
KRITIS Experts in Düsseldorf
in minutes from over 15,000 CVs with the power of AIHire experts who know KRITIS reporting, security controls, and documentation for critical services. They support audits, incident readiness, and gap analysis across regulated environments with fast, precise matching to vetted, available freelancers.
Meet FRATCH Experts in Düsseldorf, who have recently used KRITIS
Marcus W.
Last position:
CIO (ad interim) at Bartec Group
- Responsible for infrastructure, operations, network and VoIP, security, quality assurance, as well as asset management and business continuity
- Planning and implementation of all requirements related to NIS 2.0
- Responsible for application development
- Company-wide implementation of SAP S/4Hana and leading development of new business processes, incl. cut-over planning
- Digital transformation and cultural transformation toward a "doer mentality"
- Realignment of infrastructure (hybrid)
- Restructuring of the organization with partial outsourcing
- Management of four direct reports with a total of 25 internal and external employees
- Budget responsibility of up to €25 million
Alicja W.
Last position:
Integrated Security and Emergency Documentation for a 24/7 Logistics Company at Medium-Sized Logistics Company
- Creation of complete bilingual (DE/EN) security and emergency documentation: Business Continuity Plan / Disaster Recovery Plan, Incident Response Plan v2.0 with four case-specific playbooks (PICERL), Access Control Policy, Vulnerability Management Policy, Business Resilience Programme, Risk Governance Plan
- Consolidation into an integrated emergency manual (12 chapters) with immediate-action checklists for six emergency scenarios, a prioritized action table and a formal approval structure
- Review and documentation of the applicability of NIS2 and HinSchG, including the legal justification for non-applicability
Federico L.
Last position:
Senior IAM Manager & Single Point of Contact for Information Security at EnBW Energie Baden-Württemberg AG
As the only large integrated energy company in Germany, EnBW covers the entire value chain - from energy production through distribution to customers. It expands its renewable energy sources, advocates for a socially responsible coal exit, and drives key technologies like green hydrogen. A rapid energy transition and achieving climate neutrality by 2035 are priorities for EnBW. Developed and implemented a holistic process view covering both technical and organizational aspects Ensured end-to-end control of all IAM-related technical services Established clear responsibilities and accountabilities within the IAM landscape Collaborated with different departments to identify and optimize a holistic architecture and act as Single Point of Contact (SPoC) for Information Security Introduced and monitored governance policies to ensure compliance and security Continuously improved IAM processes and systems through regular audits and evaluations Participated in external audits of the process as part of official ISO audits Further developed the policy for setting administrative requirements and procedures and aligned it with administrative units Conceptually advanced the KPI system to measure process quality
Ralph K.
Last position:
Product Owner / Business Owner at AXIS Management Consulting GmbH
- Full product responsibility from a business perspective: requirement analysis, UX design, product strategy, and go-to-market implemented without an internal dev team using fully AI-supported development (Claude Code / Anthropic)
