<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Bsi on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/bsi/</link><description>Recent content in Bsi on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/bsi/index.xml" rel="self" type="application/rss+xml"/><item><title>BSI C5</title><link>https://lesitedefrancois.be/en/compliance/bsi-c5/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/bsi-c5/</guid><description>&lt;p&gt;The &lt;strong&gt;BSI C5&lt;/strong&gt; (Cloud Computing Compliance Criteria Catalogue) is a German federal standard published by the BSI that defines minimum security requirements for cloud service providers. First released in 2016, the catalogue has undergone two major revisions: &lt;strong&gt;C5:2020&lt;/strong&gt; and the current &lt;strong&gt;C5:2026&lt;/strong&gt; (published 7 April 2026, replacing C5:2020). C5:2026 contains &lt;strong&gt;168 criteria&lt;/strong&gt; (up from 121 in C5:2020, a 39 % increase) structured across 17 domains aligned with ISO/IEC 27001 Annex A. The new version introduces a &lt;strong&gt;sub-criteria structure&lt;/strong&gt; aligned with the European EUCS scheme, and adds five major new requirement areas: &lt;strong&gt;Confidential Computing&lt;/strong&gt; (OPS-32/33: documented policies for Trusted Execution Environments and technical implementation of Remote Attestation), &lt;strong&gt;Container Management&lt;/strong&gt; (OPS-34/35: lifecycle security for containerized workloads), &lt;strong&gt;Post-Quantum Cryptography&lt;/strong&gt; (inventory of cryptographic assets and migration plan to quantum-resistant algorithms), &lt;strong&gt;AI transparency&lt;/strong&gt; (disclosure of AI use in internal control systems), and &lt;strong&gt;Supply Chain Security&lt;/strong&gt; (SBOM requirements, documented sub-processor audits). The catalogue is published in machine-readable YAML format for the first time. C5 is designed as an &lt;strong&gt;attestation standard&lt;/strong&gt; (not a certification): providers undergo a &lt;strong&gt;Type 2 audit&lt;/strong&gt; by an independent auditing firm (under IDW PS 880 or ISAE 3000), which verifies both the design and operational effectiveness of security controls over a period of at least six months. C5 is now &lt;strong&gt;effectively mandatory&lt;/strong&gt; in two key domains: since 1 July 2025, cloud providers processing healthcare data must hold a valid C5 Type 2 attestation under §393 SGB V (Social Code, Fifth Book), and the revised BSI-KritisV (2024) requires KRITIS operators to use C5-attested cloud services in security-relevant contexts. Public-sector procurement in Germany also increasingly demands C5 attestation. &lt;strong&gt;C5:2026 becomes mandatory on 1 June 2027&lt;/strong&gt; for all audit periods starting on or after that date. During the transition: C5:2020 audits remain valid without additional requirements until 28 February 2027; between 28 February and 31 May 2027, C5:2020 is still permitted but requires a transition roadmap to C5:2026 in the system description.&lt;/p&gt;</description></item><item><title>BSI IT-Grundschutz</title><link>https://lesitedefrancois.be/en/compliance/bsi-it-grundschutz/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/bsi-it-grundschutz/</guid><description>&lt;p&gt;&lt;strong&gt;BSI IT-Grundschutz&lt;/strong&gt; is Germany&amp;rsquo;s national framework for establishing, implementing, and certifying an Information Security Management System (ISMS). It is developed and maintained by the BSI (Bundesamt für Sicherheit in der Informationstechnik) and stands out from generic standards like ISO/IEC 27001 by its extreme level of prescriptive detail — the IT-Grundschutz Compendium contains hundreds of specific security building blocks (&amp;ldquo;Bausteine&amp;rdquo;) covering technical, organizational, infrastructure, and personnel aspects. The framework is defined across four BSI Standards: &lt;strong&gt;200-1&lt;/strong&gt; (ISMS requirements), &lt;strong&gt;200-2&lt;/strong&gt; (methodology with three approaches: Basis-Absicherung, Standard-Absicherung, Kern-Absicherung), &lt;strong&gt;200-3&lt;/strong&gt; (risk analysis), and &lt;strong&gt;200-4&lt;/strong&gt; (business continuity management). Organizations can pursue &lt;strong&gt;ISO 27001 certification based on IT-Grundschutz&lt;/strong&gt;, which is recognized as equivalent to standalone ISO 27001 but with the added rigor of the BSI&amp;rsquo;s detailed control catalog. Compliance is &lt;strong&gt;mandatory&lt;/strong&gt; for German federal agencies (Bundesbehörden) under the UP Bund framework and is strongly recommended — often contractually required — for KRITIS operators and public-sector contractors. A major modernization is underway: &lt;strong&gt;Grundschutz++&lt;/strong&gt;, introduced in 2025–2026, replaces the traditional PDF-based building blocks with OSCAL/JSON machine-readable catalogs, aligning with the NIS2 implementation requirement for a BSI-defined &amp;ldquo;state of the art.