77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
§ 30(2) no. 5 BSIG: security in acquisition, development and maintenance. A scan is evidence of the measure, not fulfilment of the duty
IT Security & NIS-2

§ 30(2) no. 5 BSIG: security in acquisition, development and maintenance. A scan is evidence of the measure, not fulfilment of the duty

21 September 20269 min readBy CIVAC Redaktion
CIVAC

§ 30(2) no. 5 and no. 6 of the German BSI Act describe exactly what an automated code and policy scanner does. This article quotes both numbers and shows, from § 30(1) sentence 3 and § 38(1) BSIG, why the scan report is evidence but the documented obligation and the supervising management are what the statute actually requires.

The two numbers that describe a scanner

The BSI Act, in the version in force since the German NIS 2 implementation act, governs the risk-management measures of essential and important entities in § 30. Subsection 2 sentence 2, rendered here in our own translation, reads: “The measures must at least comprise the following”, followed by a list of ten numbers. Two of them describe exactly the activity an automated code and policy scanner carries out.

Number 5 reads: “security measures in the acquisition, development and maintenance of information technology systems, components and processes, including the management and disclosure of vulnerabilities”. Number 6 reads: “concepts and procedures for assessing the effectiveness of risk-management measures in the field of information technology security”. There is no official English version of the BSIG; the German text is authoritative.

Anyone who has source code, architecture documents and configuration checked against a stored security policy on every change is operating a security measure in development and maintenance within the meaning of number 5. Anyone who records, tracks and where necessary reports the vulnerabilities found is operating the management and disclosure of vulnerabilities within the meaning of the same number. And anyone who compares the results over time is operating a procedure for effectiveness assessment as number 6 describes it. That is not a generous reading. It is the activity the statutory text describes.

What follows: the scan report is evidence

What follows first is something positive for entities that run such a scanner. Its report is evidence for two of the ten numbers of § 30(2) BSIG. It should therefore not stay hidden in a development tool but be filed where the entity documents its risk-management measures. A scanner whose reports nobody keeps produces findings, but no evidence.

§ 30(1) sentence 3 BSIG: the sentence that no scan writes

§ 30(1) BSIG opens with the obligation to take “appropriate, proportionate and effective technical and organisational measures, specified in subsection 2”. The third sentence of the same subsection reads: “Compliance with the obligation under sentence 1 shall be documented by the entities.”

Three words of that sentence carry the weight. First, “the obligation”: what is documented is compliance with the entire obligation under sentence 1, that is with all measures specified in subsection 2, not only numbers 5 and 6. The risk-analysis concepts under number 1, incident handling under number 2, supply-chain security under number 4, training under number 7 and access control under number 9 are not files a scanner could read. They are tasks, contracts, instruction sessions and concepts. Second, “by the entities”: the addressee of the documentation duty is the entity, not its tool. Third, “shall be documented”: it is a free-standing duty, breached independently of whether the measures themselves were taken.

A scan report is therefore one building block of that documentation. It is not the documentation itself. Anyone who answers the question about § 30(1) sentence 3 BSIG with a binder of scan reports has evidenced two numbers out of ten and left eight open.

The duty that falls on a person: § 38(1) BSIG

The second provision is addressed not to the entity but to its management. § 38(1) BSIG reads: “Management bodies of essential entities and important entities are obliged to implement the risk-management measures to be taken by those entities under § 30 and to supervise their implementation.”

Implementing and supervising are two activities, and both presuppose a person who performs them. A scanner can be configured to run on every commit. It cannot decide that it will be deployed, which policy it checks, what happens with a critical finding, and whether the measure as a whole is still proportionate. Those decisions are made by management or by a person to whom management has delegated execution, and the supervision of that execution remains with management under § 38(1) BSIG. Subsection 2 attaches to this the liability towards the entity for culpably caused damage; subsection 3 the duty to attend training regularly.

This duty too, when fulfilled, leaves a record: decisions, ownership, reports to management, deadlines and their completion. A scan report can sit in that record. It cannot replace it, because it says nothing about who read it, assessed it and answered it with a decision.

The difference in one sentence

A scan evidences that a measure under § 30(2) no. 5 BSIG was carried out. The statute additionally requires that the entity documents compliance with the entire obligation and that a named management supervises implementation. The scan is input. The documented obligation and the supervising person are what § 30(1) sentence 3 and § 38(1) BSIG actually require.

What this becomes in practice

  • The scan report is filed as evidence, assigned to § 30(2) no. 5 and no. 6 BSIG, with date, the policy checked and the state checked.
  • Every finding that is not closed immediately in the development team gets an owner and a date. Only then does the history arise that evidences supervision under § 38(1) BSIG.
  • The remaining eight numbers of § 30(2) BSIG are run as recurring tasks, instruction sessions and audits. There is no scanner for them.
  • Management receives a report at a fixed cadence covering all ten numbers, and its decision on it is recorded.

In the CIVAC workspace the information security officer role is set up for exactly this structure: tasks with owner and due date, recurring audits with a criteria catalogue, trainings with attendance records and a documentation into which reports such as a scan result belong as attachments. The workspace does not check source code. It records that somebody did, what came out of it and who decided on it.

Where this article ends

Whether your organisation is an essential or an important entity within the meaning of § 28 BSIG, whether a particular scanner meets the requirements of number 5 in your case, and how far management's supervision duty reaches in an individual case are questions that require a legal examination of the individual case. CIVAC is not a law firm and does not provide legal advice. This article reproduces the wording of the statute and places it in context; the assessment of your case belongs with your appointed person or with someone authorised to give it.

Frequently asked questions

Is an automated code scan on every commit enough for § 30(2) no. 5 BSIG?

It is a security measure in development and maintenance within the meaning of number 5 and evidences that measure. Whether it is “appropriate, proportionate and effective” within the meaning of § 30(1) sentence 1 BSIG depends on what is checked and what happens with the findings. The scan fulfils neither the documentation duty of § 30(1) sentence 3 BSIG nor the supervision duty of § 38(1) BSIG.

Does § 30 BSIG expressly require a scanner or a particular tool?

No. § 30(2) sentence 1 BSIG requires the measures to comply with the state of the art and to take account of the relevant European and international standards, and sentence 2 lists the areas. Which tool an entity uses for this, the statute does not prescribe.

Who is liable if the measures under § 30 BSIG are not implemented?

§ 38(2) BSIG governs management's liability towards its entity for culpably caused damage under the rules of company law applicable to the entity's legal form. Liability under the BSIG itself applies, under § 38(2) sentence 2, only where the relevant company-law provisions contain no liability rule.

Do the scan reports have to be retained?

§ 30(1) sentence 3 BSIG requires compliance with the obligation to be documented and names no retention period. Anyone using the scan report as evidence for numbers 5 and 6 must keep it for as long as they want to rely on that evidence. A period in years is not in the statute, and this article does not invent one.

Does a scanner cover supply-chain security under § 30(2) no. 4 BSIG?

Number 4 requires “security of the supply chain including security-related aspects of the relationships with direct suppliers or service providers”. A scanner can check purchased components in your own code insofar as they exist as files. The relationship with a supplier, its contracts, certificates and reporting channels, does not exist as a file. That number is evidenced by supplier assessments and contracts, not by a scan.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles