[eu]cite

Home› Cybersecurity & IT Security› BSIG-EN

Part 7 · Supervision › Section 61

Supervisory and enforcement measures for essential entities

(1) The BSI may order individual essential entities to have audits, examinations or certifications carried out by independent bodies to review compliance with the obligations under section 30(1), first sentence, also in conjunction with section 31(1) and (2), first sentence, and section 32(1) to (3) and section 38(3).
(2) The BSI may, after hearing the entities and trade associations concerned, determine professional and organisational requirements for the examining bodies. The determination under the first sentence is made by public notice on the BSI's website.
(3) The BSI may also order other essential entities, at the earliest three years after this Act enters into force, to submit evidence of compliance with individual or all of the obligations named in subsection (1). Insofar as the BSI has exercised its right under subsection (1), it may also require the transmission of the results of the audits, examinations or certifications carried out, including the security defects thereby uncovered, and the submission of the documentation on which the review was based. In the case of security defects it may require the submission of a suitable defect-remediation plan, in agreement with the competent federal supervisory authority or with the otherwise competent supervisory authority. The BSI may require submission of suitable evidence that the defects have been remedied. By way of derogation from the first sentence, the BSI may order licensed hospitals under section 108 of Book Five of the Social Code, at the earliest five years after this Act enters into force, to submit evidence of compliance with individual or all of the obligations named in subsection (1), unless an earlier time is determined by statutory instrument under section 56(6).
(4) In selecting the entities from which the BSI requires evidence under subsection (3), the BSI takes into account the degree of risk exposure, the size of the entity, the probability of occurrence and severity of possible security incidents, and their possible societal and economic impact.
(5) The BSI may review essential entities' compliance with the requirements under this Act. It may avail itself of a qualified independent third party in carrying out the review. The essential entity must, for the purpose of the review, permit the BSI and the persons acting on its behalf to enter its business and operational premises during normal business hours, and, on request, submit, in a suitable manner, the relevant records, documents and other papers, provide information, and grant the necessary support. The BSI charges fees and expenses to the respective essential entity for the review only where it has acted on the basis of indications giving rise to legitimate doubts as to compliance with the requirements under section 30(1).
(6) The BSI may order essential entities, in consultation with the competent supervisory authority, to take the measures under section 30(1), first sentence necessary to prevent or remedy a security incident or a defect, and to submit a suitable defect-remediation plan and suitable evidence that the defects have been remedied. Consultation with the competent supervisory authority may be dispensed with where there is imminent danger. The BSI may further require reporting on the measures ordered under the first sentence within a reasonable period.
(7) The BSI may, in consultation with the competent supervisory authority, issue orders to essential entities to implement the obligations named in subsection (1). Consultation with the competent supervisory authority may be dispensed with where there is imminent danger. It may order the implementation of specific recommendations formulated within the framework of a security review, in the individual case, within a reasonable period.
(8) The BSI may order essential entities 1. to inform the natural or legal persons for whom they provide services or carry out activities and who are potentially affected by a significant cyber threat, of the nature of the threat and of possible defensive or remedial measures those persons can take in response to the threat, and 2. to publicly disclose information on infringements of the obligations named in subsection (1), in accordance with requirements determined by the BSI.
(9) Where essential entities fail, despite the setting of a period, to comply with the BSI's orders under this Act, the BSI may notify the respective competent supervisory authority of this. Where a connection exists between the enforcement measure and the order, the competent supervisory authority may, as a last resort, 1. temporarily suspend, wholly or in part, the authorisation granted to that entity under the respective sectoral law, and 2. temporarily prohibit unreliable management from exercising the activity to which they are called (section 2, no. 13). The suspension under the second sentence, no. 1 and the prohibition under the second sentence, no. 2 are admissible only for so long as the essential entity does not comply with the BSI's orders for non-compliance with which they were issued.
(10) Insofar as the BSI carries out measures against essential entities, it informs the competent federal supervisory authority of this. The information must be given without delay where it is a measure under subsection (6) or (7) issued, on account of imminent danger, without consultation with the competent supervisory authority.
(11) Where the BSI determines, in the course of supervising an entity or enforcing a measure, that an infringement of the obligations under this Act may result in a breach of the protection of personal data within the meaning of Article 4, point 12 of Regulation (EU) 2016/679 that must be notified under Article 33 of that Regulation, it informs the competent supervisory authorities without delay.
(12) In the case of entities that provide services in other Member States of the European Union, the BSI may also take measures under subsections (1) to (11) at the request of the respective competent supervisory authorities of the Member State.

←→ also move between sections