&amp;rdquo; The classic IT-Grundschutz remains valid for audits until end of 2028.&lt;/p&gt;</description></item><item><title>KRITIS (German Critical Infrastructure)</title><link>https://lesitedefrancois.be/en/compliance/kritis/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/kritis/</guid><description>&lt;p&gt;&lt;strong&gt;KRITIS&lt;/strong&gt; (Kritische Infrastrukturen) is Germany&amp;rsquo;s national regulatory framework for the security and resilience of critical infrastructure. It is enforced by the &lt;strong&gt;BSI&lt;/strong&gt; (Bundesamt für Sicherheit in der Informationstechnik — Federal Office for Information Security) and, for physical resilience, by the &lt;strong&gt;BBK&lt;/strong&gt; (Bundesamt für Bevölkerungsschutz und Katastrophenhilfe — Federal Office of Civil Protection). The framework is now governed by two primary laws: the &lt;strong&gt;NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG)&lt;/strong&gt;, which rewrote the BSI-Gesetz and entered into force on 6 December 2025, and the &lt;strong&gt;KRITIS-Dachgesetz (KRITISDachG)&lt;/strong&gt; for physical resilience, in force since 17 March 2026. Together they transpose the EU NIS2 Directive and CER Directive into German law. The scope expanded dramatically: from approximately 4,000 regulated entities under the previous IT-Sicherheitsgesetz 2.0 to around &lt;strong&gt;30,000 entities&lt;/strong&gt; now classified as either &amp;ldquo;besonders wichtige Einrichtungen&amp;rdquo; (particularly important, equivalent to NIS2 essential) or &amp;ldquo;wichtige Einrichtungen&amp;rdquo; (important). KRITIS applies to organizations in 18 sectors (energy, water, health, finance, transport, digital infrastructure, space, public administration, manufacturing, etc.) meeting defined size thresholds. Compliance is &lt;strong&gt;mandatory&lt;/strong&gt; with no transitional period: entities must register with the BSI, implement risk management (§30 BSIG), report security incidents within 24 hours (§32), and management is &lt;strong&gt;personally liable&lt;/strong&gt; (§38) for overseeing cybersecurity measures. Penalties reach up to €10M or 2 % of global turnover for particularly important entities.&lt;/p&gt;</description></item><item><title>VSA / VS-NfD (German Classified Information)</title><link>https://lesitedefrancois.be/en/compliance/vs-nfd/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/vs-nfd/</guid><description>&lt;p&gt;&lt;strong&gt;VS-NfD&lt;/strong&gt; (Verschlusssache — Nur für den Dienstgebrauch, &amp;ldquo;Classified — For Official Use Only&amp;rdquo;) is the lowest of Germany&amp;rsquo;s four classification levels (VS-NfD, VS-Vertraulich, Geheim, Streng Geheim). The legal and regulatory framework governing its handling consists of the &lt;strong&gt;Sicherheitsüberprüfungsgesetz (SÜG)&lt;/strong&gt; as the legal basis, the &lt;strong&gt;Verschlusssachenanweisung (VSA)&lt;/strong&gt; as the administrative directive for federal agencies (fundamentally revised in 2023), and the &lt;strong&gt;VS-NfD-Merkblatt&lt;/strong&gt; (Annex 4 to the Geheimschutzhandbuch) for private-sector companies handling classified contracts. The framework is administered by the &lt;strong&gt;BSI&lt;/strong&gt; for IT security aspects and the &lt;strong&gt;BMWK&lt;/strong&gt; (Federal Ministry for Economic Affairs) for industrial security (Geheimschutz in der Wirtschaft). Compliance is &lt;strong&gt;absolutely mandatory&lt;/strong&gt; — it is a legal obligation under the SÜG, and failure to comply results in loss of the ability to participate in classified government contracts. Key IT requirements include: using &lt;strong&gt;exclusively BSI-approved (zugelassen) IT security products&lt;/strong&gt; listed in the VS-Produktkatalog (BSI-Schrift 7164) for encryption, VPN, and security-critical functions; implementing an information security concept based on &lt;strong&gt;BSI IT-Grundschutz&lt;/strong&gt; (including risk analysis and Grundschutz-Check); applying the multi-layered security principle (prevention, detection, reaction); and personnel security clearances under the SÜG. Since &lt;strong&gt;1 September 2025&lt;/strong&gt;, a &lt;strong&gt;mandatory self-accreditation&lt;/strong&gt; (Selbstakkreditierung) obligation entered into force: every three years, the VS-NfD-responsible person must formally confirm to their management (and on request to the BMWK or the contracting authority) that all technical and organizational measures are fully implemented. The BSI&amp;rsquo;s IT-Grundschutz module &lt;strong&gt;CON.11.1&lt;/strong&gt; specifically addresses VS-NfD requirements that go beyond standard IT-Grundschutz measures.&lt;/p&gt;</description></item></channel></rss>