Icon Welt mit Netzwerkverbindung

KRITIS audits pursuant to Section 39 BSIG (new version)


What are KRITIS audits pursuant to Section 39 BSIG (new version)?

Operators of so-called "critical infrastructures" (KRITIS operators) must demonstrate to the German Federal Office for Information Security (BSI) that their precautions to prevent disruptions comply with the current state of the art. Critical services within the meaning of the BSI Criticality Regulation (hereinafter "BSI-KritisV") are those provided for the supply of the general public – for example in the information technology and telecommunications, energy and food sectors – and whose failure or impairment would lead to significant supply bottlenecks or endanger public safety.
Under the BSI Act (hereinafter "BSIG"), regulated operators must submit their evidence to the BSI pursuant to Section 39 BSIG (new version).
As a certification body accredited by the German Accreditation Body (DAkkS), we are qualified to carry out audits for the provision of evidence pursuant to Section 39 BSIG (new version).


Benefits of a KRITIS evidence audit by RSM Certification GmbH

Compliance – meeting legal and regulatory requirements

Nationally recognised on the basis of RSM Certification GmbH's accreditation

Option of a combined audit, e.g. ISO/IEC 27001 certification and a Section 39 BSIG (new version) evidence audit

Proof of effectiveness of the security measures you have implemented, through an independent audit


Process of a KRITIS evidence audit

Our audit approach follows a phased concept:

  • Review of the suitability of the scope (approx. 8–12 weeks ahead of the on-site audit) and definition of the audit basis
  • Preparation of the audit plan (approx. 8–12 weeks ahead of the on-site audit)
  • Document review (approx. 3–6 weeks ahead of the on-site audit)
    • Review of the ISMS documentation
    • Assessment of fundamental requirement fulfilment
    • Assessment of whether a functionality review of the ISMS can be carried out effectively
  • Functionality review (on-site audit)
    • Review of the ISMS regarding the implementation of the requirements from the audit criteria, in particular with respect to organisational, technical, personnel, infrastructural and industry-specific aspects
    • Assessment of the management system's ability to ensure compliance with the applicable legal, regulatory and contractual requirements
    • Determination of the management system's conformity with the audit criteria
    • Review of the appropriateness and effectiveness of the security measures
    • Review of the implementation of the KRITIS reporting process
    • Review of the handling of notifications from the BSI and of the handling of security incidents
    • Review of the textual and graphical documentation of the KRITIS scope against the BSI's criteria
  • Follow-up of the on-site audit
  • Documentation

Your path to a KRITIS evidence audit

Enquiry

Submit an enquiry and optionally arrange a meeting at short notice to exchange information and clarify questions.

Quotation

Complete our basic data as a basis for preparing the quotation.

Planning

Order placement and joint coordination of the next steps (including scheduling).

Document review

Review of the ISMS documentation and assessment of fundamental requirement fulfilment.

Effectiveness review

Conducting the Section 39 BSIG (new version) effectiveness review of the ISMS.

Follow-up

Follow-up, documentation and quality assurance of the audit for obtaining evidence pursuant to Section 39 BSIG (new version).

Handover of documentation

Handover of the documentation of the BSI evidence documents and the audit report.


Certification by RSM Certification GmbH

Would you like us to certify you? Feel free to get in touch with us without obligation.

info@rsm-certification.com
+49 211 540148 00


Get in touch without obligation

What is the sum of 9 and 5?

FAQ

How much does a KRITIS evidence audit cost?

The costs depend on a wide variety of factors and are made up in particular of the following components: review of the suitability of the scope; definition of the audit basis; preparation of the audit plan; document review (adequacy review of your ISMS); site visit (effectiveness review of your ISMS); documentation of the results. Further factors influencing the costs include the size and complexity of an organisation, among other things in connection with the number of legal entities and critical installations, the number of sites and thus also the degree to which the ISMS is centralised or decentralised. Further components are the legal and regulatory requirements, which have increased successively in recent years. For example, since 1 May 2023, attack detection systems (SzA) must be audited in accordance with the "Guidance on the use of attack detection systems". In addition, the BSI has defined the so-called GAiN ("Requirements pursuant to Section 8a (5) BSIG – Fundamental requirements in the evidence procedure").

Can the audit basis be chosen freely?

A wide range of audit bases is possible, provided they are suitable for demonstrating compliance with Section 39 BSIG (new version). The operator selects the audit basis in coordination with the auditing body. The description of the audit basis is an explanation of how and from what the audit basis is composed. This includes: a statement of which industry-specific security standards (B3S) or sets of rules are used as a basis; an explanation of how the industry-specific topics are covered; and an account making clear that the audit basis sensibly and completely covers the state of the art for the critical infrastructure to be audited. An audit can be carried out using an industry-specific security standard (B3S) or without one. It should be noted, however, that a corresponding B3S does not exist for all sectors/areas. The description of the audit basis must follow the BSI's requirements, i.e. as Annex PD.C, which forms part of evidence document P.

When do I have to determine that I am a critical infrastructure?

Under the BSI Criticality Regulation, operators of critical infrastructures (KRITIS) must check annually whether their installations are subject to the evidence obligation. By 31 March, it should be checked whether installations exceeded the thresholds under the BSI Criticality Regulation in the previous calendar year. If a threshold is exceeded, the installation is deemed a critical service from 1 April. The installation is therefore subject to the evidence obligation and should be registered with the BSI without delay. Registration as a critical infrastructure with the BSI takes place via the BSI's reporting and information portal (MIP). The KRITIS operator must provide a point of contact that is reachable 24/7.

 

I have determined that I fall below the thresholds. Do I still have to provide evidence?

No general statement can be made on this. We recommend clarifying this directly with the BSI.

Which documents are provided by us and which by you?

The BSI provides templates for audits pursuant to Section 39 BSIG (new version), which we also use in the course of the audit. You are required to complete or produce and submit evidence document KI as well as a description and graphical representation of the scope in a network/installation plan (Annex PD.A). You will receive the following documents from us: evidence document P; Annex PD.C: description of the audit basis; Annex PE.A: list of security deficiencies including an implementation plan for remedying the deficiencies; optional: self-declaration on the suitability of the auditing body.

Is a combined audit of Section 39 BSIG (new version) and ISO/IEC 27001 or ISO 27001 based on IT-Grundschutz possible?

Yes, you can carry out such a combined audit. What matters in this context is the scope. This means that the scope under Section 39 BSIG (new version) should ideally cover the scope of your ISO/IEC 27001 certification in full, so that the possible synergies can be used. At the same time, the scope must cover the installations operated under the BSI Criticality Regulation. Beyond this, Section 39 BSIG (new version) audits are more extensive, as additional requirements apply (e.g. the SzA audit since 1 March 2023) and additional audit aspects for the critical service must also be taken into account.

 

How is the audit team composed?

In order to carry out KRITIS audits, the audit team must have competencies in the following areas: additional audit procedure competence for Section 8a BSIG; audit competence; IT security or information security competence; industry competence. An individual auditor does not have to possess all competencies; assembling a suitable audit team covering all competence areas is sufficient.

Are there requirements for the structure of the documents, the scope and the network structure plan?

The BSI has published a document on this, the so-called "Requirements pursuant to Section 8a (5) BSIG – Fundamental requirements in the evidence procedure (GAiN)". This sets out the requirements for documenting the scope.

Can a valid ISO/IEC 27001 certificate or an ISO 27001 certificate based on IT-Grundschutz be used as part of evidence pursuant to Section 8a (3) BSIG?

Yes, you can use your existing certificate, provided the conditions specified by the BSI have been met. A key part concerns the scope, as the relevant scope of your certification does not automatically have to correspond to the KRITIS scope. In total, the BSI has defined six audit aspects, which the auditing body reviews for compliance with the KRITIS requirements and documents accordingly. The documentation must be submitted together with the ISO/IEC 27001 certificate. The relevant audit aspects are:

  • Delimitation of the scope: the scope of the certificate must cover the installations falling under KRITIS.
  • Extended scope: the scope must be extended to outsourced areas and a comprehensive security assessment from a KRITIS perspective must be carried out.
  • Consideration of the KRITIS protection objectives: maintaining security of supply for the population is the paramount concern in information security risk treatment. The KRITIS protection objectives derived from this – availability, confidentiality, integrity and authenticity – must be included.
  • KRITIS IT protection requirements: the protection objectives of availability, confidentiality, integrity and authenticity must be assessed in relation to maintaining the critical service. The focus here is on the extent of a risk to the general public, not only to your own organisation.
  • Handling of risks: here, too, risks must be assessed with an extended focus on the extent of a risk to the general public.
  • Implementation of measures: all measures necessary to maintain the critical service must be implemented as part of risk treatment, as otherwise they count as security deficiencies and must be documented. An implementation plan is not sufficient for these measures.

The use of an existing ISO/IEC 27001 certificate or ISO 27001 certificate based on IT-Grundschutz, and compliance with the requirements of the further audit aspects, must be documented in Annex PD.2.