Order ISB for critical infrastructure: obligation, profile and appointment certificate in detail
KRITIS operators, particularly important and important facilities according to the NIS 2 Implementation Act, must appoint, document and provide evidence to the BSI of an information security officer. The article shows the legal basis, requirement profile, appointment certificate and the operational structure in the CIVAC workspace.
With the NIS 2 Implementation Act (NIS2UmsuCG) and the modernization of the Act on the Federal Office for Information Security (BSIG), the appointment of an information security officer for operators of critical systems, particularly important facilities and important facilities is no longer a recommendation, but a requirement with a specific deadline. Around 29,500 companies in Germany fall under the expanded scope, from energy supply and healthcare to transport and digital infrastructure to food production and waste management. The obligation arises from Section 38 BSIG-new in conjunction with Annex I and II of Directive (EU) 2022/2555 and is sanctioned with fines of up to 10 million euros or 2% of group turnover for essential facilities and up to 7 million euros or 1.4% for important facilities.
The article addresses the operational questions surrounding the order: When is a company a KRITIS operator, when is it particularly important, when important facility? What minimum qualification must the information security officer (ISB) meet? What does the appointment certificate that is presented in the audit look like? How does the reporting line to management work in relation to the Federal Office for Information Security? And how does the 24-hour early warning and 72-hour follow-up path integrate into ongoing work? The article dispenses with the general NIS-2 primer and focuses on the representative obligation and its concrete implementation in the CIVAC workspace.
Key Takeaways
- KRITIS operators and facilities according to NIS-2 must formally order an ISB, with an appointment certificate, reporting line and evidence to the BSI.
- The requirements profile requires demonstrable expertise, independence and a direct reporting line to management; Duplication of IT management is fraught with conflict.
- The ISB can be ordered via the CIVAC workspace within two working days, including a 24/72 reporting path, statement of applicability and escalation path to management.
Who falls under the ISB obligation: CRITICISM, particularly important, important
The NIS 2 Directive distinguishes between three categories, which are adopted in the German NIS 2 Implementation Act. KRITIS operators are system operators in eleven sectors above defined thresholds (energy, water, nutrition, health, information technology and telecommunications, transport and traffic, finance and insurance, municipal waste disposal, government and administration, media and culture, space). Particularly important facilities are companies with 250 employees or more or a turnover of 50 million euros and a balance sheet total of 43 million euros in the NIS 2 sectors with a high degree of criticality. Important institutions are companies with 50 or more employees or a turnover of 10 million euros in the other NIS 2 sectors.
The ISB obligation follows from Section 38 BSIG-new in conjunction with the requirements for risk management and cyber hygiene from Section 30 BSIG-new. Unlike KRITIS under the old IT Security Act 2.0, the appointment of a designated representative under NIS-2 is no longer optional and cannot be replaced by generic IT security management. The ISB is expressly the person who is designated for the implementation of the risk management measures according to Section 30 BSIG-new, for the reporting obligations according to Section 32 BSIG-new (24h early warning, 72h follow-up report, final report) and for communication with the Federal Office for Information Security. The requirements profile is based on the BSI standard 200-2 description of the role. The external information security officer can fulfil this obligation for medium-sized institutions without the function having to be filled full-time internally. It is important that the distinction between KRITIS operator, particularly important and important institution is examined in each individual case, because sector allocation, threshold values and special sector regulations overlap and a company is often recorded in several categories at the same time. This multiple assignment is expressly mentioned in the ISB appointment certificate.
Legal basis in detail: § 38 BSIG-new, BSI standard 200-2, sectoral requirements
The obligation to order results from three overlapping sets of rules. Firstly, the NIS 2 Implementation Act, which transposes Directive (EU) 2022/2555 into German law and stipulates ten minimum requirements for risk management measures in Section 30 BSIG-new: risk analysis, incident management, backup and restart, supply chain security, procurement and development security, effectiveness control, basic cyber hygiene, encryption, personnel security and multi-factor authentication. Secondly, the BSI standard 200-2 (IT-Grundschutz methodology), which describes the role of the information security officer in terms of tasks, authorities, reporting line and independence. Thirdly, special sectoral regulations for KRITIS operators, such as the industry-specific security standard (B3S) in the healthcare sector, in the energy sector or in the water supply, which each place additional requirements on the ISMS and on the ISB function.
