(1) The BSI promotes IT security. To that end it performs the following important tasks in the public interest: 1. averting dangers to the IT security of the Federation; 2. collecting and evaluating information on security risks and security precautions, and making the findings obtained available to other bodies insofar as necessary for the performance of their tasks, and to third parties insofar as necessary to safeguard their security interests; 3. performing tasks in the Cooperation Group and in the CSIRTs network under Articles 14 and 15 of the NIS 2 Directive; 4. investigating security risks in the application of information technology and the development of security precautions, in particular of information technology procedures and devices for IT security (IT security products), insofar as necessary for the performance of federal tasks, including research within the framework of its statutory tasks; 5. developing criteria, procedures and tools for examining and assessing the security of information technology systems or components and for examining and assessing conformity in the field of IT security; 6. carrying out peer reviews under Article 19 of the NIS 2 Directive; 7. determining, in agreement with the respective operators, security requirements for the communications infrastructure of the cross-departmental communications networks and of other governmental communications infrastructures of the Federation, and reviewing compliance with those security requirements; 8. examining and assessing the security of information technology systems or components, and issuing security certificates; 9. performing the tasks and powers under Article 58(7) and (8) of Regulation (EU) 2019/881 as the national cybersecurity certification authority; 10. examining and confirming the conformity, in the field of IT security, of information technology systems and components with the BSI's technical guidelines; 11. examining, assessing and approving information technology systems or components intended for use in processing officially classified information under section 4 of the Security Clearance Act within the federal sphere or by undertakings in connection with federal contracts; 12. producing key data and operating cryptographic and security management systems for information-securing systems of the Federation, which are used in the field of state secrecy protection or, at the request of the authority concerned, also in other fields; 13. supporting and advising on organisational and technical security measures, and carrying out technical examinations for the protection of officially classified information under section 4 of the Security Clearance Act against unauthorised access; 14. developing security-related requirements for the information technology of the Federation to be used, and for the suitability of contractors, in the field of federal information technology with special protection needs; 15. providing IT security products and IT security services for federal administration entities; 16. supporting the bodies of the Federation competent for IT security, in particular insofar as they perform advisory or oversight tasks; this applies primarily to the Federal Commissioner for Data Protection and Freedom of Information, whose support takes place within the framework of the independence to which they are entitled in performing their tasks under Regulation (EU) 2016/679 and the Federal Data Protection Act; 17. advising and supporting federal administration entities on questions of information security, including the handling of security incidents, and providing concrete, practice-oriented tools for implementing information security requirements, in particular for implementing the requirements under sections 30 and 44; 18. supporting a) the police forces and prosecuting authorities of the Federation and of the Länder in performing their statutory tasks, b) the authorities for the protection of the constitution of the Federation and of the Länder and the Military Counter-Intelligence Service in evaluating and assessing information obtained through the observation of activities directed against the free democratic basic order, the existence of the state, or the security of the Federation or of a Land, or obtained through the observation of security-endangering or intelligence activities within the framework of the statutory powers under the constitutional protection statutes of the Federation and of the Länder, or the Military Counter-Intelligence Service Act, c) the Federal Intelligence Service in performing its statutory tasks; support may be granted only insofar as necessary to prevent or investigate activities directed against IT security or carried out using information technology; the BSI must keep a record of requests for support; 19. supporting the competent bodies of the Länder, at their request, on questions of averting dangers to IT security; 20. advising, informing and warning federal administration entities, the Länder, and manufacturers, distributors and users on questions of IT security, in particular having regard to the possible consequences of missing or inadequate security precautions; 21. consumer protection and consumer information in the field of IT security, in particular advising and warning consumers on questions of IT security, having regard to the possible consequences of missing or inadequate security precautions; 22. establishing suitable communication structures for early crisis detection, crisis response and crisis management, and coordinating cooperation with the private sector to protect the IT security of critical facilities; 23. performing tasks as the central body in the field of IT security with regard to cooperation with competent bodies abroad, without prejudice to the particular competences of other bodies; 24. performing the tasks under section 40 as the central body for the IT security of essential entities and important entities, including requesting and providing mutual assistance under Article 37 of the NIS 2 Directive; 25. supporting the restoration of the security or functionality of information technology systems in exceptional cases under section 11; 26. developing recommendations for identification and authentication procedures and assessing those procedures with regard to information security; 27. describing and publishing the state of the art of security-related requirements for IT products, having regard to existing norms and standards and involving the trade associations concerned; 28. cooperating with, and supporting, national computer emergency response teams of third countries or equivalent bodies of third countries; the BSI's deployments in third countries may not take place against the will of the state on whose territory the measure is to take place; the decision on a deployment of the BSI in third countries is taken by the Federal Ministry of the Interior in agreement with the Federal Foreign Office; 29. cooperating and exchanging information with the Federal Financial Supervisory Authority, insofar as necessary for performing their respective tasks, in particular with regard to measures taken under Regulation (EU) 2022/2554; the Federal Financial Supervisory Authority transmits to the BSI the information necessary for the performance of its tasks.
(2) The BSI may, at their request, support the Länder in securing their information technology.
(3) The BSI may, at their request, advise and support essential entities in securing their information technology, or refer them to qualified security service providers.
Home› Cybersecurity & IT Security› BSIG-EN
Part 2 · The BSI › Chapter 1 · Tasks and Powers › Section 3
Tasks of the BSI
←→ also move between sections