NIS2Compass — NIS2-Compliance-Plattform
Use CasesPricing
Go to platform

Weiterführende Seiten

  • Blog
  • FAQ
  • Glossar
  • Use Cases
  • Branchen
  • Preisgestaltung

Offizielle Quellen

  • BSI – Bundesamt für Sicherheit in der Informationstechnik
  • NIS2-Richtlinie (EUR-Lex)
  • NIS2UmsuCG (Bundesgesetzblatt)
NIS2Compass — NIS2-Compliance-Plattform

Ihr Navigator durch die NIS2-Compliance

Rechtliches

  • Datenschutzerklärung
  • Allgemeine Geschäftsbedingungen
  • Cookie-Richtlinie
  • Impressum

Ressourcen

  • Blog
  • Use Cases
  • Branchen
  • Preise
  • FAQ
  • Glossar

Kontakt

Kontakt

kontakt@nis2compass.de

NIS2Compass bietet Informationen und Orientierungshilfen zur NIS2-Compliance. Die Inhalte stellen keine Rechtsberatung im Sinne des Rechtsdienstleistungsgesetzes (RDG) dar und ersetzen keine individuelle rechtliche oder fachliche Beratung.

© Copyright 2026 NIS2Compass. Alle Rechte vorbehalten.

Entwickelt in DeutschlandAllianz für Cyber-Sicherheit — Teilnehmer
Home/Blog/Management Self-Check under Section 38 BSIG: The Free Excel Template
Tips & Tricks

Management Self-Check under Section 38 BSIG: The Free Excel Template

Authored by NIS2Compass Redaktion, NIS2 Compliance Expert
Last updated:July 27, 20266 min read
Isometric graphic: a glowing paragraph symbol on a short staircase leads into a checklist with three traffic-light dots – symbolizing the management self-check under Section 38 BSIG

Free Management Self-Check under Section 38 BSIG as an Excel template: 20 yes/no questions, 5 sections, traffic-light status, no email gate.

Free download

Management Self-Check under Section 38 BSIG

20 yes/no questions across 5 sections on management duties under Section 38 BSIG — implementation, oversight, training, reporting/registration and liability cover.

  • Traffic-light status per question: open, partial, fulfilled
  • Addressed directly to management, not to the IT department
  • No legal advice, but a structured self-assessment for the management board
Download self-check (Excel)

XLSX · no email required · version 1.00

Optional: NIS2 updates by email

No spam, unsubscribe anytime. Double opt-in, processed via Brevo.

Looking for the operational counterpart for IT? The NIS2 checklist covers the 10 minimum measures under §30 BSIG. View the NIS2 checklist →

Written by the NIS2Compass editorial team · Last updated: July 2026

Since December 2025, §38 BSIG has personally obligated management to implement and monitor NIS2 measures — a duty that cannot be delegated to the IT department. The free Management Self-Check under Section 38 BSIG from NIS2Compass uses 20 yes/no questions across 5 sections to pinpoint exactly where evidence gaps exist, with no email gate required.

Why isn't an IT checklist enough for management?

§38 BSIG applies personally to management, not the IT department: they must implement the NIS2 measures, monitor them, and undergo training themselves — none of this can be delegated, and a technical checklist for IT doesn't answer these leadership-level questions. The Management Self-Check closes exactly this gap.

NIS2Compass already covers operational duties in a §30 checklist for IT managers, addressing technical measures like risk management and reporting processes. The new §38 self-check adds the personal leadership duties: approving the measures, monitoring implementation, evidencing management's own training, reporting organization, and liability protection.

The legal basis is §38 paragraph 1 BSIG, which expressly assigns implementation and monitoring to management as a non-delegable duty. A detailed legal explanation of §38 BSIG is available in our article on management liability under §38 BSIG.

The fine framework shows why this distinction matters: under §65 BSIG, gesetze-im-internet.de, essential entities face fines of up to EUR 10 million or 2% of worldwide annual turnover, and important entities up to EUR 7 million or 1.4% — whichever is higher applies. The fine is imposed on the company, not directly on management personally; more detail is in our article on NIS2 fines and the penalties at stake. This split between corporate liability and personal duty of care is what motivates the self-check.

The Management Self-Check does not replace legal advice. It is a working tool for self-assessment, not a legal review of your individual liability position.

What does the Management Self-Check under Section 38 BSIG cover in its 5 sections?

The Management Self-Check under Section 38 BSIG organizes management's duties under §38 BSIG and §§32/33 BSIG into 5 sections with a total of 20 yes/no questions: implementation, monitoring, training obligation, reporting/registration duty, and liability protection. Each question can be marked with a traffic-light status of Open, Partial, or Fulfilled, so your evidence status is visible at a glance.

Each section covers a distinct set of duties for which management is personally responsible:

  • A) Implementation (§38 para. 1, 6 questions): Checks approval of the risk analysis, adoption of the policy framework, resources provided, the approved risk treatment plan, the authorized emergency plan, and the formal appointment of an information security officer or CISO.
  • B) Monitoring (§38 para. 1, 6 questions): Covers at least quarterly security reports with written confirmation, IT security as a standing agenda item, documented decisions on critical findings, an escalation process, and minute-keeping for at least 5 years.
  • C) Training obligation (§38 para. 3, 3 questions): Covers individual training for each management member, evidence of that training, and currency of no more than 3 years.
  • D) Reporting/registration duty (§§32/33, 3 questions): Clarifies whether BSI registration is complete, whether a 24/7-reachable reporting officer with a deputy is designated, and whether the three-stage reporting cascade is known.
  • E) Liability protection (2 questions): Checks whether the D&O policy has been explicitly reviewed for NIS2 and fine coverage, and whether a formal management resolution with individual signatures is in place.

