5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

Germany

§ 38 BSIG: the personal exposure of the Geschäftsleitung, and what it means for a foreign parent's German GmbH

§ 38 Abs. 1 BSIG obliges the Geschäftsleitung — the managing body — to umzusetzen und ihre Umsetzung zu überwachen: to implement the risk-management measures under § 30 and supervise their implementation. It does not oblige them to approve those measures. That is not pedantry. Approve is the word used in Article 20(1) of the NIS2 Directive and in the German ministerial draft; it is not in the enacted section, and it is the single most widespread mistranslation in English-language coverage of the German regime. The liability under Absatz 2 runs to the entity itself and under company law; the BSIG applies only subsidiarily. The new BSIG has been in force since 6 December 2025.

Also available in Deutsch

How Barzel applies here Start free with BarzelVault

One point of standing before anything else. The binding text is the German one — the BSIG as promulgated. This page is a working guide for a reader who does not read German; where it matters, check the instrument, and where this page and the German text diverge the German text governs. On this particular section that warning is the whole point of the page.

Since when has the new BSIG applied?

The German transposition is the NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG): Bundestag 13 November 2025, Bundesrat 21 November 2025, promulgated 5 December 2025. The new BSIG has applied since 6 December 2025. Germany missed the EU transposition deadline of 17 October 2024 by nearly fourteen months.

That delay has a practical consequence that outlives it. Preparatory papers, training decks and group NIS-2 programmes written during the drafting phase contain formulations that never made it into the Act. In § 38 this happened twice.

What does § 38 BSIG actually say?

The section has three subsections. Its official heading is already the answer: Umsetzungs-, Überwachungs- und Schulungspflicht für Geschäftsleitungen besonders wichtiger Einrichtungen und wichtiger Einrichtungen — the duty to implement, to supervise and to train. The word for approval does not appear in the heading or in the text.

  • Absatz 1: Geschäftsleitungen besonders wichtiger Einrichtungen und wichtiger Einrichtungen sind verpflichtet, die von diesen Einrichtungen nach § 30 zu ergreifenden Risikomanagementmaßnahmen umzusetzen und ihre Umsetzung zu überwachen. In English: the managing bodies of particularly important and important entities are obliged to implement the risk-management measures to be taken by those entities under § 30 and to supervise their implementation.
  • Absatz 2: managing bodies that breach their duties under Absatz 1 are liable to their entity for culpably caused loss under the company-law rules applicable to the entity's legal form. They are liable under the BSIG itself only where the applicable company-law provisions contain no liability rule of that kind.
  • Absatz 3: the members of the managing body must attend training regularly, in order to acquire sufficient knowledge and skills to identify and assess risks and risk-management practices in information security, and to judge their effect on the services the entity provides.

Correction 1: implement and supervise, not approve

The familiar summary says the managing body must approve the measures and oversee their implementation. That is what Article 20(1) of Directive (EU) 2022/2555 says — Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities — and it is what the German ministerial draft said. It is repeated to this day in professional commentary, in vendor material and in training packs. It is not what § 38 Abs. 1 BSIG says, and the difference is substantive.

An approval duty is discharged by a decision on a submission. A dated agenda item, a minute, a signature: done, and provably done. It is a point event, and the evidence of it is the minute.

An implementation and supervision duty is continuous. It requires the management level to be able to establish, on an ongoing basis, whether the measures are working. There is no single artefact that discharges it, and no date on which it is complete. A group that builds its German NIS-2 programme around an annual approval resolution has satisfied a duty German law does not impose and failed the one it does.

For a director's personal exposure the consequence is direct, because Absatz 2 measures the breach against Absatz 1. If the duty were approval, the defence would be the minute: the board approved the measures on this date, on the basis of this paper. Under the enacted wording that defence is incomplete on its face. The question a German court will be asked is not whether the managing director approved a programme but whether they implemented the measures and supervised their implementation — and what they can show for the period between the approval and the incident. An English-language control narrative that says the board approves the information security programme annually describes a control that does not answer the statutory question. Our register of corrections tracks this one.

Correction 2: the void waiver is not in the Act

The draft contained a sentence under which a waiver by the entity of compensation claims, or a settlement over them, would be void. That sentence did not become law, though it continues to be quoted in blog posts and on advisory pages. What applies instead are the general rules of German company law, including the waiting periods and consent requirements of the law on stock corporations.

To whom is the liability owed, and under which law?

The short form — managing directors are personally liable under NIS2 — is inaccurate in both directions. Absatz 2 is doubly bounded.

  1. Internal liability. The liability runs to the entity, not to customers or other injured parties. § 38 creates no external cause of action.
  2. A company-law standard. The cause of action and the standard of care come from the company law applicable to the legal form — for a GmbH, § 43 GmbHG; for an AG, § 93 AktG. The BSIG is expressly subsidiary and applies only where no such liability rule exists.

For German-law capital companies the BSIG liability therefore runs largely empty — not because the risk is smaller, but because it already existed. What § 38 does is define the duty: it fills the company-law standard of care with reviewable content. Before 6 December 2025 a claimant had to argue what a diligent managing director should have done about information security. Now the statute says so.