- Technical differentiation: KRITIS-compliant air-gapped deployment (Windows/NSIS), GDT interface for PVS integration, DATEV-LODAS export for payroll
- Managed pilot operation with initial external client (Dormagen medical practice): structured requirement gathering, test support, error analysis, and release management
- Developed rollout and sales strategy for market entry in the segment of private practices and small medical centers
- Human-in-the-Loop development principle: business decision → AI implementation → manual review → approval → release – each sprint documented in Jira (TIME project), every change traceable via co-authored commits
- Product outcome: Tauri/Rust desktop app with GDT watcher, multi-tier model (Starter/Professional/Enterprise), cloud mirror on Hetzner/Traefik, complete ISMS framework based on ISO 27001 and BSI basic protection as product foundation
- Direct method validation for the test manager role: hands-on experience with quality assurance of AI-generated products from a user perspective, review gate discipline, release approval under GDPR and the EU AI Act
Nikolaus B.
Last position:
ICT Risk Management and Information Security at B. Metzler seel. Sohn & Co. AG
- Independently develop policies, guidelines, and frameworks for ICT risk management and information security
- Advise business units on ICT risk management and information security
- Further develop the ICT risk management framework that governs the identification, assessment, and control of ICT risks
- Evaluate the Information Security Management System (ISMS) and adjust it for new challenges
- Conduct risk analyses to identify and assess potential ICT risks and information security risks for the Metzler Group
- Advise on defining and implementing measures to reduce risks and improve the resilience of ICT systems
- Advise on ensuring compliance with relevant internal and external regulatory requirements (MaRisk, DORA, BAIT, BSI IT baseline protection, ISMS, ISO 27001, ISO 42001, ISO 27005, BCM ISO 22301)
- Advise on internal and cross-functional projects (SAP DORA compliance, Target2, Section 8a BSI Act)
Bernhard D.
Last position:
Enterprise Architect. And responsible for the cross-functional architecture as well as all domains with a focus on the sales at Süddeutsche Krankenversicherung
Creation of business and technical concepts as well as support for enterprise architecture management as part of the migration to the Adesso standard insurance solutions and the renewal of surrounding systems
Interface definitions
Business analysis and creation of the business concepts for input management and sales
Creation of architecture guidelines and processes
Processing technical and business decisions in the architecture board
Definition of service processes and system management aspects
Creation of the technical target operating model
Creation of an integration architecture for AI/LLMs from the providers Commasoft and Insiders
CommaSoft (Alan) webpages and web services
Insiders for Smartfix based on web services
Creation of a question catalog for a security/regulatory check.
Analysis of threats using threat modeling / STRIDE incl. creation of a set of measures to secure the systems
System environment: Jira, Confluence, Java, Enterprise Architect, VAIT/DORA, KritisV, GDPR, IT ServiceMgmt, Adesso Ecosphere and Insure Health, DoPIX and successor product, SmartFix, SmartFlow, Zabas, Kolumbus, Clarc archive, BiPRO, AI / LLM, MS Azure, AWS, TOM/FMO
Discover over 15,000 top freelancers
Statistics of experts using KRITIS
Aggregated from the professional profiles of matched freelancers.
Experience
22 years (Germany: 23 years)