In practical terms, this means: A particularly important healthcare facility with 600 employees is simultaneously under NIS-2, under the KHZG-recognised B3S hospital and under the GDPR requirements for patient data. The ISB must include both the NIS 2 tasks and the B3S obligations in the appointment certificate, or two representatives are appointed in parallel with a clearly defined scope. CIVAC manages this overlay in a single workspace, with an appointment certificate that lists all relevant legal bases and with cross-references to the respective audit templates. An auditor from the Federal Office for Social Security or the BSI sees the same function and the same person responsible in every case, and there are no gaps in the scope. This clear demarcation is also a control tool for management, because an appointment certificate with clear areas of application shows which systems, locations and companies are subject to which supervision and which reports are to be submitted to which authority and at what frequency. This clarity reduces the likelihood of double reporting and reporting gaps alike.
Requirements profile: specialist knowledge, independence, availability
The BSI describes the minimum profile of an information security officer in the IT-Grundschutz Compendium and in BSI Standard 200-2. Firstly, professional qualifications: knowledge of information security management systems in accordance with ISO/IEC 27001:2022 or IT-Grundschutz, the threat level of typical sector attack patterns, the applicable legal bases (BSIG, BDSG, sectoral laws) and incident handling with forensic connections. Secondly, independence: The ISB must not have a conflict of interest with its own activities. Duplication of IT management is often a source of conflict because the same actor would have to implement and control security measures. Thirdly, availability: The ISB must be reachable within the 24-hour early warning period according to Section 32 BSIG-neu, which is not fulfilled by a pure deputy regulation without an escalation path.
This requirement profile leads many medium-sized companies to decide on an external ISB. The market situation for internal full-time ISBs is tense: the Federal Employment Agency reports tens of thousands of open positions in the IT security area in 2025, the average annual salary is over 90,000 euros, and fluctuation in the role is high. An external ISB solves availability, conflict and costs in one step, provided the order is formally clear and accessibility is fixed in the contract. CIVAC appoints the ISB within two business days from a vetted officer pool, with proven industry experience, ISO/IEC 27001 Lead Auditor or BSI certified qualification and a binding response SLA for the NIS-2 reporting paths. Licence the workspace for your internal ISB, or have our ISB ordered. Both models are documented in the appointment certificate according to the same standards, so that a supervisory authority does not recognise any formal difference between the internal and external solution during the audit and both variants work with the same templates in ongoing reporting.
The appointment certificate: content, form, signature
The appointment certificate is the central evidentiary document for the BSI. It states the legal basis (§ 38 BSIG-new, supplementary BSI standard 200-2 and sectoral regulations), the full name of the person appointed, the date of the order, the scope (companies, locations, facilities), the tasks (implementation of risk management measures according to § 30 BSIG-new, reporting paths according to § 32 BSIG-new, communication with the BSI, training, internal audits, reporting to the management), the reporting line to the top management level with accessibility, the independence clause with express freedom of instruction in technical questions and the period of validity. The document is signed by the management and the ISB, stamped with a time stamp and stored in the workspace.
Without this document, the order is deemed not to have been placed in the event of an audit. The BSI regularly checks the existence, content and timeliness of the appointment certificate as part of self-declarations and on site. Common findings include: lack of independence clause, generic scope without a list of the companies covered, no reporting line to management, appointment date before taking over the function, expired period of validity without extension. The CIVAC template eliminates each of these pitfalls and produces an appointment certificate that is immediately auditable. The appointment certificate, signed, filed, verifiable. In the workspace, the certificate is linked to the statement of applicability, the risk treatment plan and the reporting path templates, so that the ISB can operationally control its tasks from the order and does not have to start in a separate tool. In addition, a replacement arrangement is part of the order because 24-hour early warning must also be ensured in the event of vacation or illness. The replacement is named, also trained and given identical authorizations in the workspace. This interlinking of the order and the operational file is also important because when making a self-declaration in accordance with Section 39 BSIG-new, the BSI not only checks the existence of the ISB, but also its actual effectiveness.
The 24/72-hour reporting path according to Section 32 BSIG-new
With NIS-2, the reporting deadline is set on a three-stage path: 24 hours of early warning after knowledge of a significant security incident, 72 hours of follow-up reporting with initial assessment, one month of final reporting. The deadlines start from knowledge, not from completed forensics. Section 32 BSIG-new specifies the contents of the three reports: early warning with indications, suspected cause, possible impact and immediate measures taken; Follow-up message with updated rating; Final report with a detailed description of the incident, the cause, the effect, the measures taken and the lessons learned.
