Procedure
Implementing NIS2
The ten subjects in section 30(2) BSIG are the minimum scope, and their depth is measured by the five factors in section 30(1) sentence 2 BSIG. Under section 38(1) BSIG the management has to implement the measures and supervise their implementation, while damages under section 38(2) BSIG follow company law. The reporting periods in section 32 BSIG run alongside those in Art. 33 GDPR and attach to a different concept.
The list is there, the depth is not
The registration is done and the list of measures is to hand. It has ten items, the first suggestion is to work through it from top to bottom, and nobody knows how deep each individual item has to go.
Ten subjects, and the depth is not in the list
What the scope of the measures depends on the list does not itself say. Section 30(1) sentence 1 BSIG requires appropriate, proportionate and effective measures, and sentence 2 names five factors for proportionality, namely the extent of exposure to risk, the size of the entity, the cost of implementation and the likelihood and severity of incidents together with their effects. The ten subjects in subsection 2 are accordingly the minimum scope and not the measure.
The ten subjects in four groups
What settles the approach
No. 1 requires policies on risk analysis and on information security, no. 6 policies and procedures to assess the effectiveness of the measures. The second is the more demanding, because it calls for a statement about effect and not about existence.
What operates during an incident
No. 2 concerns incident handling, no. 3 business continuity with backup, recovery and crisis management. The ability to report hangs here, because a period of 24 hours presupposes a named responsibility.
What comes in from outside
No. 4 names supply chain security including the relationships with direct suppliers, no. 5 security in acquisition, development and maintenance together with vulnerability handling. Both look outwards and are worked on last.
What reaches the workplace
No. 7 requires basic training, no. 8 policies on cryptography, no. 9 policies on human resources security and access control, and no. 10 multi-factor authentication and secured communication. These four are visible at the workplace.
Under section 30(1) sentence 3 BSIG compliance has to be documented. The documentation is therefore a duty of its own and not merely a means of evidencing another one.
The management implements, and its liability sits in company law
What the management owes is frequently read as approval. Section 38(1) BSIG requires more, namely the implementation of the measures and the supervision of their implementation. Under subsection 3 there is in addition a duty to attend training regularly, and since management is a natural person under section 2 no. 13 BSIG, that is addressed to individuals and not to a body.
In practice it follows that attendance at the training should be capable of proof. Section 61(1) BSIG covers section 38(3) BSIG expressly, and an audit that is ordered asks about it.
Two clocks, and they do not measure the same thing
Which report falls due when turns on a concept that is not congruent with the one in data protection law. Section 32(1) BSIG attaches to the significant incident under section 2 no. 11 BSIG, Art. 33(1) GDPR to the personal data breach under Art. 4(12) GDPR. Neither of the two concepts includes the other.
Four reports to the federal office
24 hours
Early warning
Under section 32(1) no. 1 BSIG, stating whether there is a suspicion of unlawful or malicious acts or whether cross-border effects are possible.
72 hours
Report with an initial assessment
Under section 32(1) no. 2 BSIG, confirming or updating, with the severity, the effects and where applicable the indicators of compromise.
On request
Intermediate report
Under section 32(1) no. 3 BSIG on relevant status updates. It falls due only where the federal office asks for it.
One month
Final report
Under section 32(1) no. 4 BSIG with a description, the cause and the remedial measures. Where the incident is ongoing, subsection 2 puts a progress report in its place.
One incident, two reporting chains
| Section 32 BSIG | Merkmal | Art. 33 GDPR |
|---|---|---|
| Significant incidentUnder section 2 no. 11 BSIG serious operational disruption or financial loss, or considerable harm to others. A link to personal data is not required. | Trigger | Personal data breachUnder Art. 4(12) GDPR destruction, loss, alteration, unauthorised disclosure of or access to personal data. Operational disruption is not required. |
| 24 hours | First period | 72 hoursWithout undue delay and where feasible within 72 hours of becoming aware. |
| The joint federal reporting point | Recipient | The competent data protection authority |
| Final report after one month | Final stage | Documentation and where applicable communication |
An encryption attack on a production line without any link to personal data triggers the left-hand chain alone, a misdirected personnel list the right-hand one alone. Both chains run together frequently, but not always.
Under section 32(1) sentence 2 BSIG the duty exists at the earliest once the reporting channel is set up. The federal office accepts reports through its portal and provides a form there for entities that are not registered.
How we support you with NIS2 implementation
The shortest route begins not with the risk analysis but with the ability to report. Who detects, who decides and who reports can be settled in a morning, and without that settlement a period of 24 hours cannot be met. After it comes the delimitation of the scope, that is, which systems concern the service in question, because without it the effort becomes unbounded.
The measures under section 30 BSIG overlap largely with those under Art. 32 GDPR, and the assessment of effectiveness appears in both provisions. A measure is therefore implemented once and evidenced twice. Construing the BSIG in a dispute with the federal office, defence in fine proceedings and the liability of the management under company law are legal advice outside our secondary field of law. They run through the affiliated law firm, lexICT legal Rechtsanwaltsgesellschaft.
Frequently asked questions
When do the 24 hours begin?
On becoming aware of the significant incident and not on clarifying it. At that point section 32(1) no. 1 BSIG requires only the statement whether there is a suspicion of unlawful or malicious acts or whether cross-border effects are possible. The assessment follows with the report after 72 hours.
Is the management personally liable under the BSIG?
As a rule not under the BSIG. Section 38(2) sentence 1 BSIG refers to company law, and under sentence 2 liability under the BSIG applies only where company law contains no rule. For a GmbH it sits in section 43 GmbHG and for a stock corporation in section 93 AktG. What is new is therefore not the liability but the standard of duty against which it is measured.
Do we have to prove implementation to the federal office?
Not from the outset. Section 30(1) sentence 3 BSIG requires documentation, and a recurring proof every three years falls under section 39 BSIG on operators of critical installations alone. Under section 61 BSIG the federal office may order audits against individual particularly important entities and, against the remaining ones, require proof at the earliest three years after entry into force. For important entities section 62 BSIG requires facts justifying the assumption of a breach.
Do we have to inform our customers?
On being ordered to. Under section 35(1) BSIG the federal office may order the recipients of the services to be informed, and publication on the entity's own website suffices for that. For certain sectors subsection 2 adds a duty to communicate on significant cyber threats, which depends on a balancing of interests.
More questions from this area
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.