What does the Regulatory Expertise Center deliver?
The Regulatory Expertise Center places the EU and German IT security requirements for regulated environments in context. It is aimed at IT and compliance decision-makers in pharma, chemicals, biotechnology and medtech. They view cyber requirements not in isolation but together with GxP, data integrity and validated systems.
Every regulation here comes with a concise classification and a link to its official primary source. Added to that are the paths to the services with which cube one supports implementation.
IT security and GxP reinforce each other: risk management, access control and incident response also protect the integrity of electronic records and the availability of qualified systems.
Every regulation on this page answers three questions in the same order: Who is in scope?, In what form? and What to check now? For each one we name typical cases inside scope, typical cases outside, and one next step to check. Abbreviations carry their full name: hover over them, or tap them.
This page supports a first assessment and does not replace legal advice. What binds you is the text of the act or ordinance including its annexes. Scope under NIS 2 and the BSIG is a self-assessment: no authority issues a notice that assigns your status. In case of doubt, use the BSI guidance for NIS 2-regulated entities and involve your legal department.
IT security in the EU
At EU level, three legal acts shape IT security: the NIS 2 Directive, the Cyber Resilience Act and the GDPR. The legal form decides where you look things up. A regulation such as the CRA or the GDPR applies directly to companies. A directive such as NIS 2 addresses the member states and takes effect through their national laws.
NIS 2 Directive
The Directive (EU) 2022/2555 (NIS 2) is an EU directive. It addresses the member states, not companies directly. Each member state transposes it into its own law. For companies in Germany, the applicable law is therefore the BSIG, not the text of the directive. In substance, the directive sets the frame: risk management and reporting duties for essential and important entities in defined sectors, including health and the manufacture of certain critical products. For contrast: the CRA is a regulation and applies directly, without a national implementation act.
Who is in scope?
- Essential and important entities in the sectors of Annexes I and II, including healthcare, manufacture of pharmaceutical products, medical devices, food, chemicals, digital infrastructure and research.
- Classification follows from sector and company size together. A sector link alone is not enough.
- Groups with sites in several member states assess country by country, because transposition is national and deadlines as well as thresholds can differ.
- Not covered by NIS 2: requirements on individual products. Those come from the CRA.
In what form?
- Organisational duties, not product duties: risk management, reporting of significant incidents, registration with the competent national body.
- Minimum measures include incident handling, business continuity and crisis management, supply chain security, access control and cryptography.
- Management accountability including training, plus supervision and sanctions under national law.
What to check now?
- Settle first which national law applies to you. For German sites you assess the BSIG, not the text of the directive.
- List your EU sites with country, activity and size figures. Every country needs its own answer.
- Compare your activity against Annexes I and II of the directive and record the entity type you find in its exact wording.
- Define who runs the assessment and who approves it. Without a named owner the result carries no weight.
- Separately, check whether you make products available on the Union market. That question belongs to the CRA, not to NIS 2.
Map your entity type and size class, then check the German duties in the BSIG. The scope funnel walks you through the classification in three stages.
NIS 2 Implementation Act and BSIG
The BSIG is the law that companies in Germany apply. To find out what NIS 2 means for your own operation, you check the BSIG and its annexes, not the text of the directive. The impulse came from the EU: the Act implementing the NIS 2 Directive (BGBl. 2025 I No. 301) contains as Article 1 the revised BSI Act (BSIG). For in-scope entities this brings registration, reporting and risk-management duties. The BSI provides guidance for NIS 2-regulated entities and self-assessment of scope.
Who is in scope?
- Particularly important entities: operators of critical facilities under the BSI-KritisV, plus large companies matching the entity types in Annex 1, meaning from 250 employees or with more than 50 million euros annual turnover and more than 43 million euros balance sheet total.
- Important entities: medium-sized companies matching the entity types in Annex 1 and Annex 2, meaning from 50 employees or with more than 10 million euros in both annual turnover and balance sheet total.
- Entity types typical for life science: providers of healthcare services, companies carrying out research and development on medicinal products, manufacturers of pharmaceutical products, manufacturers of medical devices and in vitro diagnostics, food businesses in production and wholesale, manufacturers of chemicals, research organisations.
- Also in scope are IT providers serving GxP sites where they qualify as managed service provider, managed security service provider, data centre or cloud provider. Digital infrastructure counts regardless of the customer's size.
- Not automatically in scope: a consultancy, an engineering office or a contract laboratory that matches no entity type in the annexes or does not reach the size criteria. Sector and size must both be met.
In what form?
- Registration with the BSI within the statutory deadline, stating entity type, sector and points of contact.
- Reporting chain for significant incidents: initial report, update and final report, staggered by deadline.