Which entities are caught, and what is the penalty?

CategoryThresholdsFine range
Besonders wichtige Einrichtungen (particularly important entities) ≥ 250 employees or annual turnover > EUR 50m and balance sheet total > EUR 43m; KRITIS operators regardless of size up to EUR 10m or 2 % of worldwide annual turnover
Wichtige Einrichtungen (important entities) ≥ 50 employees or turnover and balance sheet total each > EUR 10m up to EUR 7m or 1.4 % of worldwide annual turnover

The fine falls on the entity — and can itself become the loss whose compensation the entity claims from its managing body under § 38 Abs. 2. That loop is worth modelling explicitly in a group, because it converts a regulatory penalty into an internal claim against the parent's own appointee, brought by a subsidiary the parent controls.

Which entity in a group is actually caught, and who is the Geschäftsleitung?

This is the question that a group compliance function has to answer first, and it is not answered by an organisation chart.

The duty attaches to the German Einrichtung and to its own managing body. For a German GmbH that means the Geschäftsführer entered in the commercial register, personally. A group board, an EMEA management committee, a regional president or a global CISO is not the Geschäftsleitung of that entity unless its members hold that office. Where several entities in a structure are caught, each has its own managing body, its own duty and its own evidence; there is no consolidated discharge and no group filing.

Three consequences follow that are specific to a foreign parent.

  • Residence is irrelevant. A managing director resident in London, New York or Singapore is still the Geschäftsführer of the German entity, and Absatz 3 obliges that person to attend training regularly. It is not discharged by a group security function attending in their place.
  • The claim, if it comes, is German. It is a company-law claim brought by the German entity against its own appointee under § 43 GmbHG. Whether a group indemnity or a D&O programme written under another system of law answers that claim is a question to put to German counsel before an incident, not during one.
  • The person who owes the duty is rarely the person who took the decision. Security architecture, logging retention, integration permissions and the incident-response runbook are usually set at group level. The duty and the liability sit with someone who was in none of those meetings. That gap is the practical content of § 38 for a multinational, and it is closed by giving the German managing director sight of the controls, not by giving them a policy to sign.

How does Germany differ from its neighbours on this word?

The comparison with Denmark is the instructive one: the same Directive, two formulations. Denmark took the Directive's wording into the NIS 2-loven, LOV nr 434 af 06/05/2025, in force since 1 July 2025 — the ledelsesorgan godkender, approves, and oversees implementation. Belgium's NIS2 Act of 26 April 2024, in force since 18 October 2024, does the same.

Germany left the Directive's wording: the Geschäftsleitung implements and supervises. A group operating in both countries therefore cannot mirror its evidence. The Danish approval resolution does not discharge the German duty, and a single European control description written once, in English, around the word approve is wrong in exactly one Member State — the largest one it applies in.

Two further points of orientation. The United Kingdom's Cyber Security and Resilience Bill is not yet in force, at committee stage in the House of Lords. Norway's digitalsikkerhetsloven, in force since 1 October 2025, implements NIS1: NIS2 has not been incorporated into the EEA Agreement and does not apply there.

Which deadlines are already running?

Registration is due within three months of an entity first being affected — for entities caught at entry into force, by 6 March 2026. The BSI states that the statutory deadline has expired; the obligation continues to exist regardless. Changes must be notified within two weeks. Access runs through Mein Unternehmenskonto into the BSI portal. A group that registered its parent rather than the affected German entity has not registered.

StageDeadline
Early initial reportwithin 24 hours
Follow-up or detailed reportwithin 72 hours
Final reportwithin one month

The BSI's standard for the first stage is Schnelligkeit vor Vollständigkeit — speed before completeness. For a group that means the German entity must be able to file without waiting for a group approval loop in another time zone.

What does implement and supervise mean for automated and AI-driven processes?

For access management, backup and patching the question is unproblematic. It gets harder where systems act on their own: integrations with write access to finance systems, workflows that initiate payments, AI agents that interpret inputs and react to them. The managing body must be able to say what those systems may do and see that the controls hold. Three requirements follow.

A defined action boundary that somebody decided

Integration rights are rarely limited by amount, counterparty or type of action; usually they are inherited from the user account under which the integration was set up. That is a boundary nobody drew — and about which, therefore, there is no decision whose implementation could be supervised. The same reasoning underlies approving AI actions.

Controls that bite before execution

Monitoring and logging report what happened; they do not prevent it happening. Where an action has financial or legal effect, the question is whether a control stands before execution: a policy that refuses it, or a human release above defined thresholds. Supervision under Absatz 1 is more than an after-the-fact notification — and that distinction is exactly what separates it from an approval duty.

Evidence that survives long enough

Application logs rotate. If the record of what a system did exists only in log files with thirty-day retention, it no longer exists when the authority, the supervisory board or the insurer asks. A durable audit trail for AI agents is therefore not a side issue for § 38: without one, the supervision cannot be evidenced, and an unevidenced supervision is, in a liability claim, indistinguishable from none.

