Technical Measures — §30 BSIG and NIS2
Management is personally liable. Not the IT department.
§30 of the German BSIG, the national transposition of the EU NIS2 Directive, lists ten mandatory security measures. Eight of them are technical: access control, multi-factor authentication, vulnerability management, threat detection. They have applied since 6 December 2025, with no transition period. The BSI’s extended registration deadline expired on 31 July 2026. Enforcement is under way. If one of these measures fails, management is held personally liable — not the IT department.
What usually follows is the same mistake. A company buys the tools one at a time: a vulnerability scanner here, an awareness platform there, DDoS protection somewhere else. A year later there are five contracts, five dashboards, and no one owns the whole picture.
What each measure covers
We deliver this block as one operating line, with every service mapped directly to §30 BSIG / NIS2 Article 21:
- Access control and MFA — §30(2) No. 9–10, both measures named explicitly in the statute.
- Vulnerability and patch management — §30(2) No. 5, security across the full system lifecycle.
- Security awareness training and phishing simulation — §30(2) No. 7, reinforced by management’s personal training obligation under §38.
- IT/OT network segmentation — production networks require a distinct discipline, which we source where it actually lives.
- DDoS protection — availability is listed among §30’s mandatory measures directly.
What we answer for
We select the platform, configure it against §30 requirements, operate it, and answer for the outcome. One point of contact, not five separate vendor relationships to manage.
Where the technical work stops
Legal classification and the BSI incident-reporting obligation remain with your legal counsel; we deliver the technical foundation, not legal advice.