Competence Centre

Regulatory Expertise Center: IT Security in Germany and the EU

Guidance on regulatory requirements for IT security in life science and GxP, with verified primary sources from the EU and Germany, plus a clear bridge to data integrity, CSV and IT administration.

What does the Regulatory Expertise Center deliver?

The Regulatory Expertise Center places the EU and German IT security requirements for regulated environments in context. It is aimed at IT and compliance decision-makers in pharma, chemicals, biotechnology and medtech. They view cyber requirements not in isolation but together with GxP, data integrity and validated systems.

Every regulation here comes with a concise classification and a link to its official primary source. Added to that are the paths to the services with which cube one supports implementation.

IT security and GxP reinforce each other: risk management, access control and incident response also protect the integrity of electronic records and the availability of qualified systems.

Every regulation on this page answers three questions in the same order: Who is in scope?, In what form? and What to check now? For each one we name typical cases inside scope, typical cases outside, and one next step to check. Abbreviations carry their full name: hover over them, or tap them.

This page supports a first assessment and does not replace legal advice. What binds you is the text of the act or ordinance including its annexes. Scope under NIS 2 and the BSIG is a self-assessment: no authority issues a notice that assigns your status. In case of doubt, use the BSI guidance for NIS 2-regulated entities and involve your legal department.

IT security in the EU

At EU level, three legal acts shape IT security: the NIS 2 Directive, the Cyber Resilience Act and the GDPR. The legal form decides where you look things up. A regulation such as the CRA or the GDPR applies directly to companies. A directive such as NIS 2 addresses the member states and takes effect through their national laws.

NIS 2 Directive

The Directive (EU) 2022/2555 (NIS 2) is an EU directive. It addresses the member states, not companies directly. Each member state transposes it into its own law. For companies in Germany, the applicable law is therefore the BSIG, not the text of the directive. In substance, the directive sets the frame: risk management and reporting duties for essential and important entities in defined sectors, including health and the manufacture of certain critical products. For contrast: the CRA is a regulation and applies directly, without a national implementation act.

Who is in scope?

  • Essential and important entities in the sectors of Annexes I and II, including healthcare, manufacture of pharmaceutical products, medical devices, food, chemicals, digital infrastructure and research.
  • Classification follows from sector and company size together. A sector link alone is not enough.
  • Groups with sites in several member states assess country by country, because transposition is national and deadlines as well as thresholds can differ.
  • Not covered by NIS 2: requirements on individual products. Those come from the CRA.

In what form?

  • Organisational duties, not product duties: risk management, reporting of significant incidents, registration with the competent national body.
  • Minimum measures include incident handling, business continuity and crisis management, supply chain security, access control and cryptography.
  • Management accountability including training, plus supervision and sanctions under national law.

What to check now?

  • Settle first which national law applies to you. For German sites you assess the BSIG, not the text of the directive.
  • List your EU sites with country, activity and size figures. Every country needs its own answer.
  • Compare your activity against Annexes I and II of the directive and record the entity type you find in its exact wording.
  • Define who runs the assessment and who approves it. Without a named owner the result carries no weight.
  • Separately, check whether you make products available on the Union market. That question belongs to the CRA, not to NIS 2.

Next step Map your entity type and size class, then check the German duties in the BSIG. The scope funnel walks you through the classification in three stages.

NIS 2 Implementation Act and BSIG

The BSIG is the law that companies in Germany apply. To find out what NIS 2 means for your own operation, you check the BSIG and its annexes, not the text of the directive. The impulse came from the EU: the Act implementing the NIS 2 Directive (BGBl. 2025 I No. 301) contains as Article 1 the revised BSI Act (BSIG). For in-scope entities this brings registration, reporting and risk-management duties. The BSI provides guidance for NIS 2-regulated entities and self-assessment of scope.

Who is in scope?