Operationally, the ISB is the focus of each of these reports. He classifies the incident, checks the relevance based on the criteria of Implementing Regulation (EU) 2024/2690 (extension of the definition), decides whether to activate the early warning and sends the report via the BSI reporting platform. The CIVAC workspace contains the prepared early warning and follow-up report template with the mandatory fields, a classification guide and an escalation scheme for management. Deadline begins as soon as we become aware of it. A significant incident is opened internally in the workspace, the clock runs with the time stamp of awareness, the early warning is sent within 24 hours, the follow-up report within 72 hours, and the final report within a month. Every shipment is documented with a receipt and confirmation of receipt in the workspace, and the management receives the same status at the same time. The materiality criteria are listed in a separate template so that the classification decision is documented and can be traced afterwards. Anyone who later recognises an incident class that was classified as not significant as significant can clearly justify the subsequent report with reference to the original classification. The management is involved synchronously via the workspace, so that no parallel communication via email is necessary and the escalation decision remains documented in an audit trail with a time stamp.
Reporting line to management and liability profile
§ 38 Paragraph 1 BSIG-new stipulates that management must monitor the implementation of risk management measures. Section 38 paragraph 2 BSIG-new specifies the personal liability of management for violations of the supervisory obligation. Both regulations have a concrete consequence for the ISB's reporting line: it must go directly to the management, it must be documented, and the management must demonstrably take note of the reports and react to identified risks. A reporting line to the IT management with occasional escalation to the management does not meet the requirement.
CIVAC structures the reporting line in a quarterly report with standard points (risk situation, status of measures, incidents, audits, regulatory changes), event reports for reportable incidents with defined thresholds and an escalation path to management and the supervisory board in the event of repeatedly untreated risks. The quarterly report is delivered electronically, management confirms receipt, and the measures are tracked in the workspace. In the event of liability, this logging is doubly valuable: it protects the management against accusations of ignorance and it protects the ISB against accusations of omission. The platform not only provides the reports, but also the evidence that the reports were made and that they were acted upon. The auditor calls, the evidence is ready. Management and the supervisory board also receive a condensed view for their own meeting preparation, so that the reporting line does not end in a pile of files, but is placed on the agenda as a control instrument. Deadline begins as soon as we become aware of it. Anyone who, as a managing director, receives a report from the ISB without taking immediate action or providing documented reasons for accepting the risk assumes the personal liability risk in accordance with Section 38 Paragraph 2 BSIG-neu.
Costs, conflict checking and construction in two working days
The costs of an external ISB for a particularly important facility with 250 to 1,000 employees in Germany range between 1,800 and 4,800 euros per month in a fixed price model, depending on the sector, number of locations, complexity of the OT environment and existing ISMS maturity. For KRITIS systems with distinctive operational technology and requirements from the industry-specific security standard, the range is 5,000 to 12,000 euros per month. An internal main office ISB costs 110,000 to 160,000 euros in total annual costs and requires a deputy. The economic basis for comparison is therefore clearly in favor of the external model for most facilities below the group size.
The order from CIVAC runs in two working days. Day one: Intake with sector, number of employees, location list, ISMS status, existing certificates, OT inventory, incident history and sectoral requirements. Conflict check against the officer pool. Draft contract from the template and NDA. Day two: signed appointment certificate, notification to the responsible authority (BSI for NIS-2, if necessary Federal Network Agency, Federal Financial Supervisory Authority or Federal Office for Civil Protection and Disaster Assistance depending on the sector), publication of the contact on the company website, kick-off with management to confirm the reporting line. From this point onwards, the rolling two business day SLA applies to risk assessments, ISMS reviews and incident response. The platform licence for the internal ISB follows the same process, except that the person comes from within the company. The ongoing effort remains calculable for the management because the fixed price includes not only the representative hours, but also the audit templates, the reporting obligations and the reporting path configuration and no hidden renegotiations are necessary at the beginning of a new quarter. Purchasing and legal departments can compare the SLA obligations line by line with the NIS 2 deadlines and pass them on in the supplier questionnaire because the SLAs are contractually agreed and not promised in the sales discussion.
ISMS connection: ISO 27001:2022, BSI IT-Grundschutz and the 93 controls
The ISB is not the ISMS, but it is responsible for its effectiveness. Section 30 BSIG-new requires a documented risk management system without prescribing a specific framework. In practice, companies either use ISO/IEC 27001:2022 with the 93 controls according to Appendix A or the BSI IT-Grundschutz with its modules. Both frameworks are accepted by the BSI as suitable evidence. Anyone who is already certified must integrate the NIS-2-specific requirements from Section 30 BSIG into the existing ISMS in the transition phase after October 2026 without breaking the certificate logic.
