Procedure
Are we within the scope of NIS2?
Under section 33(1) BSIG it is the entity itself that establishes whether it is in scope, and the federal office registers of its own motion only where that duty is not met. The classification follows the activity actually carried on rather than the objects clause. The three months run from the moment an entity first or again counts as being in scope, and therefore run afresh on every change of status.
Above fifty employees, the check is missing
The undertaking manufactures machinery and is above fifty employees. Whether it is within the scope of the new BSI Act has not been examined. No notice has arrived from the federal office, and from that it is concluded that the question is answered.
No notice arrives from the federal office
What the examination sets out from is usually the expectation that the authority will approach the entities in scope. The Act reverses the order. Section 33(1) BSIG addresses the duty to register to the entity, and under section 33(3) BSIG the federal office may register an entity itself only where that duty is not met.
A scoping questionnaire is available on the pages of the federal office, and as to its weight the office says what is needed itself.
The scoping check does not replace the examination for self-identification and carries no evidential weight for any proceedings.
That leaves the entity’s own record, and section 33(4) BSIG gives it its function. Where facts justify the assumption that an entity has omitted to register, it has to produce documents and give information on request. A dated result of an examination would then be the answer to that.
The classification follows the activity, not the register
What the classification turns on is neither the objects clause nor the self-image. Annexes 1 and 2 to the BSIG each list seven sectors, and their types of entity are in many cases defined by an economic activity under the NACE Rev. 2 statistical classification. Mechanical engineering appears there as division 28 in Annex 2, and a machinery manufacturer above fifty employees would accordingly be an important entity.
Four steps to a result
Step 1
Classify the activities
Does one of the activities carried on fall under a type of entity in Annexes 1 or 2. Section 28(1) no. 4 BSIG requires in addition that goods or services be offered for consideration.
Step 2
Set aside the marginal
Under section 28(3) BSIG business activities may be disregarded which are negligible in relation to the entity’s overall business. Everything else remains in scope.
Step 3
Determine the size
Headcount, annual turnover and annual balance sheet total under section 28(1) and (2) BSIG, together with attribution within the group under subsection 4, in both directions.
Step 4
Record the result
With a date, the basis and the figures relied on, including where the result is negative. Section 33(4) BSIG may require documents to be produced.
Attribution within the group is not a matter of course
Whether the group’s figures count is either passed over or affirmed across the board, and both answers go past section 28(4) BSIG. Sentence 1 refers to Commission Recommendation 2003/361/EC and thus to attribution among partner and affiliated undertakings. Sentence 2 withdraws that attribution where the entity is independent of those undertakings as regards the design and operation of its information technology.
Three points at which a self-assessment turns
Several lines of business under one legal person
Classification is per activity and not per company. An undertaking can be in scope in one line of business and outside it in the others, and section 28(3) BSIG permits only the setting aside of what is negligible. The result would accordingly be partial scope.
A subsidiary below the threshold
It can be in scope through attribution under section 28(4) sentence 1 BSIG. Conversely attribution can fall away under sentence 2, and what matters for that is the actual independence of the systems rather than the shareholding structure.
A result from the year before last
It ages with the next acquisition and with every new activity. Section 33(1) BSIG attaches the period to first or renewed application, and the period therefore runs afresh on a change of status.
Two duties to register, and the second is overlooked
Whether the submission under section 33 BSIG settles the matter is decided by the type of entity. For the types named in section 60(1) sentence 1 BSIG, section 34(1) BSIG requires a second submission, with content of its own and its own period for changes. Managed service providers, cloud computing providers and operators of data centre services fall within it.
Two duties, two sets of content
| Section 33 BSIG | Merkmal | Section 34 BSIG |
|---|---|---|
| Every entity in scope | Whom it covers | Only the types in section 60(1) sentence 1 BSIGDNS services, cloud computing, data centre services, content delivery networks, managed service and managed security service providers, online marketplaces, search engines and social networks. |
| Name, address, sector, member states, authorities | What has to be submitted | In addition the main establishment and IP rangesThe main establishment in the Union under section 60(2) BSIG and the entity’s public IP address ranges. |
| Period under the transitional ruleSection 66 BSIG suspends the application of section 33(5) BSIG until a regulation under the KRITIS framework Act enters into force. | On a change | Without delay, at the latest three monthsSection 34(2) BSIG, counted from the day on which the change occurred. |
| To the federal office | Where the data go | On to the Union agencyUnder section 34(3) BSIG to the European Union Agency for Cybersecurity, with the exception of the IP ranges. |
The reason for the second duty is jurisdiction. Under section 60(1) BSIG the federal office is centrally competent for these types across the Union as soon as the main establishment is in Germany.
How we support you in the NIS2 assessment
The examination itself takes a few hours once the figures on the group structure are available. The effort lies in obtaining them, and it is therefore obvious to attach the examination to the annual accounts, where the same figures are assembled in any event. At the end there is a dated record, and where the result is positive, the registration.
With us the examination sits as part of the security of processing under Art. 32 GDPR. Representation before the federal office, defence in fine proceedings under section 65 BSIG and the liability of the management are legal advice outside our secondary field of law. They run through the affiliated law firm, lexICT legal Rechtsanwaltsgesellschaft.
Frequently asked questions
Will the federal office tell us if we are in scope?
Not as a first step. Section 33(1) BSIG addresses the duty to the entity, and under section 33(3) BSIG the federal office registers an entity itself only where the duty is not met. The scoping questionnaire the office provides serves, on its own account, only as guidance and does not replace self-identification.
Do affiliated undertakings count towards the thresholds?
As a starting point yes, because section 28(4) sentence 1 BSIG refers to Commission Recommendation 2003/361/EC. Sentence 2 withdraws that attribution where the entity is independent of its partner and affiliated undertakings as regards the design and operation of its information technology. The examination is therefore in two stages, and the second is frequently passed over.
The deadline has passed. What now?
The duty continues, because section 33(1) BSIG attaches to counting as an entity and not to a calendar date. A late submission is therefore called for. It remains an administrative offence under section 65(2) no. 6 BSIG, and the frame for it under section 65(5) no. 5 BSIG reaches five hundred thousand euros rather than the amounts that apply to the risk management and reporting duties.
We are in scope. Does everything then apply?
Not necessarily. Section 28(5) BSIG removes telecommunications and energy undertakings from part of the duties in so far as they are subject to rules of their own, and section 28(6) BSIG does the same for financial entities under Regulation (EU) 2022/2554 and for parts of the telematics infrastructure. The duty to register is unaffected.
What does this have to do with data protection?
The measures overlap with Art. 32 GDPR, and being in scope decides which further yardstick has to be applied. On penalties, section 65(11) BSIG draws a line. Where the data protection authority has imposed a fine for the same conduct, a further fine under the BSIG may not be imposed.
More questions from this area
Cyber Resilience Act
Under Art. 3(13) CRA a manufacturer is also anyone who has a product developed and markets it under its own name or trade mark, irrespective of payment.
Supply chain security
Section 30(2) no. 4 BSIG covers the relationships with direct suppliers and service providers and reaches no further into the chain.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.