Step 3 · Gap analysis

The ten minimum measures under Section 30 BSIG What NIS2 requires in concrete terms.

Section 30 BSIG adopts the minimum measures from Art. 21(2) of the NIS2 Directive. They must be appropriate, proportionate and effective, and follow an all-hazards approach.

What it is about

The measures aim to prevent disruption to the availability, integrity and confidentiality of the systems, components and processes you use for your services, and to keep the impact of incidents as low as possible. What is appropriate depends on your risk exposure, your size, the cost of implementation and the likelihood and severity of possible incidents and their societal and economic impact.

Step 3Gap analysis
  • NIS262 %
  • ISO 2700148 %
  • AI Act35 %

Answers · 120

  • Yes 54
  • Partly 31
  • No 21
  • Open 14

Sample values

The ten areas

  1. 01

    Risk analysis and information system security policies

  2. 02

    Incident handling

  3. 03

    Business continuity, backup management and crisis management

  4. 04

    Supply chain security

  5. 05

    Security in acquisition, development and maintenance, including vulnerability handling

  6. 06

    Assessing the effectiveness of measures

  7. 07

    Basic training and awareness

  8. 08

    Use of cryptographic procedures

  9. 09

    Human resources security, access control and management of ICT systems, products and processes

  10. 10

    Multi-factor or continuous authentication, secured communications and emergency communications

Common mistakes

  • The risk analysis leaves out the supply chain.
  • There is no criterion for “significant” and no practised reporting route.
  • Restoring from backup has never been tested.

What an auditor wants to see

  • Approved policy and current risk report
  • Incident register and reporting templates
  • Restore test records and training records, including management

How UniqSuite helps

UniqSuite maps the ten areas as testable requirements and shows where they overlap with ISO 27001.

References

  • Section 30(1) and (2) BSIG
  • Directive (EU) 2022/2555, Art. 21
  • Implementing Regulation (EU) 2024/2690 for certain digital services

Frequently asked questions

Are there binding technical requirements?

For certain digital services, yes, in Implementing Regulation (EU) 2024/2690. For everyone else: appropriate, proportionate and effective, measured against your risk.

Does ISO 27001 cover all ten?

Largely, in substance. The mapping is a professional assessment, not an official concordance.

Which reporting deadlines apply to a significant incident?

An early warning without undue delay and within 24 hours at the latest, and an incident notification without undue delay and within 72 hours, each from becoming aware of the incident, and a final report no later than one month after the notification (Section 32(1) BSIG).

When is an incident significant?

When it has caused or can cause severe operational disruption of the services or financial loss for your entity. Or when it has affected or can affect others by causing considerable material or non-material damage (Section 2 No. 11 BSIG).

Do we have to prove implementation to the BSI?

All entities must document compliance (Section 30(1) BSIG). Operators of critical facilities prove implementation every three years through audits, inspections or certifications (Section 39 BSIG). For other entities, the BSI can order audits (Sections 61 and 62 BSIG).

See what this looks like in UniqSuite.

In half an hour we walk you through it with your own questions.

→Demo request

Show us your questions.

We will get back to you within two working days and arrange a demo of about 30 minutes – built around your own requirements.

Please fill in.

Please fill in.

Please fill in.

Please enter a valid email address.

Please use digits, spaces and + ( ) / - only.

We use your details solely to answer your request. Details in our privacy policy.