The traffic-light status dropdown records the current state for each of the 20 questions and can be updated directly at the next review. This creates an ongoing record of evidence rather than a one-off snapshot.

For management's personal training obligation under §38 para. 3 BSIG, the legislator estimates an effort of around half a day, to be repeated at least every 3 years, as shown in the regulatory impact assessment for the NIS2UmsuCG from the German Bundestag.

The self-check is one of 45+ templates from the overview of all NIS2 templates and specifically covers the management level. For operational IT implementation under §30 BSIG, the NIS2 checklist as an Excel template offers the matching complement.

How should management read the results — and where is the greatest liability risk?

Five or more "Open" markings in the Monitoring section signal the highest liability risk in the self-check. Here, the corporate-law standard of care hinges on what management knew or should have known — a derived benchmark, not a verbatim statutory quote. Anyone who identifies gaps here should close the reporting and documentation processes first.

The self-check has no automated scoring, but the distribution of traffic-light statuses across sections reveals clear priorities, and working through the results section by section shows where attention is needed most urgently.

In the Monitoring section, documentation and reporting duties sit closest together, and evidence gaps here are hardest to remedy after the fact — which explains why this section carries so much weight.

The reason lies in the statutory text itself: §38 BSIG literally obligates management "to implement the measures under §30 BSIG and to monitor their implementation" — two separate, non-delegable duties.

In the event of a breach, the fine under §65 BSIG initially falls on the company. Separately, corporate-law recourse under §43 GmbHG or §93 AktG can hold the responsible individual personally liable — which is why evidence at the management level is more than a formality.

A mid-sized company completes the self-check and finds four to five "Open" markings in the Monitoring section: no documented quarterly reports, and information security isn't a standing management agenda item. As a first step, it introduces regular reporting from the information security officer on a defined schedule. This scenario is anonymized for illustration.

The self-check does not replace legal advice or a formal BSI review — it merely structures the internal self-assessment at the management level. For a company-wide gap analysis that goes beyond this level, the Pre-Check is a suitable next step.

What comes after the self-check — what are the next steps?

Open items in the self-check translate directly into concrete steps: completing a missing registration, introducing reporting processes, reviewing the D&O policy — turning every "Open" marking into a scheduled task rather than a vague intention. The NIS2 Guide walks you through implementation step by step, with matching templates in the Template Library.

The current BSI registration status shows how prevalent reporting and registration duties are in practice. As of 2 April 2026, according to BSI, "NIS-2 in Zahlen", 15,691 entities had registered in the BSI portal (15,477 in the core portal plus 214 branch offices), against an estimated 29,500 affected companies in Germany. An open registration item therefore affects a substantial share of the companies concerned, not an exception.

Section D is especially time-critical: the three-stage reporting cascade (24 hours, 72 hours, one month) follows a strict deadline logic. Under §32 BSIG, the clock starts as soon as any employee becomes aware of the incident, not only once management is informed. A missing internal reporting process quickly becomes a genuine risk as a result.

The same applies to Section E and D&O insurance: many existing policies expressly exclude intent, gross negligence, and regulatory fines, so an open marking here should prompt a concrete review of your own policy.

For working through these open items, the NIS2 Guide from NIS2Compass offers a structured, step-by-step approach starting with Chapter 1 on governance documentation. Matching templates are available in the Template Library. Anyone taking stock of their own results at their own pace will find a concrete starting point there.

Frequently Asked Questions

Is the Management Self-Check under Section 38 BSIG legally binding?

No, the Management Self-Check is a free working tool for self-assessment and does not replace legal advice or a formal BSI review. It structures which duties under §38 BSIG are already documented and where evidence gaps remain, so management can act internally before an external review uncovers the gaps.

Do I need to provide an email address to download the self-check?

No, the Management Self-Check under Section 38 BSIG is available for immediate download with no email gate. NIS2Compass deliberately skips any request for contact details on this deliverable, so management can review the template immediately without filling out a form or registering on the website first.

What does a high share of "Open" answers in the Monitoring section mean?

Five or more "Open" markings in the Monitoring section point to the highest liability risk. §38 para. 1 BSIG requires active, documented monitoring of the measures by management, and this is precisely where evidence is most often missing during a review.

Who is the self-check for — IT managers or management?

The Management Self-Check is aimed directly at management itself, not at the IT department as a mere go-between for technology and leadership. IT managers who need the legal background and arguments to make their case to management will find both in our article on §38 BSIG, linked at /en/blog/nis2-management-liability-paragraph-38-bsig.

Implement NIS2 step by step

NIS2Compass guides you step by step through implementation – with guide, templates and knowledge hub.

Get started

Ähnliche Artikel

guide

When Is a Security Incident Reportable? (§ 32 BSIG)

A significant security incident under § 2 no. 11 BSIG: when you have to report to the BSI, and why the 500,000 euro threshold binds only eleven types of digital service provider.

9 Min. Lesezeit

guide

NIS2 Guide: How 8 Chapters Lead to Compliance

The NIS2Compass NIS2 Guide walks you through 8 chapters, from registration to training, toward NIS2 compliance. What each chapter covers and how templates help.

10 Min. Lesezeit

guide

The Best ISMS Tool to Kick Off Strong After the 2026 Summer Lull

A comparison of the six leading ISMS tools for 2026: KaitoSec, Kertos, Vanta, Grasp, Athereon, and HiScout, with guidance on which tool fits which company profile.

11 Min. Lesezeit

Back to Blog