Mandatory scheme
IT security catalogue duty for energy network and facility operators (EnWG §5c)
IT security catalogue duty for energy network and facility operators (EnWG §5c) — mandatory scheme, Germany. It binds operators of an energy supply network (for telecommunications and electronic data-processing systems necessary for its safe operation); operators of an energy facility that is an "especially important" or "important" entity under BSIG §28(1)/(2) and connected to an energy supply network; and operators of a digital energy service that is such an entity and exercised at a connected energy facility.
- Jurisdiction
- Germany
- Record class
- Mandatory scheme
- Last verified
Where this applies
This record is scoped to Germany. Scope is part of the claim: a rule that binds one part of a country does not bind the whole of it, and this library states the scope its sources state.
Instrument
Energiewirtschaftsgesetz (EnWG), §5c
Who it binds
Operators of an energy supply network (for telecommunications and electronic data-processing systems necessary for its safe operation); operators of an energy facility that is an "especially important" or "important" entity under BSIG §28(1)/(2) and connected to an energy supply network; and operators of a digital energy service that is such an entity and exercised at a connected energy facility
What it requires
EnWG §5c(1) requires the operators it names to ensure appropriate protection against threats for the telecommunications and electronic data-processing systems necessary for safe operation, secured already at the procurement stage. §5c(2): the Bundesnetzagentur, in agreement with the BSI, sets the appropriate-protection requirements in a Katalog von Sicherheitsanforderungen (IT-Sicherheitskatalog) via a Festlegung under §29(1) — the Bundesnetzagentur reviews the catalogue every two years and updates it as needed, and an operator's compliance with the catalogue is deemed to satisfy the appropriate-protection duty ("gilt der angemessene Schutz als eingehalten"). §5c(3) requires the catalogue to be proportionate to risk exposure, operator size, incident likelihood/severity, and societal/economic impact, drawing on relevant European or international standards and the state of the art. §5c(4) requires the catalogue to cover at minimum: risk-analysis and security concepts, incident handling, business continuity (including backup/recovery and crisis management), and supply-chain security, among other minimum topics not reproduced here. A transition rule (per the Bundesnetzagentur's own overview page) keeps the IT-Sicherheitskatalog issued under the prior EnWG §11(1a)/(1b) in force for existing network and facility operators until a new catalogue is published under §5c.
Route to the authority
Further sources cited on this page
Last verified:
This page is for information only; it is not legal advice, and it does not establish whether this record applies to your business. Verify current status through the official source above.