Operators of critical infrastructure are required to demonstrate to the Federal Office for Information Security (BSI) that they have implemented the necessary cybersecurity measures as outlined in Section 30(1) in connection with Section 31(1) and (2).
This proof must be submitted:
- No earlier than three years after the organization is first designated as a critical infrastructure operator
- No later than three years after being designated again (if the status was lost and regained)
- Every three years thereafter
Compliance must be demonstrated through security audits, inspections, or certifications. The results of these assessments, including any identified security weaknesses, must be submitted to the BSI.
The BSI may also request the underlying documentation used in these assessments. If security deficiencies are found, the BSI may require the operator to submit an appropriate remediation plan. In coordination with the relevant supervisory authority, BSI may also demand that the deficiencies be resolved and request suitable evidence confirming that the remediation has been completed.