Federal Office for Information Security (BSI)
Germany's federal cybersecurity authority, operating under BMI to set IT security standards, certify organizations and products, oversee NIS-2 and KRITIS compliance, coordinate cyber incident response, and protect citizens — funded entirely by the federal budget.
- Company typePublic
- Founded1991
- HeadquartersBonn, Germany
- Headcount—
- GTM typeB2B
- OfferingServices
Federal Office for Information Security (BSI) firmographics
Firmographics- Name
- Federal Office for Information Security (BSI)
- Legal name
- Bundesamt für Sicherheit in der Informationstechnik
- Website
- https://bsi.bund.de
- Company type
- Public
- Founded year
- 1991
- Operating status
- Operating
- Short description
- Germany's federal cybersecurity authority, operating under BMI to set IT security standards, certify organizations and products, oversee NIS-2 and KRITIS compliance, coordinate cyber incident response, and protect citizens — funded entirely by the federal budget.
- Ownership category
- akta.pro rank
Federal Office for Information Security (BSI) industry classification
Industry- Product category
- Government Cybersecurity Services
- NAICS
- National Security (928110), National Security and International Affairs (9281), International Affairs (92812), Security Systems Services (56162), Security Systems Services (except Locksmiths) (561621)
- SIC
- Communications Services, Nec (4899), International Affairs (9721)
- akta.pro primary industry
- Data Protection, Privacy & Cybersecurity Regulators (BPAIAOAH)
- akta.pro secondary industries
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC), Border Security & Homeland Security (BPAIAHAI)
Keywords
Where Federal Office for Information Security (BSI) is headquartered
LocationHeadquarters
- HQ city
- Bonn
- HQ country
- Germany
- HQ region
- Europe
Offices3 records
Markets served
Federal Office for Information Security (BSI) business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure, Others
Revenue model
- Government Funding: BSI is funded through the federal budget as a German federal government agency under the Federal Ministry of the Interior (BMI). Operations are financed by tax revenues with no commercial revenue model.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Monthly | Public advisory and warning services |
Go-to-market motion1 record
Distribution channels5 records
Marketing channels8 records
Federal Office for Information Security (BSI) product offering
Product offeringCore offering
The Federal Office for Information Security (BSI) is Germany's central federal cybersecurity authority operating under the Federal Ministry of the Interior. It delivers cybersecurity standards (IT-Grundschutz), technical guidelines (TR-series), incident response coordination (CERT-Bund, Nationales IT-Lagezentrum), cloud security assessment criteria (C5), IT security certification (IT-Sicherheitskennzeichen), and digital consumer protection programs. Its mandate spans protection of federal IT, critical infrastructure (KRITIS) oversight, NIS-2 implementation, and lead market surveillance authority role for the EU Cyber Resilience Act.
Product overview
The Federal Office for Information Security (BSI) — Bundesamt für Sicherheit in der Informationstechnik — is Germany's central federal cybersecurity authority. BSI does not offer a single commercial product; rather, it provides a broad portfolio of public-sector services, standards, platforms, and programs. The core offerings include: CERT-Bund and Bürger-CERT (computer emergency response for government and citizens), the BSI-Portal (central platform for NIS-2 registration and incident reporting), IT-Grundschutz (information security management methodology with ISO 27001 certification), the IT-Sicherheitskennzeichen (voluntary security label for consumer IoT products), and a suite of Technische Richtlinien (technical guidelines including TR-03188 Passkey Server, TR-03108 Secure Email Transport). BSI also operates the Nationales IT-Lagezentrum for real-time cyber situational awareness, maintains BSI-Standard C5 for cloud security assessment, publishes the annual Cybersicherheitsmonitor consumer survey, and delivers digital consumer protection programs including the 'Einfach • Cybersicher' newsletter and 'Update verfügbar' podcast. BSI serves as lead market surveillance authority for the EU Cyber Resilience Act and supports NIS-2 implementation in Germany. Recent additions include the Cyberdome initiative for automated cyber defense and sovereignty criteria for cloud solutions.