- Risk management measures reflecting the state of the art, including supply chain security, access control, cryptography, business continuity and crisis management, awareness and effectiveness reviews.
- Management accountability: approval of the measures, oversight of implementation, mandatory training. Operators of critical facilities additionally owe evidence to the BSI.
- Classification is a self-assessment: no notice is issued that assigns your status.
What to check now?
- Map your entity type against Annex 1 and Annex 2 before you talk about numbers. Without an entity type the assessment ends here.
- Determine headcount, annual turnover and balance sheet total for the relevant reference period, including affiliated companies.
- Work through the BSI scope assessment tool and file the result with its date and the data it rests on.
- Name the people who register, who report incidents and who in management approves the measures, each with a deputy.
- For an operational self-assessment under the BSIG: NIS 2 check.
Map your entity type against Annexes 1 and 2, then check the size class and document the result. For the operational BSIG self-assessment: NIS 2 check.
Cyber Resilience Act
The Cyber Resilience Act (Regulation (EU) 2024/2847) is an EU regulation. Unlike the NIS 2 Directive, it applies directly in every member state; no national implementation act is needed. It sets cybersecurity requirements for products with digital elements made available on the Union market. It covers software or hardware whose intended or foreseeable use includes a direct or indirect data connection to a device or network. Components made available separately count as well. There is no size threshold based on headcount, turnover or amount of code. What matters is your role on the market, not your industry.
Who is in scope?
- Manufacturers who make a product with digital elements available on the Union market under their own name or trademark, wherever the company is based. Anyone who resells a purchased product under their own brand or substantially modifies it also counts as a manufacturer.
- Importers and distributors, with their own verification and due diligence duties along the supply chain.
- Not covered are purchasing and operation: a GxP laboratory that buys a connected HPLC system or a LIMS is a user. An evaluation tool used purely in house and never made available on the market is not a covered product either.
- In scope as manufacturer: a monitoring device, an add-on module or an on-premise application that you place on the market as a cube one product or as a customer product.
- Excluded are products covered by sector-specific Union law with equivalent requirements, in particular medical devices under the MDR and in vitro diagnostics under the IVDR, plus automotive, aviation and certain marine products. Standalone laboratory software without a medical purpose does not fall under that exclusion.
- Free and open-source software outside a commercial activity is excluded. Open-source stewards who sustain such software for commercial use follow a separate, lighter regime.
In what form?
- Product duties across the lifecycle: secure default configuration, vulnerability handling, security updates throughout the declared support period.
- Market access as in the CE framework: risk assessment, technical documentation, conformity assessment, EU declaration of conformity and CE marking. Important and critical product classes follow stricter procedures, in part involving a notified body.
- Reporting duties for actively exploited vulnerabilities and severe incidents. They apply from 11 September 2026, the remaining obligations from 11 December 2027.
- Remote data processing belongs to the product where it is necessary for a product function and developed under the manufacturer's responsibility, for example a cloud backend without which a measuring device cannot deliver its evaluation. A pure cloud or software service without that product link is not caught by the CRA but may fall under NIS 2 and the BSIG.
- Micro and small enterprises meet the same requirements but may keep the technical documentation in a simplified form.
What to check now?
- Draw up a product list and enter your role for each product: manufacturer, importer, distributor or user.
- Check per product whether a data connection to a device or network belongs to the intended use. Without it, there is no product with digital elements.
- Map your products to the classes in the annexes of Regulation (EU) 2024/2847. That decides whether a notified body becomes necessary.
- Separate placing on the market from your own operation. A tool used purely in house stays outside, a purchased product resold under your own brand does not.
- Record per product the intended support period and who owns vulnerability reporting. The reporting duties start on 11 September 2026.
List your digital products and settle your role for each one: manufacturer, importer, distributor or user. For implementation in a GxP context, see our software development for life science.
GDPR
The Regulation (EU) 2016/679 (GDPR), being a regulation, likewise applies directly. It requires appropriate technical and organisational measures to protect personal data, including under Art. 32. In regulated IT landscapes this mainly concerns access management and logging.
Who is in scope?
- Controllers and processors who process personal data. There is no sector and no size threshold, so a contract laboratory with ten employees is in scope as well.
- Typical in life science: employee data, study and subject data, training and qualification records, access and visitor logs, remote maintenance accounts of external providers.
- Not in scope are pure process and measurement data without any link to a person. As soon as user IDs appear in the audit trail, that link exists.
In what form?
- Technical and organisational measures under Art. 32, in particular access control, logging, encryption, resilience and restorability.
- Documentation and contracts: record of processing activities, data processing agreements with IT providers, data protection impact assessment where the risk is high.
- Notification of personal data breaches to the supervisory authority within 72 hours. This reporting line is separate from incident reporting to the BSI.
