DevSecOps · KRITIS · BSI · NIS2
Compliance created in the pipeline — not in a binder.
KRITIS operators and companies affected by NIS2 must demonstrate state-of-the-art security. We build that evidence directly into your CI/CD: SBOM, CVE governance, SAST/DAST and complete audit trails — automated instead of manually compiled.
Scope of services
Security building blocks for your CI/CD
Each building block automatically produces the evidence auditors want to see — as a by-product of normal development work.
SBOM-Generierung
Automated software bills of materials (CycloneDX, SPDX) for every build version: your own code, open-source dependencies, container images. The basis of any supply-chain statement.
CVE-Governance
Continuous matching of your SBOMs against vulnerability databases, prioritisation by reachability and criticality, documented treatment decisions.
SAST & DAST
Static and dynamic security analysis as pipeline stages: fast checks in the pull request, deep scans nightly — findings directly in the developers' workflow.
Audit trails & evidence
Who deployed, reviewed and approved what, and when? Complete, tamper-proof change histories for BSI audits and § 8a evidence reviews.
Secrets & access management
No credentials in pipelines or repos: vault integration, service connections with minimal rights, regular rotation — verifiably implemented.
Compliance-Mapping
We translate BSI Grundschutz modules, KRITIS and NIS2 requirements into concrete technical measures in your toolchain — including documentation for the audit.
Auditors want evidence. Developers want to ship. A good pipeline delivers both.
The classic approach — spreadsheets, manually maintained evidence documents, security reviews right before the audit — doesn't scale and is always outdated. Our approach: every merge, every build, every deployment produces its own compliance artifacts. The audit becomes a query instead of archaeology. And your developers barely notice — except that findings arrive earlier, when they're still cheap to fix.
FAQ
Frequently asked questions about DevSecOps & KRITIS
What does KRITIS mean for our software development in concrete terms?
As a KRITIS operator you must demonstrate appropriate organisational and technical measures in line with the state of the art under § 8a BSIG. For software development this means: traceable build and deployment processes, controlled software supply chains (SBOM), vulnerability management (CVE) and auditable change histories. These are exactly the artifacts we generate directly in your CI/CD pipeline.
What does NIS2 change compared to existing KRITIS obligations?
NIS2 significantly widens the circle of affected companies and tightens requirements for risk management, supply chain security and reporting obligations. Companies that previously did not fall under KRITIS will also have to demonstrate security measures in their software supply chain. A pipeline with SBOM generation and CVE governance is a solid technical foundation for that.
Does DevSecOps slow our developers down?
Not if it's built right. Our security checks run parallelised and incrementally: fast checks in the pull request, deep scans nightly. Developers get findings where they work — in the PR, not in a PDF report weeks later. In practice teams get faster, because security issues are fixed earlier and more cheaply.
What is an SBOM and why do we need one?
An SBOM (Software Bill of Materials) is a machine-readable parts list of all components of your software — your own code, open-source packages, container base images. It's the prerequisite for knowing immediately whether and where you are affected when new vulnerabilities (CVEs) appear. We generate SBOMs automatically in the build (CycloneDX/SPDX) and link them to continuous CVE matching.
Does this also work in environments without internet access?
Yes — that's one of our specialities. SBOM generation, CVE databases and scanning tools can be operated in air-gapped networks using controlled offline replication paths. Details on the page air-gapped & VLAN environments.
Next step
Where does your pipeline stand today?
In a free initial call we assess which KRITIS/NIS2 requirements your toolchain already meets — and where the critical gaps are.
info@xeam-solutions.com