[eu]cite

Home› Cybersecurity & IT Security› BSIG-EN

Part 2 · The BSI  ›  Chapter 1 · Tasks and Powers › Section 5

General reporting point for IT security

(1) To perform the tasks under section 3, the BSI, as the central body for reports from third parties, receives and evaluates information on IT security risks. In doing so the BSI is the national coordinator for the purposes of coordinated vulnerability disclosure under Article 12(1) of the NIS 2 Directive.
(2) In performing the tasks under subsection (1), the BSI receives information on vulnerabilities, malware, actual or attempted attacks on IT security and the methods observed in that connection, as well as on security incidents, cyber threats and near misses. The BSI must establish suitable means for such reports. Reports may be made anonymously. Where a report is not made anonymously, the reporting person may, at the time of the report or later, require that their personal data be passed on only in anonymised form. This does not apply in the cases of section 8(6) and (7), first sentence. A transmission of personal data in the cases of section 8(6) and (7), first sentence must not take place where it is apparent to the BSI that the reporting person's interests worthy of protection outweigh the public interest in the transmission. The manner in which the reporting person obtained the findings must also be taken into account in this regard. The decision under the sixth sentence must be submitted for prior review to the BSI's official data protection officer and to a further member of the BSI's staff qualified for judicial office.
(3) To perform its tasks under section 3(1), first sentence, the BSI must pass on information concerning vulnerabilities reported under subsection (2) to the responsible manufacturer or product owner without delay, for the purpose of closing the vulnerability, unless it is already publicly known. The BSI should use the information reported under subsection (2) to
1. inform third parties of vulnerabilities, malware or actual or attempted attacks on IT security that have become known, insofar as necessary to safeguard their security interests,
2. warn and inform the public or the circles concerned under section 13,
3. inform federal administration entities under section 4(2), no. 2 of information concerning them,
4. inform essential entities and important entities under section 40(3), no. 4(a) of information concerning them,
5. perform its tasks as competent authority, CSIRT and single point of contact within the meaning of the NIS 2 Directive.
(4) A passing on under subsection (3), nos. 1, 2 or 4 does not take place insofar as the information reported under subsection (2)
1. contains trade or business secrets of third parties and the measures under subsection (3) cannot be carried out without disclosing those trade or business secrets, or
2. may not be transmitted on account of agreements between the BSI and third parties.
(5) Other statutory reporting obligations, secrecy-protection provisions, statutory obstacles to transmission and transmission provisions remain unaffected.
(6) The BSI publishes, on 6 December 2026, a description of the procedure for implementing subsections (1) to (3).

←→ also move between sections