(1) Federal administration entities must satisfy minimum requirements for protecting the information processed in the federal administration. The minimum requirements result from the BSI standards and the Basic Protection Compendium (IT-Grundschutz), and from the minimum standards for IT security of the Federation (minimum standards), in their respective current versions. The respective current versions are published on the BSI's website. The BSI determines the minimum standards in consultation with the departments and other supreme federal authorities. IT-Grundschutz and the minimum standards are regularly evaluated by the BSI and further developed in accordance with the state of the art and having regard to experience from practice and from the advice and support under subsection (3); in doing so the implementation effort is minimised as far as possible. The BSI will modernise and further develop IT-Grundschutz by 1 January 2026. The exceptions under section 7(6) and (7) apply accordingly to the obligation under the first sentence.
(2) The implementation of the minimum requirements under subsection (1), first sentence ensures compliance with the requirements under section 30, unless the European Commission adopts an implementing act under Article 21(5), second subparagraph of the NIS 2 Directive in which the technical and methodological requirements go beyond the minimum requirements under subsection (1), first sentence. Where a federal entity is at the same time an operator of critical facilities, and the requirements of IT-Grundschutz and the minimum standards conflict with the requirements under section 30(9) and section 31, the latter take precedence.
(3) The BSI advises federal administration entities, at their request, on implementing and complying with the minimum requirements under subsection (1), first sentence, provides tools, and supports the provision of corresponding solutions by the Federation's IT service providers over the entire lifecycle.
(4) The BSI provides, within the framework of its tasks under section 3(1), second sentence, no. 10, technical guidelines and reference architectures, to be taken into account by federal administration entities as a framework for developing appropriate requirements for contractors — in the sense of suitability — and IT products — in the sense of specification — for conducting procurement procedures. The provisions of procurement law and of secrecy protection remain unaffected.
(5) The Federal Ministry of the Interior may, for federal administration entities, in agreement with the other departments, determine that they are obliged to retrieve IT security products provided under section 19 from the BSI. In that case, own procurement by federal administration entities is admissible only where the specific requirements profile requires the use of different products. This does not apply to the courts and constitutional organs named in section 2, no. 21, or to the foreign information and communications technology under section 7(6).
Home› Cybersecurity & IT Security› BSIG-EN
Part 3 · IT Security of Entities › Chapter 3 · Information Security of Federal Administration Entities › Section 44
BSI requirements
←→ also move between sections