CIVAC links each of the 93 ISO controls in the workspace with the responsibility of the ISB, the scope, the maturity level and the next audit date. The Statement of Applicability is generated from this database and is no longer a separate document, but a view of the workspace. The risk treatment plans are derived from the identified risks, with responsibility for measures, due dates and effectiveness measurement. The internal audit program is planned in the workspace, the management reviews are documented, and the corrective actions are tracked. If the BSI requests a self-declaration in accordance with Section 39 BSIG-new, the declaration can be exported from the workspace, with the date, person responsible and full reference to the measures implemented. Audit-proof, documented, Section 30-proof. This interlinking of ISMS content and ISB responsibility is also the reason why certification bodies accept the CIVAC mandates as verifiable in the transition phase to ISO/IEC 27001:2022 because the auditor does not have to jump between the ISMS tool and the representative file. Supplier audits by major customers are served via the same database, meaning there is no need for a separate document route for customer questionnaires and the compliance function can use its time for risk work instead of file maintenance.
Turn reading into an assignment
The ISB obligation for KRITIS operators and NIS 2 facilities has been operational since the NIS 2 Implementation Act was passed. Anyone who is identified as a particularly important or important institution and does not yet have a formal order with an appointment certificate, reporting line and reporting path bears the risk of fines in accordance with Section 39 BSIG-new (up to 10 million euros or 2% of group sales for important institutions, up to 7 million euros or 1.4% for important institutions) and the personal liability risk of the management in accordance with Section 38 Paragraph 2 BSIG-new. Both risks do not only materialize in the incident, but rather in the supervisory control without an incident if the appointment certificate is not available.
CIVAC is a compliance platform and officer-as-a-service. Licence the workspace for your internal information security officer, or have our ISB order it. Both methods deliver the same standard: appointment certificate according to § 38 BSIG-new with all mandatory information, statement of applicability for the 93 controls according to ISO/IEC 27001:2022, 24-hour early warning and 72-hour follow-up reporting path to the BSI, documented reporting line to the management, EU data residency, SLA of two working days. The order is by email to info@civac.de or the contact form on civac.de. The intake is available within the first working day, the signed appointment certificate is in the workspace on the second working day, the reporting line is active in the same week and the reporting path to the BSI is configured. Turn reading into an assignment. The appointment certificate, signed, filed, verifiable. The auditor calls, the evidence is ready. Anyone who postpones this step today is not postponing the risk, but only the time at which it is realized; An order with an appointment certificate and an active reporting line is the only form in which the obligation from Section 38 BSIG-new is recognised as fulfilled in the audit.
FAQ
Which companies need to order an ISB according to NIS-2?
KRITIS operators, particularly important facilities (from 250 employees or 50 million euros in sales in NIS 2 sectors with a high degree of criticality) and important facilities (from 50 employees or 10 million euros in sales in the other NIS 2 sectors) are required to order. A total of around 29,500 companies in Germany are affected. The legal basis is Section 38 BSIG-new in conjunction with Section 30 BSIG-new and the appendices of Directive (EU) 2022/2555.
Can the IT manager also be an ISB?
A personal union with the IT management is often prone to conflict because the same person would have to implement and control security measures. BSI Standard 200-2 and supervisory practice require independence. In smaller institutions, a staff union may be permissible if the conflict is documented and mitigated through compensatory measures (such as external audits). Separation is standard for particularly important facilities.
What fines are there if you don't have an ISB order?
For essential facilities up to 10 million euros or 2% of global annual turnover, for important facilities up to 7 million euros or 1.4%. In addition, there is the personal liability of the management in accordance with Section 38 Paragraph 2 BSIG-new for violations of the supervisory obligation. Fines are imposed even without incident if the formal order cannot be proven in the audit.
What deadlines apply for the ISB report to the BSI in the event of an incident?
§ 32 BSIG-neu prescribes a three-stage reporting path: early warning within 24 hours of knowledge, follow-up report with first assessment within 72 hours, final report within one month. The deadlines start from knowledge, not from completed forensics. The ISB is the central person for classification, reporting and communication with the BSI.
How does the ISB differ from the data protection officer?
The ISB is responsible for information security in accordance with BSIG and ISO/IEC 27001, the DPO is responsible for the protection of personal data in accordance with GDPR and BDSG. The roles overlap (for example in data breaches that are also security incidents), but remain legally separate. Most institutions fill both roles separately to avoid conflicts of interest and regulatory questions.
How long does it take to order an external ISB via CIVAC?
Two working days. Day one includes the intake with sector, number of employees, ISMS status, conflict check against the officer pool and draft contract. Day two includes the signed appointment certificate, the notification to the responsible authority, the publication of the contact and the kick-off with the management. Thereafter, the rolling two business day SLA applies to risk assessments, ISMS reviews and incident response.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.