PWR Blog

B3S Standards for Hospitals and KRITIS Explained

Written by i-doit Team | 03. September 2026

Table of contents

1 B3S: Sector-specific security standards for hospitals and other KRITIS sectors
2. What are sector-specific security standards?
3. What requirements does B3S set in detail?
4. B3S security requirements: MUST, SHOULD, CAN
5. A structured guide to B3S implementation
6. B3S is more than a legal requirement
7. Synergies between B3S and NIS-2
8. Practical example: B3S for hospitals
9. Audit-proof B3S documentation with ISMS software
10. B3S is the foundation of resilient KRITIS infrastructures

 

B3S: Sector-Specific Security Standards for Hospitals and Other KRITIS Sectors 

Critical infrastructures (KRITIS) form the backbone of our society. A failure—whether in energy supply, water management, or healthcare—usually has immediate and far-reaching consequences for public life. This is why lawmakers require KRITIS operators to prove effective IT security measures based on state-of-the-art standards ("Stand der Technik"). But what does this mean in daily operational practice?

Sector-specific security standards (B3S) bring clarity here: They translate the general requirements of Section 8a of the BSI Act (BSIG) into specific action guidelines tailored to the respective sector. Whether hospitals, energy suppliers, or water utilities: Every KRITIS sector receives a detailed guide that clearly describes technical and organizational risks and converts them into actionable requirements.

In this article, you will learn what defines a B3S standard, which specific security requirements it sets, and how the B3S implementation guide can be applied step by step and documented comprehensibly.

What are sector-specific security standards (B3S)? 

 Sector-specific security standards (B3S) are guidelines recognized by the Federal Office for Information Security (BSI) that define the implementation of IT security measures for specific KRITIS sectors. Developed by industry associations in cooperation with UP KRITIS working groups, they ensure that legal requirements are met effectively and in a sector-appropriate manner. Recognized sector-specific security standards exist for medical care (e.g., hospitals) or energy (electricity and gas supply), among others. 

 

What requirements does B3S set in detail? 

Sector-specific security standards are based on established frameworks such as ISO 27001 and BSI IT-Grundschutz, covering all areas of an Information Security Management System (ISMS).

Key requirement areas of a B3S standard:

  • Risk analysis and management: Systematic identification and assessment of threats to IT and OT systems.

  • Determination of protection requirements: Classification of systems based on their criticality. Control systems, water treatment plants, or the HIS (Hospital Information System) in a hospital require a higher level of protection according to B3S than administrative back-office systems.

  • Technical and organizational measures (TOMs): Specific guidelines for implementation, including network segmentation, systems for attack detection (SzA), patch management, and incident response processes.

  • Documentation and proof of compliance: Seamless and traceable documentation of all measures as a basis for internal and external audits.

  • Continuous improvement process (CIP): PDCA cycle (Plan-Do-Check-Act) to regularly review and adjust the effectiveness of security measures.

 

B3S security requirements: MUST, SHOULD, CAN 

B3S standards classify their requirements into three levels of obligation:

  • MUST requirements: Mandatory. Examples: Designating a BSI contact point, conducting regular risk analyses, using systems for attack detection.

  • SHOULD requirements: Strongly recommended. A deviation is only permissible if it can be comprehensibly justified through a risk analysis.

  • CAN requirements: Optional. Serve to provide additional protection for systems with particularly high protection needs.

This gradation allows for a pragmatic, risk-oriented prioritization and scalability.

 

A structured guide to B3S implementation 

Implementing a sector-specific security standard follows a clear roadmap:

  1. Define scope: Precisely determine which systems, processes, and locations are relevant to critical service delivery.

  2. Asset inventory (Asset Management): Record all IT assets, OT systems, applications, and interfaces in a central CMDB (Configuration Management Database).

  3. Conduct risk analysis: Identify threats, assess vulnerabilities, and prioritize measures based on real-world risk.

  4. Plan and implement measures: Create an implementation plan for technical solutions (e.g., firewalls, IDS/IPS) and organizational processes (e.g., emergency plans, awareness training).

  5. Ensure documentation: Establish audit-proof documentation of all analyses, decisions, and implemented measures.

  6. Prepare for audit: Proof of implementation must be provided no later than two years after determining that the threshold has been exceeded.