- Overlap with GxP: the same user, role and audit trail concepts serve data protection and data integrity at once.
What to check now?
- Reconcile your record of processing activities with the list of your GxP systems. Systems carrying user IDs in the audit trail are frequently missing there.
- Check which remote maintenance and provider accounts are covered by a data processing agreement, and who keeps it current.
- Make sure your reporting paths know two separate lines: 72 hours to the data protection authority, and independently of that the incident report to the BSI.
- Clarify whether a data protection impact assessment under Art. 35 GDPR is required, for example for study and subject data or extensive access logging.
Review the authorisation and logging concepts of your GxP systems against both sets of requirements. Support for this: IT administration in GxP environments.
IT security in Germany
For companies in Germany, the applicable IT security law sits in the BSIG. The NIS 2 Directive triggered its revision. Alongside it, the BSI standards provide the method and the BSI-KritisV defines the critical facilities.
BSI IT-Grundschutz
BSI IT-Grundschutz is a method, not a law. It provides a procedure and building blocks for information security management and, in practice, often sits alongside the ISO/IEC 27000 series. It creates no statutory obligation the way NIS 2 or the BSI-KritisV do. It becomes binding through a contract, a customer requirement, a funding condition, or as the implementation route you choose yourself.
Who is in scope?
- By law, nobody. IT-Grundschutz assigns no scope, it describes a way of working.
- Intended for manufacturers in pharma, medical technology and food production who build an ISMS or need to evidence one to customers and authorities.
- IT providers serving GxP sites who want to show their security level in a traceable way, for example in supplier audits and questionnaires.
- Entities under NIS 2, the BSIG or the BSI-KritisV that choose IT-Grundschutz as the implementation route for their risk management measures. The duty then comes from the law, the structure from IT-Grundschutz.
- Companies aligning with ISO/IEC 27001 that address German clients or authorities in BSI terminology.
- Laboratories and departments that manage audit-relevant data and want to document protection needs, measures and residual risks.
In what form?
- A procedure following BSI Standards 200-1 to 200-3: structure analysis, protection needs assessment, modelling with the building blocks of the IT-Grundschutz Compendium, and risk analysis.
- Choice of depth: basic, core or standard protection, graded by maturity, criticality and available time. BSI Standard 200-4 adds business continuity management.
- Voluntary evidence: certification as ISO 27001 on the basis of IT-Grundschutz is possible but not mandatory. Without a certificate, IT-Grundschutz still evidences your own due diligence.
- Touchpoint with GxP: authorisations, logging, change control and contingency planning are the same controls that Annex 11 and Part 11 address. Duplicated effort can be avoided.
What to check now?
- Settle the trigger first: your own decision, a customer requirement, a tender, a funding condition, or the implementation route for a statutory duty. The trigger sets the scope, not the other way round.
- Read customer contracts and supplier questionnaires literally: does the customer ask for IT-Grundschutz, for ISO/IEC 27001, or for a certificate from an accredited body? The three answers lead to very different effort.
- Define the information domain you want to protect, then choose basic, core or standard protection.
- Reconcile existing GxP documents against the building blocks of the IT-Grundschutz Compendium. Authorisation concepts, change control and contingency planning are often already in place.
- For a self-assessment in the browser: BSI IT-Grundschutz check.
First define the information domain you want to protect, then choose the protection variant. For a self-assessment: BSI IT-Grundschutz check.
BSI-KritisV
The BSI Critical Infrastructure Ordinance (BSI-KritisV) makes the notion of critical infrastructure measurable. For each sector it names the facility categories, the measurement criterion and a threshold. The standard threshold corresponds to supplying 500,000 people; the annexes derive the concrete values per category from it. Operators determine the supply level of their facilities every year by 31 March for the preceding calendar year. Whoever reaches the value operates a critical facility and counts as a particularly important entity under the revised BSIG. Since March 2026 the KRITIS umbrella act applies in addition. The ordinance it foresees for identifying critical facilities continues this method; by mid-2026 it had not yet entered into force.
Who is in scope?
- Operators of facilities in the sectors energy, water, food, information technology and telecommunications, health, finance and insurance, transport, and municipal waste management. What is in scope is the facility, not the company as a whole.
- Health, with thresholds: hospitals from 30,000 full inpatient cases per year, production and distribution facilities for prescription medicines from 4.65 million packs placed on the market per year, laboratories and laboratory information networks from 1.5 million orders per year, blood and plasma donation control systems from 34,000 units per year.
- Food: facilities producing, treating or distributing food from 434,500 tonnes per year, and from 350 million litres per year for beverages.
- Information technology: data centres (housing) from 3.5 megawatts of contractually agreed capacity, server farms from 10,000 physical or 15,000 virtual instances on annual average.