  • Particularly important entities: operators of critical facilities under the BSI-KritisV, plus large companies matching the entity types in Annex 1, meaning from 250 employees or with more than 50 million euros annual turnover and more than 43 million euros balance sheet total.
  • Important entities: medium-sized companies matching the entity types in Annex 1 and Annex 2, meaning from 50 employees or with more than 10 million euros in both annual turnover and balance sheet total.
  • Entity types typical for life science: providers of healthcare services, companies carrying out research and development on medicinal products, manufacturers of pharmaceutical products, manufacturers of medical devices and in vitro diagnostics, food businesses in production and wholesale, manufacturers of chemicals, research organisations.
  • Also in scope are IT providers serving GxP sites where they qualify as managed service provider, managed security service provider, data centre or cloud provider. Digital infrastructure counts regardless of the customer's size.
  • Not automatically in scope: a consultancy, an engineering office or a contract laboratory that matches no entity type in the annexes or does not reach the size criteria. Sector and size must both be met.

In what form?

  • Registration with the BSI within the statutory deadline, stating entity type, sector and points of contact.
  • Reporting chain for significant incidents: initial report, update and final report, staggered by deadline.
  • Risk management measures reflecting the state of the art, including supply chain security, access control, cryptography, business continuity and crisis management, awareness and effectiveness reviews.
  • Management accountability: approval of the measures, oversight of implementation, mandatory training. Operators of critical facilities additionally owe evidence to the BSI.
  • Classification is a self-assessment: no notice is issued that assigns your status.

What to check now?

  • Map your entity type against Annex 1 and Annex 2 before you talk about numbers. Without an entity type the assessment ends here.
  • Determine headcount, annual turnover and balance sheet total for the relevant reference period, including affiliated companies.
  • Work through the BSI scope assessment tool and file the result with its date and the data it rests on.
  • Name the people who register, who report incidents and who in management approves the measures, each with a deputy.
  • For an operational self-assessment under the BSIG: NIS 2 check.

Next step Map your entity type against Annexes 1 and 2, then check the size class and document the result. For the operational BSIG self-assessment: NIS 2 check.

Cyber Resilience Act

The Cyber Resilience Act (Regulation (EU) 2024/2847) is an EU regulation. Unlike the NIS 2 Directive, it applies directly in every member state; no national implementation act is needed. It sets cybersecurity requirements for products with digital elements made available on the Union market. It covers software or hardware whose intended or foreseeable use includes a direct or indirect data connection to a device or network. Components made available separately count as well. There is no size threshold based on headcount, turnover or amount of code. What matters is your role on the market, not your industry.

Who is in scope?

  • Manufacturers who make a product with digital elements available on the Union market under their own name or trademark, wherever the company is based. Anyone who resells a purchased product under their own brand or substantially modifies it also counts as a manufacturer.
  • Importers and distributors, with their own verification and due diligence duties along the supply chain.
  • Not covered are purchasing and operation: a GxP laboratory that buys a connected HPLC system or a LIMS is a user. An evaluation tool used purely in house and never made available on the market is not a covered product either.
  • In scope as manufacturer: a monitoring device, an add-on module or an on-premise application that you place on the market as a cube one product or as a customer product.
  • Excluded are products covered by sector-specific Union law with equivalent requirements, in particular medical devices under the MDR and in vitro diagnostics under the IVDR, plus automotive, aviation and certain marine products. Standalone laboratory software without a medical purpose does not fall under that exclusion.
  • Free and open-source software outside a commercial activity is excluded. Open-source stewards who sustain such software for commercial use follow a separate, lighter regime.

In what form?

  • Product duties across the lifecycle: secure default configuration, vulnerability handling, security updates throughout the declared support period.
  • Market access as in the CE framework: risk assessment, technical documentation, conformity assessment, EU declaration of conformity and CE marking. Important and critical product classes follow stricter procedures, in part involving a notified body.
  • Reporting duties for actively exploited vulnerabilities and severe incidents. They apply from 11 September 2026, the remaining obligations from 11 December 2027.
  • Remote data processing belongs to the product where it is necessary for a product function and developed under the manufacturer's responsibility, for example a cloud backend without which a measuring device cannot deliver its evaluation. A pure cloud or software service without that product link is not caught by the CRA but may fall under NIS 2 and the BSIG.
  • Micro and small enterprises meet the same requirements but may keep the technical documentation in a simplified form.

What to check now?

