Every two years,
the evidence.
Operators of critical infrastructure in Germany must demonstrate to the BSI every two years that their safeguards meet the state of the art. We prepare that submission, accompany the auditing body and work off the deficiencies it finds — before the next submission.
What is included.
Preparing and supporting the evidence submission for operators of critical infrastructure.
Scope and B3S
Delimiting the critical service and its installations; selecting and applying the sector-specific security standard.
Pre-audit
Testing the safeguards against §8a and the B3S before the auditing body arrives — so deficiencies surface internally rather than in the submission.
Evidence documentation
Preparing the evidence in the structure the BSI expects; alignment with the auditing body.
Remediation
Every deficiency with an action, an owner and a date; technical implementation by us on request, with evidence before the next submission.
Secureskies is not an auditing body under §8a BSIG. We prepare the submission and support the review; the audit itself must be performed by an independent body.
Five steps,
one deliverable.
Delimitation
Determine the critical service, installations and thresholds.
Pre-audit
Internal review against §8a and the applicable B3S.
Preparation
Produce the evidence documentation, remedy deficiencies before the audit.
Support
Accompany the auditing body, answer queries, record deficiencies.
Remediation
Implement and document the action plan, evidence effectiveness.