§ 38 BSIG: management's duties, subsection by subsection
§ 38 BSIG has three subsections. Subsection 1: management implements the measures under § 30 BSIG and oversees their implementation. Subsection 2: if it culpably breaches this, it is liable to the company under company law. Subsection 3: it attends training regularly. The law prescribes neither a length nor a particular provider.
The wording, and what it means
The law is quoted in its German original, with what it means in plain words below.
Subsection 1
Geschäftsleitungen besonders wichtiger Einrichtungen und wichtiger Einrichtungen sind verpflichtet, die von diesen Einrichtungen nach § 30 zu ergreifenden Risikomanagementmaßnahmen umzusetzen und ihre Umsetzung zu überwachen.In plain words: Management makes sure the security measures are implemented and checks that this happens.
Subsection 2
Geschäftsleitungen, die ihre Pflichten nach Absatz 1 verletzen, haften ihrer Einrichtung für einen schuldhaft verursachten Schaden nach den auf die Rechtsform der Einrichtung anwendbaren Regeln des Gesellschaftsrechts. Nach diesem Gesetz haften sie nur, wenn die für die Einrichtung maßgeblichen gesellschaftsrechtlichen Bestimmungen keine Haftungsregelung nach Satz 1 enthalten.In plain words: If the company suffers damage because management culpably breached subsection 1, management is liable to it. Company law governs how, for a GmbH § 43 GmbHG.
Subsection 3
Die Geschäftsleitungen besonders wichtiger Einrichtungen und wichtiger Einrichtungen müssen regelmäßig an Schulungen teilnehmen, um ausreichende Kenntnisse und Fähigkeiten zur Erkennung und Bewertung von Risiken und von Risikomanagementpraktiken im Bereich der Sicherheit in der Informationstechnik zu erlangen sowie um die Auswirkungen von Risiken sowie Risikomanagementpraktiken auf die von der Einrichtung erbrachten Dienste beurteilen zu können.In plain words: Every member of management regularly learns to identify and assess IT risks and to judge what they mean for the business.
Subsection 3: training for management
Every member of management takes part in person. Nobody can attend on their behalf.
How often: the law says “regularly”. Its explanatory memorandum reads this as training offered at least every three years.
How long and with whom: the law sets neither a length nor an approval for providers. Classroom training, an online course, a webinar or in-house training all qualify.
Record who took part when and what was covered. The BSI can check compliance; for important entities, when facts point to a breach.
§ 38(3) BSIG · § 62 BSIG · Bundestag printed paper 21/1501, p. 154
Subsection 1: implement and oversee
Implement means: the measures from § 30 BSIG are in place in the business. Others can do the work, such as IT or a service provider.
Oversee means: management checks whether the measures are in place and working. The law does not set how often or in what form.
The EU directive also requires management to approve the measures (Art. 20(1) NIS 2). The German law does not use that word. It requires implementation.
§ 38(1) BSIG · Art. 20(1) NIS 2
Who counts as management
Management is every natural person who runs the business and represents the company under the law, the articles of association or the partnership agreement. In a GmbH that is the managing directors, in an AG the management board.
§ 30 BSIG says which measures the company takes. § 38 BSIG says who makes sure it happens.
§ 2 no. 13 BSIG
How liability works in detailAn example
A made-up company: an electric motor manufacturer with 140 employees and three managing directors.
The technical director attends classroom training at an education provider and receives a certificate of attendance.
The finance director takes an online course and saves the certificate as a PDF.
The sales director attends a webinar by his industry association. There is no certificate; he records the date and topic.
Each has one line in the records: who, when, which training, which topics. The company plans the next round at the latest three years later.
How the walkthrough does this
The walkthrough at nisd2.eu records what § 38 BSIG requires of management.
One step records the latest training of each member of management: one line per person, with date and type of training.
You can attach a certificate. After a webinar there sometimes is none.
nisd2.eu offers a course for management. You can also choose any other provider.
The management review records when management reviewed the status, what it decided and who does what by when.
At the end, management approves the documents in the app, signed in with its own account.
Common questions
How often does management have to be trained?
The law says “regularly”. The explanatory memorandum reads this as training offered at least every three years (Bundestag printed paper 21/1501, p. 154).
How long must training under § 38(3) BSIG last?
The law sets no minimum length. What matters is the aim: being able to identify and assess risks and judge their effect on the company's services.
Does the training provider need an approval?
No. The law requires neither an approval nor a certificate.
Does § 38 BSIG apply to every GmbH?
To the managing directors of every GmbH that is an essential or important entity. Whether it is depends on sector and size (§ 28 BSIG).
What is management liable for under § 38(2) BSIG?
For damage to its own company caused by culpably breaching its duties under subsection 1. Liability follows the company law of the legal form.
Sources
- BSI Act (BSIG) § 2 no. 13, §§ 30, 38, 62, gesetze-im-internet.de/bsig_2025
- Directive (EU) 2022/2555 (NIS 2), Art. 20, EUR-Lex
- Explanatory memorandum to the NIS2UmsuCG, Bundestag printed paper 21/1501, p. 154 (on § 38(3))
- § 43 GmbHG, gesetze-im-internet.de
In practice
Where this comes up in the walkthrough
The walkthrough turns this into steps you fill in, with the law explained beside each one. Open a step to see its screen, filled in for a made-up company.
What the walkthrough costs
€4,800 net a year, plus VAT
30 days money backBy invoice, due in 30 days. Cancel within the first 30 days: invoice cancelled or money back.
Guided NIS 2 implementation, step by step
A history of changes and sign-offs to show your regulator
Deadlines and reminders for each requirement
Security questionnaire for your suppliers
Export to PDF or CSV at any time
Been asked to handle NIS2?
In the end you have everything in one document: what is done, what is still open, and your management's approval with name and date. The app writes the texts.


