(1) The Federal Ministry of the Interior determines, after hearing the trade associations concerned, in agreement with the Federal Ministry for Economic Affairs and Energy, by statutory instrument not requiring the consent of the Bundesrat, further details of the procedure for issuing security certificates and recognitions under section 52 and their content.
(2) The Federal Ministry of the Interior determines, by statutory instrument not requiring the consent of the Bundesrat, after hearing the trade associations concerned, in agreement with the Federal Ministry for Economic Affairs and Energy and the Federal Ministry for the Environment, Climate Action, Nature Conservation and Nuclear Safety, the details of the design, content and use of the IT security label under section 55, in order to ensure a uniform design of the label and clear identifiability of the marked information technology products, as well as the details of the procedure for determining the suitability of industry-agreed IT security specifications and of the application procedure for approval, including the periods and the documents to be submitted in that connection, and the procedure and design of the reference to security information.
(3) The Federal Ministry of the Interior determines, by statutory instrument not requiring the consent of the Bundesrat, in agreement with the Federal Ministry for Economic Affairs and Energy, the Federal Ministry of Finance, the Federal Ministry of Justice and Consumer Protection, the Federal Ministry of Labour and Social Affairs, the Federal Ministry of Defence, the Federal Ministry of Agriculture, Food and Home Affairs, the Federal Ministry of Health, the Federal Ministry of Transport, the Federal Ministry of Research, Technology and Space, the Federal Ministry for the Environment, Climate Action, Nature Conservation and Nuclear Safety, and the Federal Ministry for Digital Affairs and State Modernisation, which products, services or processes used by an essential entity or an important entity must, under section 30(6), have a cybersecurity certification, because they are material to the provision of the entity's services and the nature and extent of the entity's risk exposure make a mandatory use of certified products, services or processes in that field necessary.
(4) The Federal Ministry of the Interior may, in agreement with the Federal Ministry for Economic Affairs and Energy and in consultation with the Federal Ministry of Justice and Consumer Protection, the Federal Ministry of Finance, the Federal Ministry of Labour and Social Affairs, the Federal Ministry of Agriculture, Food and Home Affairs, the Federal Ministry of Health, the Federal Ministry of Transport, the Federal Ministry of Defence, the Federal Ministry for the Environment, Climate Action, Nature Conservation and Nuclear Safety, the Federal Ministry of Research, Technology and Space and the Federal Ministry for Digital Affairs and State Modernisation, determine, by statutory instrument not requiring the consent of the Bundesrat, when a security incident is to be regarded as significant within the meaning of section 2, no. 11, having regard to its technical or organisational causes or to its effects on the entity, the state, the economy or the number of persons affected by the effects. The Ministry may transfer this authorisation, by statutory instrument, to the BSI. Any implementing acts of the European Commission under Article 23(11), second subparagraph of the NIS 2 Directive determining the conditions of a significant security incident take precedence over the statutory instrument under the first and second sentences to that extent.
(5) The Federal Ministry of the Interior may, by statutory instrument not requiring the consent of the Bundesrat, in agreement with the Federal Ministry of Health, determine that the BSI may order licensed hospitals under section 108 of Book Five of the Social Code to submit evidence of compliance with individual or all of the obligations named in section 61(1) at an earlier time than that named in section 61(3), fifth sentence.
(6) The Federal Ministry of the Interior may, by statutory instrument not requiring the consent of the Bundesrat, determine critical components within the meaning of section 2, no. 23, for each of the sectors listed in section 2, no. 24, in agreement with the Federal Ministry named in section 41(1) for the respective sector. The statutory instrument may determine a component as a critical component where 1. the component is an ICT product, 2. the component is used in critical facilities, 3. the component realises a critical function, and 4. a disruption of the availability, integrity, authenticity or confidentiality of the component could lead to an impairment of the functionality of critical facilities or to other impairments of public order or security.
(7) The Federal Ministries named in section 41(1) may submit to the Federal Ministry of the Interior a proposal for the issuance of a statutory instrument within the meaning of subsection (7). The right of proposal relates only to the sector within the meaning of section 2, no. 24 for which the respective Federal Ministry is named in section 41(1).
Home› Cybersecurity & IT Security› BSIG-EN
Part 6 · Authorisations to Issue Statutory Instruments, Restrictions of Fundamental Rights and Reporting Obligations › Section 56
Authorisation to issue statutory instruments
←→ also move between sections