§ 38 BSIG · Art. 20 NIS 2

§ 38 BSIG: management's duties, subsection by subsection

§ 38 BSIG has three subsections. Subsection 1: management implements the measures under § 30 BSIG and oversees their implementation. Subsection 2: if it culpably breaches this, it is liable to the company under company law. Subsection 3: it attends training regularly. The law prescribes neither a length nor a particular provider.

Get started
Simon OrzelCory Hisey

Rather talk to us first?

Simon OrzelSimon Orzel·

The wording, and what it means

The law is quoted in its German original, with what it means in plain words below.

Subsection 1

Geschäftsleitungen besonders wichtiger Einrichtungen und wichtiger Einrichtungen sind verpflichtet, die von diesen Einrichtungen nach § 30 zu ergreifenden Risikomanagementmaßnahmen umzusetzen und ihre Umsetzung zu überwachen.

In plain words: Management makes sure the security measures are implemented and checks that this happens.

Subsection 2

Geschäftsleitungen, die ihre Pflichten nach Absatz 1 verletzen, haften ihrer Einrichtung für einen schuldhaft verursachten Schaden nach den auf die Rechtsform der Einrichtung anwendbaren Regeln des Gesellschaftsrechts. Nach diesem Gesetz haften sie nur, wenn die für die Einrichtung maßgeblichen gesellschaftsrechtlichen Bestimmungen keine Haftungsregelung nach Satz 1 enthalten.

In plain words: If the company suffers damage because management culpably breached subsection 1, management is liable to it. Company law governs how, for a GmbH § 43 GmbHG.

Subsection 3

Die Geschäftsleitungen besonders wichtiger Einrichtungen und wichtiger Einrichtungen müssen regelmäßig an Schulungen teilnehmen, um ausreichende Kenntnisse und Fähigkeiten zur Erkennung und Bewertung von Risiken und von Risikomanagementpraktiken im Bereich der Sicherheit in der Informationstechnik zu erlangen sowie um die Auswirkungen von Risiken sowie Risikomanagementpraktiken auf die von der Einrichtung erbrachten Dienste beurteilen zu können.

In plain words: Every member of management regularly learns to identify and assess IT risks and to judge what they mean for the business.

Subsection 3: training for management

Every member of management takes part in person. Nobody can attend on their behalf.

How often: the law says “regularly”. Its explanatory memorandum reads this as training offered at least every three years.

How long and with whom: the law sets neither a length nor an approval for providers. Classroom training, an online course, a webinar or in-house training all qualify.

Record who took part when and what was covered. The BSI can check compliance; for important entities, when facts point to a breach.

§ 38(3) BSIG · § 62 BSIG · Bundestag printed paper 21/1501, p. 154

Subsection 1: implement and oversee

Implement means: the measures from § 30 BSIG are in place in the business. Others can do the work, such as IT or a service provider.

Oversee means: management checks whether the measures are in place and working. The law does not set how often or in what form.

The EU directive also requires management to approve the measures (Art. 20(1) NIS 2). The German law does not use that word. It requires implementation.

§ 38(1) BSIG · Art. 20(1) NIS 2

Who counts as management

Management is every natural person who runs the business and represents the company under the law, the articles of association or the partnership agreement. In a GmbH that is the managing directors, in an AG the management board.

§ 30 BSIG says which measures the company takes. § 38 BSIG says who makes sure it happens.

§ 2 no. 13 BSIG

How liability works in detail

An example

A made-up company: an electric motor manufacturer with 140 employees and three managing directors.

The technical director attends classroom training at an education provider and receives a certificate of attendance.

The finance director takes an online course and saves the certificate as a PDF.

The sales director attends a webinar by his industry association. There is no certificate; he records the date and topic.

Each has one line in the records: who, when, which training, which topics. The company plans the next round at the latest three years later.

How the walkthrough does this

The walkthrough at nisd2.eu records what § 38 BSIG requires of management.

One step records the latest training of each member of management: one line per person, with date and type of training.

You can attach a certificate. After a webinar there sometimes is none.

nisd2.eu offers a course for management. You can also choose any other provider.

The management review records when management reviewed the status, what it decided and who does what by when.

At the end, management approves the documents in the app, signed in with its own account.

Record your management's training

Common questions

How often does management have to be trained?

The law says “regularly”. The explanatory memorandum reads this as training offered at least every three years (Bundestag printed paper 21/1501, p. 154).

How long must training under § 38(3) BSIG last?

The law sets no minimum length. What matters is the aim: being able to identify and assess risks and judge their effect on the company's services.

Does the training provider need an approval?

No. The law requires neither an approval nor a certificate.

Does § 38 BSIG apply to every GmbH?

To the managing directors of every GmbH that is an essential or important entity. Whether it is depends on sector and size (§ 28 BSIG).

What is management liable for under § 38(2) BSIG?

For damage to its own company caused by culpably breaching its duties under subsection 1. Liability follows the company law of the legal form.

Sources

  • BSI Act (BSIG) § 2 no. 13, §§ 30, 38, 62, gesetze-im-internet.de/bsig_2025
  • Directive (EU) 2022/2555 (NIS 2), Art. 20, EUR-Lex
  • Explanatory memorandum to the NIS2UmsuCG, Bundestag printed paper 21/1501, p. 154 (on § 38(3))
  • § 43 GmbHG, gesetze-im-internet.de

In practice

Where this comes up in the walkthrough

The walkthrough turns this into steps you fill in, with the law explained beside each one. Open a step to see its screen, filled in for a made-up company.

  1. Governance & Liability

    Get management trained

    Every member of management, regularly.

  2. Effectiveness Assessment

    Record the management review

    Management checks whether the measures work and approves your documents.

What the walkthrough costs

NIS 2 walkthrough
Guided implementation at nisd2.eu.

€4,800 net a year, plus VAT

30 days money back

By invoice, due in 30 days. Cancel within the first 30 days: invoice cancelled or money back.

Guided NIS 2 implementation, step by step

A history of changes and sign-offs to show your regulator

Deadlines and reminders for each requirement

Security questionnaire for your suppliers

Export to PDF or CSV at any time

Pricing and terms

Been asked to handle NIS2?

In the end you have everything in one document: what is done, what is still open, and your management's approval with name and date. The app writes the texts.

Get started
Simon OrzelCory Hisey

Rather talk to us first?

Pricing and terms
The NIS2 walkthrough: your path step by step, the first items done