Differentiator
Problem solved
Functional benefit
Brands
- Cybersicherheitsmonitor (CyMon): Annual survey on cybersecurity conducted by BSI and the police crime prevention program (ProPK) assessing internet users' protection behavior and cybercrime victimization
- E-Mail-Sicherheitsjahr (E-Mail Security Year)
- Projekt SuSi - Digitale Gesellschaft: smart & sicher
- Update verfügbar
Products and services
- BSI-Portal Central web portal for NIS-2 registration, IT security incident reporting, and access to BSI services for businesses and critical infrastructure operators. Mandatory for NIS-2 regulated entities.
- CERT-Bund Federal Computer Emergency Response Team operating within BSI; issues security advisories, vulnerability warnings, and coordinates response to cyber incidents affecting federal networks and critical infrastructure.
- Bürger-CERT Citizen-facing computer emergency response team providing security advisories, vulnerability alerts, and cybersecurity guidance to private individuals and consumers in Germany.
- IT-Sicherheitskennzeichen (IT Security Label) Voluntary certification label that rates connected consumer products (IoT devices, smart home) against defined cybersecurity criteria; enables consumers to identify products meeting minimum security standards.
- IT-Grundschutz (IT Baseline Protection) Methodology and catalog of security controls for establishing information security management systems; includes ISO 27001 certification and is the basis for BSI's IT security consulting for federal administration and organizations.
- Technische Richtlinien (Technical Guidelines) Series of technical standards and guidelines covering areas such as secure email transport (TR-03108), passkey servers (TR-03188), sovereign identity management (TR-03156), cryptographic protection of administrative documents (TR-03171), and AI evaluation (QUAIDAL).
- Nationales IT-Lagezentrum (National IT Situation Centre) National-level cybersecurity situational awareness center aggregating threat data across federal agencies and critical infrastructure operators to provide real-time coordinated cyber defense.
- BSI-Standard C5 (Cloud Computing Compliance Criteria Catalogue) Standardized criteria catalogue for assessing cloud computing security; used to evaluate cloud service providers' security properties and serves as the basis for BSI's cloud sovereignty assessments.
- NIS-2 Services Registration, guidance, and compliance support for entities covered by the NIS-2 Directive and its German implementation act; includes mandatory registration portal, reporting obligations, and documentation requirements for essential and important entities.
- Kritische Infrastrukturen (KRITIS) Support Regulatory oversight and security support for operators of critical infrastructures including energy, water, food, healthcare, transportation, and digital infrastructure; includes incident reporting, compliance checks, and KRITIS-FAQ guidance.
- Digitaler Verbraucherschutz (Digital Consumer Protection) Multi-faceted program providing consumer cybersecurity guidance including newsletters, tips for online shopping, account protection, smart home security, and digital literacy; includes Cybersicherheitsnetzwerk with Digital First Responders for private individuals.
- Cyber Resilience Act (CRA) Support BSI serves as the lead market surveillance authority for the EU Cyber Resilience Act; coordinates with 13 European market surveillance authorities; manages first reporting obligations taking effect September 2026; supports conformity assessment and accreditation for manufacturers.
Quantifiable outcome
- 92% of Exchange servers in Germany running unsupported software - BSI issued warning about critical security gap
- +1 more outcomes
Companies that use Federal Office for Information Security (BSI)
Customer profileNamed customers5 records
Segments4 records
Ideal customer profiles4 records
Federal Office for Information Security (BSI) technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration9 records
AI capability7 records
Feature6 records
Federal Office for Information Security (BSI) partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered minor and core.
- eco - Verband der Internetwirtschaft e.V.minorPartner in E-Mail Security Year initiative (E-Mail-Sicherheitsjahr) with eco association and Bitkom. Jointly honored over 120 companies in Hall of Fame for email security standards compliance.
- Bitkom e.V.minorPartner in E-Mail Security Year initiative with Bitkom industry association and eco. Joint promotion of DNSSEC and BSI TR-03108 email security standards.
- IONOScoreCooperation agreement with IONOS, one of Europe's largest hosting and cloud infrastructure providers headquartered in Montabaur, Germany. BSI supports cloud security and sovereignty aspects, focusing on cryptographic procedures for protecting critical public administration data against future decryption technologies.
