(1) Essential entities and important entities are obliged to report the following information to a joint reporting point established by the BSI and the Federal Office of Civil Protection and Disaster Assistance: 1. without delay, but at the latest within 24 hours of becoming aware of a significant security incident, an early initial report stating whether the significant security incident is suspected to be attributable to unlawful or malicious acts, or could have cross-border effects; 2. without delay, but at the latest within 72 hours of becoming aware of a significant security incident, a report on that security incident, confirming or updating the information named in no. 1, and stating an initial assessment of the significant security incident, including its severity and impact, and, where applicable, the indicators of compromise; 3. at the BSI's request, an interim report on relevant status updates; 4. at the latest one month after transmission of the report of the security incident under no. 2, subject to subsection (2), a final report containing: a) a detailed description of the security incident, including its severity and impact; b) particulars of the type of threat, or the underlying cause, that probably triggered the security incident; c) particulars of the remedial measures taken and ongoing; d) where applicable, the cross-border effects of the security incident. The obligation under the first sentence applies at the earliest from the establishment of the reporting channel.
(2) Where the security incident is still ongoing at the time named in subsection (1), first sentence, no. 4, the entity concerned submits a progress report instead of a final report at that time. The final report must be submitted to the BSI after the entity concerned has finally dealt with the security incident.
(3) Operators of critical facilities are additionally obliged to transmit particulars of the type of the facility affected and of the critical service, and of the effects of the security incident on that service, where a significant security incident has, or could have, effects on the critical facility operated by them.
(4) The BSI determines the details of the arrangement of the reporting procedure and the specification of the content of reports after hearing the operators concerned and the trade associations concerned, in agreement with the Federal Office of Civil Protection and Disaster Assistance, insofar as this does not conflict with possible implementing acts of the European Commission. The information under the first sentence is published by the BSI on its website.
(5) The BSI makes the reports it receives available to the competent federal supervisory authorities without delay.
(6) The BSI may, in accordance with section 36(1), make offers to reporting entities to support them in remedying the security incident.
Home› Cybersecurity & IT Security› BSIG-EN
Part 3 · IT Security of Entities › Chapter 2 · Risk Management, Reporting, Registration, Verification and Notification Obligations › Section 32
Reporting obligations
←→ also move between sections