Position duration
0.8 years (Germany: 2.2 years)

Positions per freelancer
17 (Germany: 18)

Top business areas
Information Technology, Project Management, Operations

Top industries
Information Technology, Healthcare, Government and Administration

Certification focus areas
Information Technology, Project Management, Audit
Bachelor's degree or higher
100% (Germany: 89%)
Master's degree or higher
75% (Germany: 47%)

Certifications per freelancer
5 (Germany: 8)

Most common languages
German, English, Spanish

Speak two or more languages
83% (Germany: 94%)
Based on our profile pool as of 19 Sep 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Düsseldorf are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Düsseldorf using KRITIS
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
KRITIS experts industry focus
See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.
- Information Technology (100%)
- Healthcare (83%)
- Government and Administration (83%)
- Banking and Finance (67%)
- Insurance (67%)
- Manufacturing (67%)
- Retail (67%)
- Energy (50%)
Please note that freelancers can work across multiple industries, so percentages overlap.
About the technology
What KRITIS means
KRITIS stands for critical infrastructure in Germany. It covers systems and services whose failure would seriously affect supply, safety, or public life. Companies search for KRITIS, Kritische Infrastrukturen, or critical infrastructure when they need clear security work and solid evidence.
Typical work
- Scope systems and services that fall under KRITIS rules
- Review security controls, policies, and technical measures
- Prepare evidence for audits, reviews, and internal checks
- Support incident handling and reporting workflows
Skills around it
Strong professionals know risk analysis, asset mapping, access control, logging, backup, and supplier governance. They also understand how technical, organisational, and documentation tasks connect. In Düsseldorf, they often work with teams in industry, logistics, energy, and regulated services.
When companies call in help
Companies bring in freelance expertise when a deadline is close, a control gap appears, or an internal team needs extra capacity. KRITIS work often spans security, legal, operations, and compliance, so outside specialists help align the moving parts. Remote work fits many tasks, while site visits help where plant, network, or facility details matter.
Ecosystem and scope
The work often touches policies, asset inventories, monitoring, emergency concepts, and supplier assessments. It can also connect to broader security topics such as ISO 27001, NIS2, and sector-specific requirements. A good expert keeps the scope practical and ties each measure back to the critical service.
What strong specialists deliver
Strong KRITIS specialists write clearly, document decisions, and translate requirements into workable actions. They can challenge weak assumptions, spot missing evidence, and keep teams focused on what matters for resilience. Searchers may also use the term Kritische Infrastrukturen when looking for the same expertise.
Frequently asked questions
Quick answers to the questions that come up most around KRITIS.
KRITIS is used to describe the security and resilience work around critical infrastructure in Germany. It helps companies identify protected services, manage risks, and prepare the evidence needed for audits, reviews, and incident handling. The work is as much about documentation and coordination as it is about technical controls.
KRITIS is the common German abbreviation for critical infrastructure, and Kritische Infrastrukturen is the full German term. In practice, people use these terms when they mean the same regulated environment and the same security expectations. Searchers may also use them when they are looking for experts who know the German framework.
A strong KRITIS specialist should understand risk analysis, asset inventories, access control, logging, backup, and supplier governance. They should also be able to write clear documentation and work across security, operations, and compliance. Experience with ISO 27001 or NIS2 is often useful because the topics overlap.
KRITIS work is broader than standard security hardening because it must fit a regulated critical service. A general security expert may know the controls, but a KRITIS specialist knows how to connect them to evidence, responsibilities, and audit-ready documentation. That is important when the organization has to prove resilience, not just improve it.
A KRITIS project usually needs someone who has already handled regulated environments, not someone learning the basics on the fly. The exact setup depends on whether you need gap analysis, documentation, control design, or incident readiness. Complex scopes often benefit from a specialist who has worked with both technical teams and compliance stakeholders.
Yes, much of KRITIS work can be done remotely from Düsseldorf, especially reviews, documentation, workshops, and preparation work. On-site time becomes important when the task depends on plant access, network topology, physical security, or local operational details. Many companies use a mixed setup.
Look for a KRITIS expert who explains requirements in plain language and ties every recommendation to a concrete risk or control. Good signs are clean documentation, structured gap analysis, and clear priorities for what to fix first. Ask for examples of how they handled audits, incident readiness, or cross-team coordination.
A KRITIS engagement often ends with gap assessments, control lists, policy updates, risk notes, and an action plan. Depending on the scope, you may also get evidence packs, incident procedures, supplier reviews, or workshop results. The best specialists make the deliverables usable for both technical teams and management.
The average hourly rate of freelancers in Dusseldorf, Germany who have used KRITIS in their recent projects is 124 €, which corresponds to a daily rate of about 989 € based on an 8-hour working day.
Of the freelancers in Dusseldorf, Germany who have used KRITIS in their recent projects, 100% hold at least a Bachelor's degree and 75% hold at least a Master's degree.
On average, freelancers in Dusseldorf, Germany who have used KRITIS in their recent projects have 22 years of professional experience, with a single engagement typically lasting around 0.8 years.
The most common languages among freelancers in Dusseldorf, Germany who have used KRITIS in their recent projects are German (100%), English (83%), and Spanish (50%).
The most common industries among freelancers in Dusseldorf, Germany who have used KRITIS in their recent projects are Information Technology (100%), Healthcare (83%), and Government and Administration (83%).
The most common business areas among freelancers in Dusseldorf, Germany who have used KRITIS in their recent projects are Information Technology (100%), Project Management (100%), and Operations (83%).
Main locations of FRATCH Experts, who have recently used KRITIS
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Munich
Frankfurt