KRITIS Reporting Requirements Under Section 39 of the BSIG: The Most Important Changes for Operators
This text was generated using artificial intelligence (AI).The BSI Act (BSIG) established new regulations governing the requirements for operators of critical infrastructure (KRITIS) to provide evidence. The previous Section 8a of the BSIG (old version) was replaced by § 39 BSIG replaced. The most notable change is the extension of the verification cycle from two to three years. At the same time, the new regulation places greater emphasis on the continuous remediation of security vulnerabilities through a formalized monitoring process conducted by the BSI.
An overview of the key points:
- Rules: BSI Act (BSIG), Section 39
- Affected individuals: Operators of critical infrastructure pursuant to the BSI Critical Infrastructure Regulation (BSI-KritisV)
- New verification cycle: Every 3 years (previously every 2 years)
- Effective as of: December 6, 2025
The New Legal Framework: From Two to Three Years
The key change in Section 39 of the BSIG is the extension of the audit cycle. KRITIS operators must now demonstrate every three years, through security audits, inspections, or certifications, that their IT security measures are state-of-the-art. The measures subject to this demonstration are those specified in Section 30(1), first sentence, in conjunction with Section 31(1) and (2) of the BSIG. This amendment is intended to reduce the burden associated with periodic inspections and to focus on fostering a sustainable security culture. The legal basis was most recently amended on March 17, 2026, by the Act Implementing Directive (EU) 2022/2557 (CER Directive).
The Federal Office for Information Security (BSI) has already comprehensively revised its „Guidance on Providing Evidence“ for 2025 to reflect the new requirements. This document is essential for the practical implementation of the legal requirements.
Deadlines, Thresholds, and Transitional Provisions
The reporting requirements apply to all organizations whose facilities exceed the thresholds defined in the BSI-KritisV. Operators are required to report this annually by March 31 to be reviewed. If the threshold is exceeded, the facility is considered critical infrastructure as of April 1 and must be registered with the BSI.
For operators who were already subject to reporting requirements before the new law took effect, the law provides that § 39(3) BSIG provides for a transitional arrangement: The BSI will set the next verification date no earlier than three years after the last verification was completed.
The Verification Process and BSI Deficiency Monitoring
If security vulnerabilities are identified during the audit, a formalized process to address them is initiated. Operators must develop a binding implementation plan that describes in detail how and by when the identified vulnerabilities will be resolved.
A key component of the new process is the BSI Deficiency Monitoring. In this context, operators must submit an updated list of deficiencies to the BSI at regular intervals—usually quarterly—and document the progress of the corrective measures. This process shifts the focus from a one-time audit to a continuous and verifiable improvement process. In the event of serious deficiencies or significant delays, the BSI may order implementation under threat of penalty payments. According to the BSI, a penalty payment is generally imposed only if the set deadline for rectification is not met.
How LocateRisk Supports Compliance with Section 39 of the BSIG
Compliance with the documentation requirements under Section 39 of the BSIG requires complete transparency regarding an organization’s own IT attack surface. Complete and up-to-date documentation of all externally accessible systems is a fundamental requirement for any security certification submitted to the BSI—and, at the same time, one of the most common gaps in audit preparation.
LocateRisk helps KRITIS operators continuously build this data foundation. The platform automatically inventories all externally accessible IT systems—including forgotten subdomains, unused cloud assets, and shadow IT—that might otherwise fall outside the scope of an audit. Configuration drifts, such as unexpected open ports or misconfigurations, are continuously detected and documented, enabling operators to maintain an up-to-date, verifiable overview of their attack surface at all times.
Since the resilience of KRITIS operators also depends on their service providers and suppliers, a systematic vendor risk management (VRM) approach may also be beneficial. LocateRisk automatically and continuously assesses the security posture of third-party providers and provides data to identify and manage risks in the supply chain.
As a „Made in Germany“ solution hosted in certified German data centers, LocateRisk is designed to meet the requirements of the GDPR and thus helps demonstrate secure and sovereign data processing.
Sources and further information
—
A note on our own behalf: This article reflects the legal situation as of the date of publication. Since IT law and compliance requirements are highly complex, this text is intended solely as a general guide and does not constitute legally binding advice. If in doubt, we recommend seeking legal counsel regarding implementation within your company. We assume no liability for the content.
Frequently Asked Questions About Section 39 of the BSIG
The key change is the extension of the compliance cycle from two to three years. At the same time, the BSI Vulnerability Monitoring system—a formalized process for tracking security vulnerabilities—was introduced, which requires regular (usually quarterly) reporting to the BSI.
Operators must verify annually, by the deadline of March 31, whether their systems exceed the thresholds specified in the BSI-KritisV. If the thresholds are exceeded, the registration and reporting requirements take effect as of April 1.
The operator must prepare a detailed implementation plan to remedy the deficiencies and submit it to the BSI. Progress is monitored as part of the BSI’s deficiency monitoring process, which typically requires quarterly status reports. If deadlines are not met, the BSI may impose fines; according to the BSI, these generally become due only after a set deadline for rectification has passed without resolution.
As of August 14, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.