Mandatory scheme

Periodic compliance-proof duty for critical facility operators (BSIG §39)

Periodic compliance-proof duty for critical facility operators (BSIG §39) — mandatory scheme, Germany. It binds betreiber kritischer Anlagen (operators of critical facilities) under the BSIG, excluding those designated as such solely under KRITIS-Dachgesetz §5(7).

Jurisdiction
Germany
Record class
Mandatory scheme
Last verified

Where this applies

This record is scoped to Germany. Scope is part of the claim: a rule that binds one part of a country does not bind the whole of it, and this library states the scope its sources state.

Instrument

BSI-Gesetz (BSIG), §39

Who it binds

Betreiber kritischer Anlagen (operators of critical facilities) under the BSIG, excluding those designated as such solely under KRITIS-Dachgesetz §5(7)

What it requires

BSIG §39(1) requires operators of critical facilities to prove implementation of the measures required under §30(1) sentence 1 in conjunction with §31(1) and (2) sentence 1 to the Federal Office for Information Security (BSI), at a point in time the BSI sets — at the earliest three years after first (or again) qualifying as such an operator — and thereafter every three years, via "Sicherheitsaudits, Prüfungen oder Zertifizierungen" (security audits, inspections, or certifications; the operator may choose among the three). Operators submit the results, including any security deficiencies found; the BSI can require a remediation plan and evidence the deficiencies were fixed. §39(3) is a transition rule: for operators who were "Betreiber Kritischer Infrastrukturen" under the old BSIG (2009) §2(10) before this law took effect, the BSI sets the next proof date at the earliest three years after their last proof under the old §8a(3); those whose old deadline would have fallen within 12 months of this law's entry into force may still prove compliance under the old rules within that window. §39(4) exempts operators designated as critical facilities solely under KRITIS-Dachgesetz §5(7).

Route to the authority

Last verified:

Related records and requirements

  • Critical/important entity registration (BSIG) (Germany) — Both records are duties under the same 2025 BSIG reform for Germany's critical/important entities: §33 requires registering with the BSI, while §39 separately requires periodically proving compliance to the BSI via audit, inspection, or certification.

This page is for information only; it is not legal advice, and it does not establish whether this record applies to your business. Verify current status through the official source above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Periodic compliance-proof duty for critical facility operators (BSIG §39)." Certifidex, FutureTechnologies. Last verified 1 September 2026. https://certifidex.com/countries/de/bsig-critical-facility-proof-duty

All Germany records →