(1) Federal administration entities within the meaning of this Act are, with the exception of social security institutions and the Deutsche Bundesbank, 1. federal authorities, 2. IT service providers of the federal administration organised under public law, and 3. further corporate bodies, institutions and foundations under public law and their associations, regardless of their legal form, at federal level, insofar as ordered by the BSI in agreement with the respective competent department.
(2) The provisions for essential entities apply to federal administration entities, but not the provisions of sections 38, 40(3), and sections 61 and 65.
(3) The portfolios of the Federal Foreign Office and the Federal Ministry of Defence, as well as the Federal Intelligence Service and the Federal Office for the Protection of the Constitution, are, in addition to the provisions under subsection (2), exempt from the provisions of section 7(5), fourth sentence, sections 10, 13(1), first sentence, no. 1(e), and sections 30, 33 and 35. The Federal Foreign Office issues, in agreement with the Federal Ministry for Digital Affairs and State Modernisation, a general administrative provision to implement the objectives of the NIS 2 Directive within the portfolio of the Federal Foreign Office through measures of equivalent outcome.
Home› Cybersecurity & IT Security› BSIG-EN
Part 3 · IT Security of Entities › Chapter 1 · Scope of Application › Section 29
Federal administration entities
←→ also move between sections