NIS2
Management liability under § 38 BSIG: Risks beyond fines
§ 38 BSIG requires management to implement measures, oversee them and attend training. Understand liability to the entity, fines and supervisory action.
By Chris Müller · Published 17 September 2026 · 6 min read
Under § 38 BSIG, management must implement risk management measures, oversee their implementation and attend training regularly. A culpable breach that causes loss may result in liability to the entity itself. Regulatory fines and supervisory measures are separate legal mechanisms. The often-cited EUR 10 million figure is not a standard amount of personal liability.
Author: Chris Müller. Legal position and editorial review: September 5, 2026.
Who is subject to § 38 BSIG?
The provision applies to the management of essential and important entities under the German BSIG, subject to any relevant exemption. Under § 2 number 13 BSIG, management means the natural person appointed by law, the entity's statutes or its articles of association to manage and represent it. Having “information security” in a job description does not, by itself, place someone under these management duties.
First check the entity's classification and the exemptions in § 28 BSIG. Other statutory rules may apply, particularly in energy, telecommunications and finance. You can prepare this assessment using the guide to determining whether NIS2 applies.
Implementation and oversight require documented decisions
Under § 38 paragraph 1 BSIG, management must implement the measures required by § 30 and oversee their implementation. Managers do not have to perform every technical task themselves. They need clear responsibilities and suitable information. The people responsible must report significant deficiencies to them in time.
Managers need to see unresolved risks even if the overall status is green. Ask which important service is affected, which safeguard is missing and when a decision is needed. If implementation is delayed, include interim safeguards and the consequences of that delay in the report.
The standard follows from § 30 BSIG: measures must be proportionate to the risk and effective, and compliance must be documented. Alongside the policy, check whether a recovery test met the agreed objective and whether the responsible people resolved any deficiency found during testing.
Liability to the entity: Breach, fault and loss
Under § 38 paragraph 2, managers are liable to their entity for losses they culpably cause, under the company-law rules applicable to the entity's legal form. The subsidiary liability rule in the BSIG applies only if those rules contain no corresponding liability provision. For a GmbH, § 43 GmbHG is particularly relevant; for the management board of an Aktiengesellschaft, it is § 93 AktG.
A successful attack therefore does not, by itself, establish personal liability. The specific breach of duty, fault, loss and causal connection must be assessed. The absence of a fine does not automatically prevent a company-law claim either. The entity may have suffered losses from inadequate security arrangements that need to be assessed independently of any fine proceedings.
Obtain a separate legal assessment of whether, and to what extent, a fine imposed on the entity can be recovered from its managers. Record recovery costs, business interruption and other losses separately so that each can be assessed in the particular case.
How the BSIG distinguishes fine limits
§ 65 BSIG sets different maximum fines for different offenses. The amounts below are statutory ceilings for the specified offenses. They are not amounts that must automatically be imposed. Any actual penalty requires an assessment of the offense and its circumstances.
| Example of an offense | Essential entity | Important entity |
|---|---|---|
| Certain breaches of duties to implement measures, document compliance or report incidents | Up to EUR 10 million | Up to EUR 7 million |
| The same specified offenses where total turnover exceeds EUR 500 million | Up to 2% of total turnover | Up to 1.4% of total turnover |
| Covered offenses involving inaccurate or late registration information | Up to EUR 500,000 | Up to EUR 500,000 |
The higher fixed limits apply to § 65 paragraph 2 number 1 letter d, numbers 2 to 5 and 9, read together with paragraph 5 number 1. The turnover-based rules appear in paragraphs 6 to 8 and include the worldwide turnover of the undertaking to which the entity belongs in the financial year preceding the authority's decision. Registration offenses are covered, among other provisions, by paragraph 2 number 6 and paragraph 5 number 5. Other offenses have their own limits.
Calling something a “NIS2 breach” is therefore insufficient to determine the applicable fine. Personal liability under § 38 is not capped by these fine limits either. As a manager, check which specific offense a potential breach of duty falls under.
Supervisory authorities can require operational changes
Under § 61 BSIG, the BSI can order inspections and the correction of deficiencies, among other measures. For essential entities, paragraph 9 also provides for the competent supervisory authority, as a last resort, to suspend authorizations under sector-specific law temporarily or to prohibit unreliable managers temporarily from carrying out their duties. The conditions include failure to comply with orders despite a deadline and the required connection between the enforcement measure and the order.
A security incident does not automatically result in such a prohibition. For important entities, the grounds for supervision under § 62 BSIG must be considered separately. Include correspondence from authorities in management reports, together with the deadline, the responsible person and evidence that the required action has been completed.
A working template for the next management meeting
| Decision item | Information needed | Recorded outcome |
|---|---|---|
| Significant risk | Affected service, impact and existing safeguards | Treatment and responsible person |
| Open measure | Reason for delay and dependencies | Deadline, resources and interim safeguard |
| Effectiveness check | Test scope, result and remaining deficiency | Remediation or justified closure |
| Incident readiness | Availability of contacts and reporting exercise results | Corrected procedure with backup personnel |
| Training needs | Existing knowledge, new risks and attendance to date | Topics and planned training date |
Record questions and differing assessments as well. A clear record shows what information management used when deciding. For guidance on assigning these tasks, read the article on § 38 BSIG and management responsibilities.
Standardize reporting if managers have to gather information from several departments themselves. You can find guidance on organizing this work at KaitoSec for mid-sized businesses and review the requirements in the NIS2 framework overview.
Training should help managers make decisions
§ 38 paragraph 3 requires regular training but does not itself set a fixed annual cycle. Participants should learn to recognize and assess IT risks and risk management practices, including their effects on the services the entity provides. Participants should therefore work through their own responsibilities and practical decision-making situations during training. Retain the training content and attendance records, and review further training needs.
Frequently asked questions
Can management hand every task over to IT?
Operational tasks can be assigned to others. Management's statutory duties to implement measures and oversee their implementation remain.
Does every manager personally face EUR 10 million?
No. That figure comes from a specific fine limit. Personal liability to the entity must be assessed under its own statutory conditions.
Is one training session enough?
§ 38 requires regular attendance. Management must continue to organize training according to its needs after the first session.
Does careful documentation prevent all liability?
No. It helps establish what managers decided and how they exercised oversight. Actual compliance with their duties and the circumstances of the individual case remain decisive.
- NIS2
- Geschäftsleitung
- Haftung
- BSIG