B3S is more than a legal requirement 

The implementation of sector-specific security standards is a legal mandate for KRITIS operators. However, viewing them merely as a top-down regulatory directive misses their strategic potential. A systematic approach to IT security protects you from the severe consequences of system outages while creating real business value.

For KRITIS operators, B3S standards offer concrete benefits:

  • Compliance fulfillment: They provide a recognized framework to demonstrate compliance with legal obligations under Section 8a BSIG.

  • Practical relevance over theory: Unlike generic frameworks, B3S standards address real-world environments, from OT process control in power plants to patient data management in hospitals.

  • Preparation for NIS-2: A compliant B3S implementation already covers a large portion of the stricter requirements of the NIS-2 Directive, giving you a strategic head start.

  • Legal certainty during audits: Recognition by the BSI creates a reliable basis for audits and minimizes room for interpretation.

The modular structure of MUST, SHOULD, and CAN requirements also allows for risk-based and efficient prioritization of measures.

 

Synergies between B3S and NIS-2 

The NIS-2 Directive, anchored and in force in German law since December 6, 2025 as the "NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG)", significantly tightens security requirements for operators of critical facilities. Those who are already implementing a B3S have a clear advantage, as the requirements overlap to a large extent.

Common core requirements of B3S and NIS-2:

  • Risk-based security management
  • Incident response processes and reporting obligations
  • Supply chain security
  • Business continuity and emergency management
  • Regular security reviews and audits

An implemented B3S standard forms a solid foundation for NIS-2 compliance. Nevertheless, analyze the deltas, particularly regarding expanded reporting duties and stricter executive management liability.

 

Praxisbeispiel: B3S für Krankenhäuser

The B3S for hospitals (officially: B3S for medical care) is a prime example of sector-specific orientation. Developed in close cooperation with the German Hospital Federation (DKG), it addresses the unique challenges in healthcare.

Key features in the medical sector:

  • Patient safety as the top priority: Here, IT security is directly tied to protecting human lives. Emergency rooms, intensive care units, and operating rooms have the highest protection requirements.

  • Heterogeneous system landscapes: The B3S standard provides clear guidelines for handling complex environments consisting of HIS, PDMS, medical technology, and administrative systems.

  • Integration of medical technology: The B3S for hospitals specifically focuses on the IT processes and interfaces of medical devices.

  • Current version 1.3.1: The version published in November 2025 integrates the requirements of the BSI's Maturity and Implementation Level Assessment (RUN).

 

Audit-proof B3S documentation with INDITOR® ISO 

Implementing a B3S requires seamless, structured, and traceable documentation. Manual processes using office documents are error-prone and no longer contemporary in complex KRITIS environments.

With INDITOR® ISO, i-doit offers a specialized ISMS software solution that enables users to implement the B3S for hospitals independently and in a structured manner. The ISMS software specifically supports organizations in implementing sector-specific security standards.

These are the key benefits of INDITOR® ISO:

  • Sector-specific support: The B3S catalog is integrated directly into the software and provides a clear procedure, for example for hospitals.

  • Integrated risk management: Perform risk analyses, evaluations, and treatments directly on affected assets.

  • Traceable implementation: Document all B3S requirements (MUST, SHOULD, CAN) with clear responsibilities and status tracking.

  • Audit-proof archiving: Complete audit trail and automated reports for internal and external audits.

Central data maintenance eliminates redundancies and saves valuable time when preparing for BSI audits.

 

B3S  is the foundation of resilient KRITIS infrastructures 

Sector-specific security standards serve as a practical guide for building a robust and future-proof IT security strategy. KRITIS operators who consistently implement a B3S standard not only increase the resilience of their own systems, but also make an active contribution to public safety.

A clearly defined B3S process ensures transparency and legal certainty. With suitable software support, implementation evolves from a mandatory obligation into a true competitive advantage. In light of growing cyber threats and new regulations such as NIS-2 or the KRITIS Umbrella Act (KRITIS-Dachgesetz), an established B3S standard becomes a core building block for your organization's long-term stability and future viability.

Looking to introduce a B3S in your organization and searching for software that reliably accompanies you from risk analysis to audit? Then INDITOR® ISO is worth a closer look.