  • Draw up a product list and enter your role for each product: manufacturer, importer, distributor or user.
  • Check per product whether a data connection to a device or network belongs to the intended use. Without it, there is no product with digital elements.
  • Map your products to the classes in the annexes of Regulation (EU) 2024/2847. That decides whether a notified body becomes necessary.
  • Separate placing on the market from your own operation. A tool used purely in house stays outside, a purchased product resold under your own brand does not.
  • Record per product the intended support period and who owns vulnerability reporting. The reporting duties start on 11 September 2026.

Next step List your digital products and settle your role for each one: manufacturer, importer, distributor or user. For implementation in a GxP context, see our software development for life science.

GDPR

The Regulation (EU) 2016/679 (GDPR), being a regulation, likewise applies directly. It requires appropriate technical and organisational measures to protect personal data, including under Art. 32. In regulated IT landscapes this mainly concerns access management and logging.

Who is in scope?

  • Controllers and processors who process personal data. There is no sector and no size threshold, so a contract laboratory with ten employees is in scope as well.
  • Typical in life science: employee data, study and subject data, training and qualification records, access and visitor logs, remote maintenance accounts of external providers.
  • Not in scope are pure process and measurement data without any link to a person. As soon as user IDs appear in the audit trail, that link exists.

In what form?

  • Technical and organisational measures under Art. 32, in particular access control, logging, encryption, resilience and restorability.
  • Documentation and contracts: record of processing activities, data processing agreements with IT providers, data protection impact assessment where the risk is high.
  • Notification of personal data breaches to the supervisory authority within 72 hours. This reporting line is separate from incident reporting to the BSI.
  • Overlap with GxP: the same user, role and audit trail concepts serve data protection and data integrity at once.

What to check now?

  • Reconcile your record of processing activities with the list of your GxP systems. Systems carrying user IDs in the audit trail are frequently missing there.
  • Check which remote maintenance and provider accounts are covered by a data processing agreement, and who keeps it current.
  • Make sure your reporting paths know two separate lines: 72 hours to the data protection authority, and independently of that the incident report to the BSI.
  • Clarify whether a data protection impact assessment under Art. 35 GDPR is required, for example for study and subject data or extensive access logging.

Next step Review the authorisation and logging concepts of your GxP systems against both sets of requirements. Support for this: IT administration in GxP environments.

IT security in Germany

For companies in Germany, the applicable IT security law sits in the BSIG. The NIS 2 Directive triggered its revision. Alongside it, the BSI standards provide the method and the BSI-KritisV defines the critical facilities.

BSI IT-Grundschutz

BSI IT-Grundschutz is a method, not a law. It provides a procedure and building blocks for information security management and, in practice, often sits alongside the ISO/IEC 27000 series. It creates no statutory obligation the way NIS 2 or the BSI-KritisV do. It becomes binding through a contract, a customer requirement, a funding condition, or as the implementation route you choose yourself.

Who is in scope?

  • By law, nobody. IT-Grundschutz assigns no scope, it describes a way of working.
  • Intended for manufacturers in pharma, medical technology and food production who build an ISMS or need to evidence one to customers and authorities.
  • IT providers serving GxP sites who want to show their security level in a traceable way, for example in supplier audits and questionnaires.
  • Entities under NIS 2, the BSIG or the BSI-KritisV that choose IT-Grundschutz as the implementation route for their risk management measures. The duty then comes from the law, the structure from IT-Grundschutz.
  • Companies aligning with ISO/IEC 27001 that address German clients or authorities in BSI terminology.
  • Laboratories and departments that manage audit-relevant data and want to document protection needs, measures and residual risks.

In what form?

  • A procedure following BSI Standards 200-1 to 200-3: structure analysis, protection needs assessment, modelling with the building blocks of the IT-Grundschutz Compendium, and risk analysis.
  • Choice of depth: basic, core or standard protection, graded by maturity, criticality and available time. BSI Standard 200-4 adds business continuity management.
  • Voluntary evidence: certification as ISO 27001 on the basis of IT-Grundschutz is possible but not mandatory. Without a certificate, IT-Grundschutz still evidences your own due diligence.
  • Touchpoint with GxP: authorisations, logging, change control and contingency planning are the same controls that Annex 11 and Part 11 address. Duplicated effort can be avoided.

