state-of-the-art security measures
- Report security incidents within short timeframes
- Strengthen supply chain security
- Clearly define responsibilities at the management level
Of particular relevance to intralogistics is the fact that companies indirectly affected — for example, as part of a supply chain — are also being held more accountable. For instance, companies that provide logistics services for critical infrastructure should also demonstrate high security standards in order to be prepared for future inquiries.
KRITIS – Protection of Critical Infrastructure
Companies classified as KRITIS operators are subject to even stricter legal requirements. These include:
- Minimum standards for IT security
- Obligations to provide evidence to authorities
- Regular audits and certifications
In intralogistics, this particularly affects companies that perform central functions in the supply chain, such as in the food, energy, or medical goods sectors. A failure in these areas can have far-reaching societal consequences, which is why the requirements are correspondingly high.
What should companies pay attention to?
- Early Analysis of Impact
Companies should assess whether they fall directly or indirectly under NIS2 or KRITIS. Future classifications should also be taken into account. Strictly speaking, this point should have been clear to the relevant companies for years. - Holistic security approach
IT security must not be viewed in isolation. Especially in intralogistics, the integration of IT and OT (Operational Technology) is crucial. - Keeping an Eye on Supply Chains
Security vulnerabilities among partners can pose significant risks. Assessing and securing the entire supply chain is essential. - Employee Awareness
Many security incidents result from human error. Training and clear guidelines are therefore a central component of any security strategy. - Continuous Improvement
Threats are constantly evolving. Companies must regularly review and adapt their measures.
Conclusion
ISO 27001, NIS2, and KRITIS, as well as the BSI Kritis Regulation, are not merely regulatory issues but key building blocks for the future viability of companies in intralogistics and intralogistics within companies. Those who act early can not only minimize risks but also gain a competitive edge. Security is increasingly becoming a decisive quality attribute—and thus a key success factor in a digitized logistics world.
If you have questions about ISO 27001 and the BSI-KritisV, or would like to learn more about other topics such as certification under BSI Basic Protection, VdS certification, TISAX certification, or the Cyber Resilience Act (CRA) — including how we handle these matters and how we support our clients to ensure they are future-proof — then simply contact us: