Field of law
Information security
Information security law consists of a multitude of separate rules. Art. 32 GDPR alone reaches everyone who processes personal data. The others attach to sector and size, to a critical installation or to the manufacturer role. None of them names a measure, because all four require appropriateness and the state of the art. Standards such as ISO 27001 and the German IT-Grundschutz fill that gap without being binding themselves.
What decides which of them applies to you
Where to begin turns on which of the rules applies at all. Three of them attach to a characteristic, namely sector and size, an installation, or a role in the market. The rules do not exclude one another as a matter of principle.
What applies to your business?
Select as many as apply. The assignment follows from the statutes and does not replace an examination of the individual case.
This applies to us
Then this binds you(0 von 4)
Select on the left what applies to your business.
Security of processingArt. 32 GDPR
Binds every controller and every processor, irrespective of sector and size. The only binding rule without a precondition.
Triggered by: We process personal data
Risk management and reporting dutiesSection 30 BSIG
Binds the entities in section 28 BSIG. Whether an entity is among them is decided by the activity actually carried on together with headcount, turnover and balance sheet total. That is established by the entity itself.
Triggered by: We operate in one of the sectors listed in the annexes to the BSIG and have at least 50 employees, We operate a critical installation
Product requirements and vulnerability reportingArt. 13 CRA
Binds manufacturers of products with digital elements. Under Art. 3(13) CRA a manufacturer is also anyone who has a product developed and markets it under their own name. The reporting duty in Art. 14 CRA already applies, the product requirements from 11.12.2027.
Triggered by: We place software or connected devices on the market under our own name
Physical resilienceSection 13 KRITISDachG
Binds operators of critical installations and concerns not cybersecurity but physical protection, access control and emergency power. The clock has not started there, because the implementing regulation is still outstanding under section 8(8) KRITISDachG.
Triggered by: We operate a critical installation
Information security law is technology neutral
What a concrete technical implementation has to look like appears in no statute, and that is deliberate, because a provision naming a key length would age with the next attack.
Three yardsticks, not one measure
| Merkmal | Art. 32(1) GDPR | Section 30(1) BSIG | Section 13(2) KRITISDachG |
|---|---|---|---|
| What is required | A level of security appropriate to the risk | Appropriate, proportionate and effective measures | Proportionate technical, security-related and organisational measures |
| What it is measured by | State of the art, cost, nature and purpose of the processing, risk | Exposure to risk, size, cost of implementation, likelihood and severity | Means-end relation, effort against risk, capability |
| What is not in it | A single concrete measure | Ten subjects, but no measure | Examples, but no requirement |
The third row is the same for all three. What is required is a procedure, and what follows from it is decided by the individual case.
The gap is filled by standards such as the German IT-Grundschutz and ISO 27001, whose legal rank is regularly overestimated. Under section 30(2) sentence 1 BSIG they are to be taken into account and not complied with, and under Art. 32(3) GDPR a certification is a factor in demonstrating compliance. Binding force would follow only from a confirmation of suitability under section 30(8) BSIG. According to the federal office’s overview none has been confirmed under the new law so far.
A management system shortens the implementation considerably, because risk analysis, effectiveness review and documentation are already in place. What follows from the statute and not from the technology it does not cover, namely registration, reporting channels and management duties.
Practical questions on this
Scope and addressees
Checking whether NIS2 applies
Under section 33(1) BSIG it is the entity itself that establishes whether it is in scope, and the federal office registers of its own motion only where that duty is not met.
Cyber Resilience Act
Under Art. 3(13) CRA a manufacturer is also anyone who has a product developed and markets it under its own name or trade mark, irrespective of payment.
Supply chain security
Section 30(2) no. 4 BSIG covers the relationships with direct suppliers and service providers and reaches no further into the chain.
Implementation and evidence
Technical and organisational measures
Art. 32 GDPR requires a level of security appropriate to the risk and names criteria rather than a list.
Implementing NIS2
The ten subjects in section 30(2) BSIG are the minimum scope, and their depth is measured by the five factors in section 30(1) sentence 2 BSIG.
SOC and SIEM
A system for evaluating security events processes large volumes of data about the conduct of staff, as a side effect of its purpose.
Frequently asked questions
Is certification to ISO 27001 enough?
As evidence it helps, as compliance it does not suffice. Art. 32(3) GDPR names an approved certification mechanism expressly as a factor and not as compliance, and section 30(2) sentence 1 BSIG requires the relevant standards to be taken into account. On top of that the scope of a certificate is self-chosen, and registration, reporting channels and management duties do not appear in it at all.
What separates the IT-Grundschutz from ISO 27001?
The shape of the work. The Grundschutz supplies modules with requirements already written out, from which a selection is made. ISO 27001 describes a management system and leaves the derivation of measures to the risk treatment. For a business without a security team of its own the first route is usually shorter, for one operating internationally the second.
Is there a recognised sector standard?
Under section 30(8) BSIG industry associations may propose security standards whose suitability the federal office confirms on application. According to its own overview none has been confirmed under the new law so far. The thirteen published standards come from the former section 8a BSIG.
We are a critical installation. What applies in addition?
Alongside cybersecurity under the BSIG, physical resilience under the KRITIS framework Act, that is, physical protection, access control, emergency power and a resilience plan filed with the Federal Office of Civil Protection. The clock has not started there, because under section 8(8) KRITISDachG the registration procedure is only set once the implementing regulation is in force, and that is still outstanding.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.