What to check now?

  • Settle the trigger first: your own decision, a customer requirement, a tender, a funding condition, or the implementation route for a statutory duty. The trigger sets the scope, not the other way round.
  • Read customer contracts and supplier questionnaires literally: does the customer ask for IT-Grundschutz, for ISO/IEC 27001, or for a certificate from an accredited body? The three answers lead to very different effort.
  • Define the information domain you want to protect, then choose basic, core or standard protection.
  • Reconcile existing GxP documents against the building blocks of the IT-Grundschutz Compendium. Authorisation concepts, change control and contingency planning are often already in place.
  • For a self-assessment in the browser: BSI IT-Grundschutz check.

Next step First define the information domain you want to protect, then choose the protection variant. For a self-assessment: BSI IT-Grundschutz check.

BSI-KritisV

The BSI Critical Infrastructure Ordinance (BSI-KritisV) makes the notion of critical infrastructure measurable. For each sector it names the facility categories, the measurement criterion and a threshold. The standard threshold corresponds to supplying 500,000 people; the annexes derive the concrete values per category from it. Operators determine the supply level of their facilities every year by 31 March for the preceding calendar year. Whoever reaches the value operates a critical facility and counts as a particularly important entity under the revised BSIG. Since March 2026 the KRITIS umbrella act applies in addition. The ordinance it foresees for identifying critical facilities continues this method; by mid-2026 it had not yet entered into force.

Who is in scope?

  • Operators of facilities in the sectors energy, water, food, information technology and telecommunications, health, finance and insurance, transport, and municipal waste management. What is in scope is the facility, not the company as a whole.
  • Health, with thresholds: hospitals from 30,000 full inpatient cases per year, production and distribution facilities for prescription medicines from 4.65 million packs placed on the market per year, laboratories and laboratory information networks from 1.5 million orders per year, blood and plasma donation control systems from 34,000 units per year.
  • Food: facilities producing, treating or distributing food from 434,500 tonnes per year, and from 350 million litres per year for beverages.
  • Information technology: data centres (housing) from 3.5 megawatts of contractually agreed capacity, server farms from 10,000 physical or 15,000 virtual instances on annual average.
  • Not KRITIS despite being pharma: a QC laboratory with a few thousand orders, a single GMP line below the pack threshold, an engineering or consulting firm, a server room far below the capacity limit. Without a facility category or without the threshold, there is no critical facility.
  • Joint assessment: several facilities of the same kind in close spatial and operational connection count as one facility and can reach the threshold together.

In what form?

  • Identification first, duties second: the ordinance itself requires you to map your facilities to the categories of the annexes and to determine the supply level annually.
  • Timing: result by 31 March for the preceding calendar year, status as a critical facility from 1 April of the following year.
  • Once a facility is critical, the duties of the BSIG apply: registration, reporting of significant incidents to the BSI, and risk management reflecting the state of the art.
  • Additionally for operators of critical facilities: attack detection systems plus evidence towards the BSI, for example through audits or inspections.
  • The role is tied to the facility: a group can run one critical facility alongside many sites without KRITIS status.

What to check now?

  • Keep a facility register, not a site list. The status attaches to the individual facility.
  • Assign every facility to a facility category and record the measurement criterion: cases, packs, orders, tonnes, litres, megawatts or instances.
  • Determine the supply level for the preceding calendar year and meet the 31 March deadline. Keep the calculation basis on file.
  • Check whether several facilities of the same kind in close spatial and operational connection have to be assessed together, because they can reach the threshold jointly.
  • What binds you are the annexes: the full text of the BSI-KritisV.

Next step List your facilities with their volume or capacity figures and compare them with the annexes of the ordinance. For classification under the BSIG: NIS 2 check and the scope funnel.

Interface to GxP, CSV and data integrity

Cyber requirements do not replace GxP rules: they complement them. For electronic records and systems, the following remain relevant:

Who is in scope?

  • EU GMP Annex 11: holders of a manufacturing or import authorisation and their contractors, as soon as a computerised system creates, changes or retains GMP records. What counts is the GMP relevance of the individual system, not the IT landscape as a whole.
  • FDA 21 CFR Part 11: organisations that keep electronic records or electronic signatures required by an FDA regulation. This includes European sites manufacturing for the US market or using data in submissions.
  • Out of scope: systems without GxP relevance, such as accounting or an internal wiki. A spreadsheet with GMP relevance is in scope regardless of its size.
  • GAMP 5 is not a regulation but an ISPE guide. It binds nobody by law and is still expected regularly by contract or in audits.

In what form?

  • System level duties: risk based validation, documented requirements, supplier assessment as well as change and deviation management across the lifecycle.
  • Data integrity as the outcome: reviewed audit trail, access rights per role, backup and restore, archiving that stays readable throughout the retention period.
  • Part 11 in addition: the distinction between open and closed systems, requirements for electronic signatures and their link to the respective record.
  • Evidence is provided through documents and testing, not through registration with an authority. It is examined in inspections and customer audits.

What to check now?

  • Settle per system which trigger applies: operation under a manufacturing or import authorisation (Annex 11), supply to the US market or data in FDA submissions (Part 11), or a way of working expected by contract under GAMP 5.
  • Keep a system inventory with process context and risk class. Spreadsheets with GMP relevance belong in it, accounting and the internal wiki do not.
  • Check per system whether audit trail, role concept, backup and archiving are documented and tested, not merely present.
  • Compare your internal requirements against the original text of Annex 11 in EudraLex Volume 4. An in-house summary does not replace the wording.
  • For a self-assessment in the browser: Annex 11 check and Part 11 check.

Next step List your GxP relevant systems with their process context and risk class. Go deeper: Data Integrity, Computer System Validation (CSV) and IT Administration in GxP environments.

Quick checks for a first assessment

Public quick checks exist for the regulations on this page. Each check asks eight questions, shows your maturity level and names the next fields of action. No registration, straight in the browser.

EU

NIS 2 check

Assess scope, registration, reporting lines and risk management under NIS 2 and the BSIG.

Start the NIS 2 check
BSI

BSI IT-Grundschutz check

Determine the maturity of your ISMS and the right protection variant under BSI Standard 200-2.

Start the Grundschutz check
GxP

Data integrity check

Review ALCOA+, audit trail and authorisations in your GxP systems.

Start the Data Integrity check
EU GMP

Annex 11 check

Compare the requirements of EU GMP Annex 11 for computerised systems.

Start the Annex 11 check
FDA

Part 11 check

Evaluate electronic records and signatures against FDA 21 CFR Part 11.

Start the Part 11 check
GxP

Supplier qualification check

Place assessment, audits and monitoring of your IT and GxP suppliers.

Start the supplier check
EU AI ACT

EU AI Act check

Clarify risk class and duties for AI systems in a regulated environment.

Start the EU AI Act check

FAQ: Regulatory Expertise & IT Security

Which rules does the Regulatory Expertise Center cover?
The page covers six sets of rules: the NIS 2 Directive, the NIS 2 Implementation Act with the BSIG, the Cyber Resilience Act, the GDPR, BSI IT-Grundschutz and the BSI-KritisV. Every regulation answers the same three questions: who is in scope, in what form, what to check now. Each one links to its official primary source.
Which EU acts apply directly, and which do not?
The Cyber Resilience Act (EU) 2024/2847 and the GDPR (EU) 2016/679 are regulations and apply directly in every member state. The NIS 2 Directive (EU) 2022/2555 is a directive and takes effect only through national law. The legal form decides which text carries your duties.
How is NIS 2 implemented in Germany?
NIS 2 is a directive addressed to the member states, not to companies. Germany transposed it with the NIS 2 Implementation Act (BGBl. 2025 I No. 301), whose Article 1 contains the revised BSI Act (BSIG). Companies in Germany therefore assess the BSIG and its annexes, not the text of the directive. Classification is a self-assessment, no notice is issued.
How do IT security and GxP relate?
Access control, logging, change control and contingency planning meet cyber duties and at the same time protect the integrity of electronic records. For records and systems, EU GMP Annex 11, FDA 21 CFR Part 11 and GAMP 5 remain decisive. Cyber requirements do not replace GxP requirements, they come on top.

