(1) The Federal Ministry of the Interior may, on the proposal of the Federal Chancellery, the Federal Ministry of Justice and Consumer Protection, the Federal Ministry of Defence, the Federal Ministry of Finance, the interior and justice ministries of the Länder, or on its own initiative, partially exempt an essential entity or an important entity from obligations under this Act in accordance with subsection (2) (simple exemption notice), or wholly exempt it in accordance with subsection (3) (extended exemption notice), provided the entity complies with requirements equivalent to the obligations under this Act. The decision under the first sentence is taken in agreement with the respective competent department, and, in the case of the interior and justice ministries of the Länder, in consultation with them.
(2) Entities that 1. are active, or provide services, in the fields of national security, public security, defence or law enforcement, including the prevention, investigation, detection and prosecution of criminal offences, (relevant fields), or 2. are active, or provide services, exclusively for authorities that perform tasks in relevant fields, may, for those activities or services, be exempted from the risk management measures under section 30 and the reporting obligations under section 32. In such cases the IT security of those entities must be otherwise ensured and supervised.
(3) Entities that are active, or provide services, exclusively in relevant fields may be wholly exempted from the obligations named in subsection (2) and from the registration obligations under sections 33 and 34. Subsection (2), second sentence applies accordingly.
(4) Subsections (1) to (3) do not apply where the entity concerned is a trust service provider.
(5) An exemption notice under this Act must be revoked where facts subsequently arise that would have led to a refusal to grant an exemption. By way of derogation from the first sentence, revocation may be dispensed with in the case of a temporary lapse of the conditions of subsection (2), first sentence, nos. 1 or 2.
Home› Cybersecurity & IT Security› BSIG-EN
Part 3 · IT Security of Entities › Chapter 2 · Risk Management, Reporting, Registration, Verification and Notification Obligations › Section 37
Exemption notice
←→ also move between sections