Mandatory scheme

IT security catalogue duty for energy network and facility operators (EnWG §5c)

IT security catalogue duty for energy network and facility operators (EnWG §5c) — mandatory scheme, Germany. It binds operators of an energy supply network (for telecommunications and electronic data-processing systems necessary for its safe operation); operators of an energy facility that is an "especially important" or "important" entity under BSIG §28(1)/(2) and connected to an energy supply network; and operators of a digital energy service that is such an entity and exercised at a connected energy facility.

Jurisdiction
Germany
Record class
Mandatory scheme
Last verified

Where this applies

This record is scoped to Germany. Scope is part of the claim: a rule that binds one part of a country does not bind the whole of it, and this library states the scope its sources state.

Instrument

Energiewirtschaftsgesetz (EnWG), §5c

Who it binds

Operators of an energy supply network (for telecommunications and electronic data-processing systems necessary for its safe operation); operators of an energy facility that is an "especially important" or "important" entity under BSIG §28(1)/(2) and connected to an energy supply network; and operators of a digital energy service that is such an entity and exercised at a connected energy facility

What it requires

EnWG §5c(1) requires the operators it names to ensure appropriate protection against threats for the telecommunications and electronic data-processing systems necessary for safe operation, secured already at the procurement stage. §5c(2): the Bundesnetzagentur, in agreement with the BSI, sets the appropriate-protection requirements in a Katalog von Sicherheitsanforderungen (IT-Sicherheitskatalog) via a Festlegung under §29(1) — the Bundesnetzagentur reviews the catalogue every two years and updates it as needed, and an operator's compliance with the catalogue is deemed to satisfy the appropriate-protection duty ("gilt der angemessene Schutz als eingehalten"). §5c(3) requires the catalogue to be proportionate to risk exposure, operator size, incident likelihood/severity, and societal/economic impact, drawing on relevant European or international standards and the state of the art. §5c(4) requires the catalogue to cover at minimum: risk-analysis and security concepts, incident handling, business continuity (including backup/recovery and crisis management), and supply-chain security, among other minimum topics not reproduced here. A transition rule (per the Bundesnetzagentur's own overview page) keeps the IT-Sicherheitskatalog issued under the prior EnWG §11(1a)/(1b) in force for existing network and facility operators until a new catalogue is published under §5c.

Route to the authority

Further sources cited on this page

Last verified:

This page is for information only; it is not legal advice, and it does not establish whether this record applies to your business. Verify current status through the official source above.

Cite this page

Attributing this record helps other researchers verify it independently.

"IT security catalogue duty for energy network and facility operators (EnWG §5c)." Certifidex, FutureTechnologies. Last verified 1 September 2026. https://certifidex.com/countries/de/enwg-it-sicherheitskatalog

All Germany records →