First assessment

Who is in scope, in what form, what to check now?

The funnel works from top to bottom and narrows as it goes. Stage 01 asks about sector and size, stage 02 about facility and threshold, stage 03 shows what falls out. Choose a stage by click, keyboard or tap.

Order of assessment

Each stage covers fewer organisations than the one before. A stage without a match does not mean the next one applies.

Stage in detail

Assess your scope

Always three questions: who, in what form, what to check now

Stage 01, NIS 2 and the BSIG. Two conditions must be met together: an entity type from Annex 1 or Annex 2 of the BSIG and the matching size class.

Who is in scope?

  • Manufacturers of pharmaceutical products, medical devices and in vitro diagnostics, providers of healthcare services, food production and wholesale, manufacturers of chemicals, research organisations.
  • IT providers serving GxP sites as managed service provider, data centre or cloud provider.
  • Particularly important from 250 employees, important from 50 employees, in each case alternatively via the turnover and balance sheet criteria.

In what form?

  • Registration with the BSI, reporting chain for significant incidents, risk management reflecting the state of the art.
  • Management accountability and training, plus effectiveness reviews of the measures.
  • Organisational duties, not product duties. Products are governed by the CRA.

What to check now?

  • Map the entity type against Annex 1 and Annex 2 in its exact wording before you talk about numbers.
  • Determine headcount, annual turnover and balance sheet total for the relevant period, affiliated companies included.
  • File the result with its date and data basis, and name the owners for registration and reporting. For a self-assessment: NIS 2 check.

What follows from it?

Applies to stage 01 and stage 02, not to stage 03

  • 01 Register

    Register the entity with the BSI, stating sector, entity type and point of contact. Operators of critical facilities additionally with the facility reference.

  • 02 Report

    Report significant incidents in a staggered chain: initial report, update, final report.

  • 03 Manage risk

    Implement measures reflecting the state of the art, include the supply chain, review effectiveness and involve the management level.

Method, not scope

Toolkit track: IT-Grundschutz and ISO/IEC 27001

This track sits beside the funnel, not inside it. It does not answer who is in scope but how you implement the duties from stages 01 and 02 in a structured way. Organisations in stage 03 use it too, whenever customers or clients ask for evidence.

  • BSI IT-Grundschutz

    Who is in scope? Voluntary, for anyone building an ISMS in German authority terminology. In what form? A procedure under BSI Standards 200-1 to 200-3, the building blocks of the compendium, and basic, core or standard protection.

  • ISO/IEC 27001

    Who is in scope? Voluntary or required by contract, frequently in international supply chains. In what form? A management system with a defined scope, risk treatment and control selection, with a certificate if wanted.

Read all stages as a list
  • Stage 01, NIS 2 and the BSIG. Who is in scope? An entity type under Annex 1 or 2 plus the size class, for example pharma manufacturers, medical technology, food production, chemicals, research, IT providers. In what form? Registration, reporting, risk management, management accountability. What to check now? Map the entity type, determine the size figures, file the result with its date and name the owners.
  • Stage 02, the BSI-KritisV and KRITIS. Who is in scope? Individual facilities in a category of the annexes above the threshold, for example a hospital from 30,000 cases, a medicines facility from 4.65 million packs, a laboratory from 1.5 million orders. In what form? Annual determination by 31 March, then BSIG duties including attack detection and evidence. What to check now? Keep a facility register, assign category and measurement criterion, evidence the supply level.
  • Stage 03, no case to answer. Who is in scope? A QC laboratory below the threshold, consulting and engineering without an entity type, a single GMP line below the pack threshold. In what form? No duties from these rules, but contractual requirements, GxP, the GDPR and where applicable the CRA. What to check now? Evidence sector, size and threshold again, read customer contracts literally, confirm the GxP and GDPR duties.
  • Toolkit track. IT-Grundschutz and ISO/IEC 27001 are method. They create no scope, they structure the implementation.

Request a regulatory orientation

Speak with our advisory team about NIS 2, the BSIG and IT security in GxP environments.

Get in touch