- Schwarz Digits (Schwarz Gruppe)coreCooperation with Schwarz Digits, the IT division of the Schwarz Group based in Neckarsulm, Germany. BSI collaborates on cybersecurity and digital infrastructure sovereignty, particularly in future-proof cryptographic procedures for protecting critical government data.
- Amazon Web Services (AWS)coreBSI supports AWS in developing security and sovereignty features for the European Sovereign Cloud (ESC). BSI reviews security and sovereignty properties including isolation capability from global AWS infrastructure, verification of control commands and cloud updates, and EU-based operations by EU personnel.
- Bundesamt für Verfassungsschutz (BfV)coreJoint security advisories with domestic intelligence agency, including warnings about Russian cyber actors targeting Signal/WhatsApp accounts and photovoltaic systems. Combined threat intelligence sharing for national cybersecurity.
- Bundesinnenministerium (BMI)coreBSI operates under BMI oversight. Joint development of Cyberdome Germany digital protection shield and national cyber defense strategy.
- European Market Surveillance Authorities (AdCo CRA)coreBSI leads the Administrative Cooperation Group for the Cyber Resilience Act (AdCo CRA) in Berlin. Coordinates with 13 European market surveillance authorities and European Commission for CRA implementation.
- Nationales Cyber-Abwehrzentrum (NCAZ)coreBSI hosts the National Cyber Defense Center, celebrating 15th anniversary in 2026. Brings together cybersecurity experts from security agencies, military cyber forces, intelligence units, and law enforcement for coordinated defense.
- Programm Polizeiliche Kriminalprävention (ProPK)coreJoint annual Cybersicherheitsmonitor survey with police crime prevention program. Combined BSI and ProPK conduct representative surveys of 3,000+ German internet users on cybersecurity awareness and cybercrime victimization.
Scale indicators4 records
Recent moves6 records
Expansion highlights6 records
Federal Office for Information Security (BSI) competitors and assessment
Company assessmentMarket position
Competitive moat4 records
Key risks1 record
Customer concentration
Federal Office for Information Security (BSI) social profiles
Digital presenceFederal Office for Information Security (BSI) compliance and trust
Trust signalCompliance7 records
Federal Office for Information Security (BSI) financial estimates
Financial estimateRevenue estimate
Valuation estimate
Federal Office for Information Security (BSI) leadership team
Management profileNumber of profiles
Profiles1 record
Federal Office for Information Security (BSI) funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Federal Office for Information Security (BSI) M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Federal Office for Information Security (BSI)
What does Federal Office for Information Security (BSI) do?
The Federal Office for Information Security (BSI) is Germany's central federal cybersecurity authority operating under the Federal Ministry of the Interior. It delivers cybersecurity standards (IT-Grundschutz), technical guidelines (TR-series), incident response coordination (CERT-Bund, Nationales IT-Lagezentrum), cloud security assessment criteria (C5), IT security certification (IT-Sicherheitskennzeichen), and digital consumer protection programs. Its mandate spans protection of federal IT, critical infrastructure (KRITIS) oversight, NIS-2 implementation, and lead market surveillance authority role for the EU Cyber Resilience Act.
Is Federal Office for Information Security (BSI) a public or private company?
Federal Office for Information Security (BSI) is a public company. It is classified as state government owned and is currently operating.
When was Federal Office for Information Security (BSI) founded?
Federal Office for Information Security (BSI) was founded in 1991.
Where is Federal Office for Information Security (BSI) based?
Federal Office for Information Security (BSI) is headquartered in Bonn, Germany, in the Europe region.
How does Federal Office for Information Security (BSI) make money?
One revenue line is on record: government Funding.
Does Federal Office for Information Security (BSI) have an API?
No public API is recorded for Federal Office for Information Security (BSI).
What industry is Federal Office for Information Security (BSI) in?
Federal Office for Information Security (BSI)'s product category is Government Cybersecurity Services. Its primary akta.pro industry code is BPAIAOAH, Data Protection, Privacy & Cybersecurity Regulators, with a secondary code of BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX). Its NAICS code is 928110 and its SIC code is 4899.