Homepage » Robin Data ComplianceOS® » Inspection according to 8a BSIG

Inspection in accordance with § 8a BSIG and official BSI certificate

We take over the complete inspection in accordance with § 8a BSIG including audit and create your official verification document for the BSI. Get advice now."

Testing in accordance with BSIG and BSI-KRITIS

Robin Data stands for highest
Quality and safety standards.

TÜV-certified data protection ISO 9001 certified quality management system
TÜV-certified data protection ISO/IEC 27001 certified information security management system

Planning

Definition of test basis and scope, preparation of the test plan.

Analysis

Document review, GAP analysis and evaluation of the measures.

audit

On-site inspection including technical tests and effectiveness checks.

Proof

Final report, list of defects & official verification document for the BSI.

Your obligation: Provide proof of your IT security to the BSI by the deadline

The IT Security Act requires operators of critical infrastructures to secure their IT systems according to the state of the art. According to BSIG proof must be submitted to the BSI every three years. Traditional certifications such as ISO 27001 or BSI IT-Grundschutz are not sufficient for this. Robin Data supports you with the Testing in accordance with BSIG and BSI-KRITIS.

We work closely with you to define the scope of the audit and draw up a detailed plan. We analyse your documentation, carry out a gap analysis and evaluate your measures. The audit includes an on-site inspection and technical tests. Finally, you receive a report with a list of deficiencies and the official BSI verification document.

Robin Data takes the pressure off your organisation and ensures that you are compliant and verifiably set up.

Testing in accordance with BSIG and BSI-KRITIS

Download (PDF)

Our expertise: Continuous security of critical infrastructures

Planning the
Examination

Determination of test basis, definition of test scope and area of application, implementation of GAP analysis

Proof of the
Effectiveness

Evaluation of safety measures, review of documentation, review of implementation on site

Creation
Test report

Preparation of audit report for BSI, recording and evaluation of weak points and deficiencies

Management of the
Defects

Documentation in the test report, recommendation to rectify defects, preparation for the next test

Our audit process - explained in a structured way

How our audit according to BSIG and BSI-KRITIS works

  • 1

    Contact and initial consultation

    In a non-binding Familiarisation meeting with Robin Data we clarify whether your organisation can be classified as a KRITIS operator. We will examine which legal requirements (Section 8a BSIG, if applicable Section 391 SGB V for hospitals or NIS-2) you must fulfil in a targeted manner and coordinate the further procedure methodically with you. We will provide you with an initial assessment of the specific requirements you will face and how the audit process will work. This discussion is the basis for a customised and efficient collaboration.

  • 2

    Document and as-is analysis

    In the next step, we take a close look at your existing documentation as well as your IT and process landscape. We check which security concepts, guidelines and evidence are already in place and how they comply with the legal requirements. This gives you a clear view of your current security status.

  • 3

    GAP analysis and evaluation

    Based on the analysis, we identify existing gaps between the current status and the required standards. We also assess the effectiveness of the existing security measures. You will find out where there is a need for action and which areas are already solidly secured.

  • 4

    On-site audit and tests

    As part of an audit, we check your systems directly on site. We carry out technical tests and effectiveness checks to ensure that the measures actually work in practice. This step is crucial as it compares the theoretical requirements with the reality in your company.

  • 5

    Report and proof

    Once the audit is complete, you will receive a detailed audit report. This contains a list of deficiencies, specific recommendations for action and an assessment of your IT security situation. At the same time, we prepare the official verification document, which you can submit to the BSI by the deadline. This enables you to fulfil your legal obligation in full.

Request a quote for testing in accordance with § 8a BSIG and for official BSI verification

We will be happy to provide you with an offer that suits your needs.

Combine your desired compliance fields and functions

Robin Data ComplianceOS®

Quality management

Improve processes, increase effectiveness and efficiency

Legal Compliance

Increase legal certainty and reduce liability risks

Reports & Analyses

Keeping an eye on key figures, evaluating performance

Supplier evaluation

Record supplier risk, avoid grievances

Process automation

Optimise workflows and automate processes

API interfaces

Connecting external systems and interacting across the board

"We wanted a modern and digital implementation of our data protection management system. Robin Data convinced us with the functions, the many templates, the automation options and the very competent and friendly service as well as the cooperation with a partner nearby."

Data Protection Officer of Westpfalz-Klinikum GmbH

FAQ Audit according to BSIG and BSI-KRITIS

The audit can only be carried out by specially qualified, independent "auditing bodies". These must provide certified auditors and provide evidence of the required test procedure expertise in accordance with Section 8a (3) BSIG.

All operators of so-called "critical infrastructures" (e.g. energy suppliers, waterworks, hospitals, telecommunications companies) are required by law to provide regular proof of their IT security. Whether you are affected depends, among other things, on your industry and company size.

According to the BSIG, operators must submit proof of the effectiveness of their IT security measures to the BSI every three years. This applies on an ongoing basis, so you should plan for the next audit in good time to ensure that deadlines are met.

No. Certifications such as ISO 27001 or IT-Grundschutz are important foundations, but do not fulfil the formal requirements of BSI verification. An audit in accordance with BSIG & BSI-KRITIS, which fulfils the legal requirements, is mandatory.

The costs for the audit depend on factors such as the size of the organisation. We therefore refer you to our free initial consultationin which the requirements are clarified. You will then receive a non-binding offer with an exact price that is specifically adapted to your needs.

The duration depends on the size and complexity of your organisation. As a rule, you should allow several weeks, starting with the analysis phase and ending with the preparation of the final report. We create a customised schedule for you to ensure that all deadlines are met.

An experienced provider relieves your internal resources, carries out the audit efficiently and ensures that all legal requirements are met. You also benefit from practical recommendations for action that will strengthen your IT security beyond the audit period.

Defects are not uncommon and can be rectified through targeted measures. We support you with structured defect management, document the improvements and thus optimally prepare you for the next inspection.

GAiN (Common requirements in the verification procedure) defines the binding rules for verifications in accordance with Section 8a BSIG. From the 1 April 2025 Version 2.1 comes into force. It introduces more structured test reports, stricter requirements for checking the effectiveness of safety measures and clearer documentation of defects. In addition, in future, inspections may only be carried out by qualified inspectors with special inspection procedure expertise.

For operators, GAiN 2.1 means more extensive and detailed checks. IT security measures must not only be documented, but also tested in practice and proven to be effective. As evidence is required every two years It is advisable to carry out internal GAP analyses now, adapt processes and involve experienced auditors in order to avoid additional claims or sanctions.

© Copyright - Robin Data GmbH
en_GB