- Not KRITIS despite being pharma: a QC laboratory with a few thousand orders, a single GMP line below the pack threshold, an engineering or consulting firm, a server room far below the capacity limit. Without a facility category or without the threshold, there is no critical facility.
- Joint assessment: several facilities of the same kind in close spatial and operational connection count as one facility and can reach the threshold together.
In what form?
- Identification first, duties second: the ordinance itself requires you to map your facilities to the categories of the annexes and to determine the supply level annually.
- Timing: result by 31 March for the preceding calendar year, status as a critical facility from 1 April of the following year.
- Once a facility is critical, the duties of the BSIG apply: registration, reporting of significant incidents to the BSI, and risk management reflecting the state of the art.
- Additionally for operators of critical facilities: attack detection systems plus evidence towards the BSI, for example through audits or inspections.
- The role is tied to the facility: a group can run one critical facility alongside many sites without KRITIS status.
What to check now?
- Keep a facility register, not a site list. The status attaches to the individual facility.
- Assign every facility to a facility category and record the measurement criterion: cases, packs, orders, tonnes, litres, megawatts or instances.
- Determine the supply level for the preceding calendar year and meet the 31 March deadline. Keep the calculation basis on file.
- Check whether several facilities of the same kind in close spatial and operational connection have to be assessed together, because they can reach the threshold jointly.
- What binds you are the annexes: the full text of the BSI-KritisV.
List your facilities with their volume or capacity figures and compare them with the annexes of the ordinance. For classification under the BSIG: NIS 2 check and the scope funnel.
Interface to GxP, CSV and data integrity
Cyber requirements do not replace GxP rules: they complement them. For electronic records and systems, the following remain relevant:
- EU GMP Annex 11 (EudraLex Volume 4)
- FDA 21 CFR Part 11
- GAMP 5 (ISPE)
Who is in scope?
- EU GMP Annex 11: holders of a manufacturing or import authorisation and their contractors, as soon as a computerised system creates, changes or retains GMP records. What counts is the GMP relevance of the individual system, not the IT landscape as a whole.
- FDA 21 CFR Part 11: organisations that keep electronic records or electronic signatures required by an FDA regulation. This includes European sites manufacturing for the US market or using data in submissions.
- Out of scope: systems without GxP relevance, such as accounting or an internal wiki. A spreadsheet with GMP relevance is in scope regardless of its size.
- GAMP 5 is not a regulation but an ISPE guide. It binds nobody by law and is still expected regularly by contract or in audits.
In what form?
- System level duties: risk based validation, documented requirements, supplier assessment as well as change and deviation management across the lifecycle.
- Data integrity as the outcome: reviewed audit trail, access rights per role, backup and restore, archiving that stays readable throughout the retention period.
- Part 11 in addition: the distinction between open and closed systems, requirements for electronic signatures and their link to the respective record.
- Evidence is provided through documents and testing, not through registration with an authority. It is examined in inspections and customer audits.
What to check now?
- Settle per system which trigger applies: operation under a manufacturing or import authorisation (Annex 11), supply to the US market or data in FDA submissions (Part 11), or a way of working expected by contract under GAMP 5.
- Keep a system inventory with process context and risk class. Spreadsheets with GMP relevance belong in it, accounting and the internal wiki do not.
- Check per system whether audit trail, role concept, backup and archiving are documented and tested, not merely present.
- Compare your internal requirements against the original text of Annex 11 in EudraLex Volume 4. An in-house summary does not replace the wording.
- For a self-assessment in the browser: Annex 11 check and Part 11 check.
List your GxP relevant systems with their process context and risk class. Go deeper: Data Integrity, Computer System Validation (CSV) and IT Administration in GxP environments.
Quick checks for a first assessment
Public quick checks exist for the regulations on this page. Each check asks eight questions, shows your maturity level and names the next fields of action. No registration, straight in the browser.
NIS 2 check
Assess scope, registration, reporting lines and risk management under NIS 2 and the BSIG.
Start the NIS 2 checkBSI IT-Grundschutz check
Determine the maturity of your ISMS and the right protection variant under BSI Standard 200-2.
Start the Grundschutz checkData integrity check
Review ALCOA+, audit trail and authorisations in your GxP systems.
Start the Data Integrity checkAnnex 11 check
Compare the requirements of EU GMP Annex 11 for computerised systems.
Start the Annex 11 checkPart 11 check
Evaluate electronic records and signatures against FDA 21 CFR Part 11.
Start the Part 11 checkSupplier qualification check
Place assessment, audits and monitoring of your IT and GxP suppliers.
Start the supplier checkEU AI Act check
Clarify risk class and duties for AI systems in a regulated environment.
Start the EU AI Act check