Why 24 hours is mainly a reconstruction problem

The deadlines have a rarely stated consequence: 24 hours is not much time to establish what actually happened. If an automated system has executed a series of actions and it cannot be determined on day one which of them were authorised, the early initial report goes out on an uncertain basis and the 72-hour report then corrects your own account. Report quality depends directly on how fast a sequence of actions can be reconstructed — a question of system architecture, and for a group also a question of whether the German entity holds its own evidence or must request it from a platform team elsewhere.

What has the KRITIS-Dachgesetz to do with it?

It is regularly conflated with the BSIG but is a separate act. The KRITIS-Dachgesetz transposes the CER Directive (EU) 2022/2557 and concerns the physical resilience of critical installations — access, site protection, continuity provision — not cybersecurity. It passed the Bundesrat on 6 March 2026; operator registration is envisaged by 17 July 2026. An entity caught by both has two registrations and two sets of running deadlines.

In practice

The core of § 38 is that somebody must answer for what the company's systems are allowed to do, and be able to show that they supervised it. BarzelVault applies policy and approval thresholds ahead of execution and issues signed audit receipts, across nine tools. BarzelOps runs governed cross-system workflow automation with durable state, approval checkpoints and tenant isolation, so a German entity's operations remain attributable to that entity.

How Barzel applies here

Frequently asked questions

Must the managing body approve the measures?

No. The Act requires them to implement the measures and supervise their implementation. The approval duty comes from Article 20(1) of the NIS2 Directive and from the German ministerial draft, and is not in § 38 Abs. 1 BSIG.

Are managing directors personally liable to third parties under NIS2?

No. Absatz 2 creates a liability to the entity itself under the company law of the relevant legal form — and under the BSIG only where that company law contains no liability rule.

Is a waiver of compensation claims void?

Not under the BSIG. The corresponding draft sentence did not become law.

Can the managing body delegate the duty?

The operational work, yes. The supervision duty and the training duty are not delegable, and the training duty attaches to each member personally.

Who is the Geschäftsleitung of a foreign parent's German GmbH?

The registered Geschäftsführer of that GmbH, whether or not resident in Germany. A group board or regional committee is not the Geschäftsleitung unless its members hold that office.

Is the registration deadline still open?

The three-month period expired on 6 March 2026 for entities affected at 6 December 2025, and the BSI records this. The obligation remains; changes must be notified within two weeks.

Where this leads

The German drafting choice looks minor and is not. By declining the Directive's verb, the legislator turned a governance formality into a standing operational duty, then routed the consequence through company law, where the machinery for enforcing it already exists. A foreign parent that reads only English-language coverage will find the wrong verb, build a control that satisfies it, and discover the difference when the German entity is asked what it supervised between the resolution and the incident.

In practice

Contain the incident first, prove what happened second — inside the reporting window.

Reporting clocks run in hours, and management liability turns on whether controls were implemented and supervised, not merely approved. Barzel isolates credentials, cuts an agent off in one action and keeps signed receipts of what ran — the material a notification and a board report are written from.

In forceThe new BSIG (NIS-2) has applied since 6 December 2025

BarzelVault

The AI action firewall: decide what an agent may do before it does it.

  • Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
  • Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
  • Credential isolation, spend and action limits, and an emergency kill switch.

Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

BarzelOps

Governed workflow automation across the systems that run the business.

  • Durable, idempotent execution: a timeout is retried once, never filed twice.
  • Human approval checkpoints that pause the workflow and resume it.
  • Isolation per entity or client, signed evidence receipts and a portable manifest; HubSpot, Xero, Gmail, Google Drive and Slack.

Free tier: 100 calls a dayPaid plans from $19 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Enterprise: written quote by email within two business days. No sales call.


Related

Sources

  1. BSIG in the version of the NIS2UmsuCG, promulgated 05.12.2025, in force since 06.12.2025 — in particular §§ 30 and 38 (Umsetzungs-, Überwachungs- und Schulungspflicht für Geschäftsleitungen besonders wichtiger Einrichtungen und wichtiger Einrichtungen).
  2. BSI, guidance on registration, reporting and evidence obligations under the BSIG.
  3. Directive (EU) 2022/2555 (NIS2), Article 20 (Governance); transposition deadline 17.10.2024.
  4. Directive (EU) 2022/2557 (CER); KRITIS-Dachgesetz, Bundesrat 06.03.2026.
  5. NIS 2-loven, LOV nr 434 af 06/05/2025 (Denmark), in force 01.07.2025.
  6. NIS2 Act of 26.04.2024 (Belgium), in force since 18.10.2024. No verified official URL used here.
  7. Cyber Security and Resilience Bill (United Kingdom), House of Lords committee stage — not yet in force.
  8. Digitalsikkerhetsloven (Norway), in force since 01.10.2025; NIS2 not incorporated into the EEA Agreement.
  9. § 43 GmbHG and § 93 AktG — the company-law liability provisions to which § 38 Abs. 2 BSIG refers. Not linked here: the register pages could not be independently verified for this edition.
  10. Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), in force since 29.07.2026 — for the parallel AI supervisory timetable.

This article is a working guide for English-speaking readers and does not constitute legal advice. The binding text is the German one. Position as at 3 September 2026.