The obligation to deploy attack detection systems was introduced by the German IT Security Act 2.0 (IT-Sicherheitsgesetz 2.0) and applied to KRITIS operators from 1 May 2023 (§ 8a(1a) BSIG, old version). With the NIS2 Implementation Act (NIS2-Umsetzungsgesetz), in force since 6 December 2025, it is now set out in § 31(2) BSIG: operators of critical facilities must deploy systems that “continuously and automatically record and analyse suitable parameters and characteristics from ongoing operations” – in compliance with the state of the art. § 2 BSIG defines SzA as processes supported by technical tools and organisational integration – explicitly not a mere product, but an interplay of technology and organisation. Under § 39 BSIG, implementation must be demonstrated through security audits, reviews or certifications – every three years under the new law (previously every two years under § 8a(3) BSIG, old version).
Systems for Attack Detection (SzA)
How to implement the obligation to deploy attack detection systems under § 31 BSIG in a structured way – from the BSI guidance through log sources and detection engineering to the required evidence.
Operators of critical facilities in Germany are legally required to deploy attack detection systems (Systeme zur Angriffserkennung, SzA) – governed, since the transposition of NIS2, by § 31(2) BSIG. What counts as appropriate is specified by the BSI in its guidance document (Orientierungshilfe) with MUST, SHOULD and MAY requirements and an implementation-level model from 0 to 5. Whether attack detection actually works, however, is decided not on paper but by the coverage of log sources, the quality of detection rules and well-rehearsed response processes. This article puts the legal situation, the BSI requirements and the technical building blocks into context – from Sigma rules and ATT&CK mapping to the use-case lifecycle.
From obligation to evidence
Five milestones from the first edition of the BSI guidance to ATT&CK v19 – tap a milestone for details.
First edition of the BSI guidance
The BSI publishes the first edition of its guidance on the use of attack detection systems.
SzA obligation applies to KRITIS
The obligation to deploy attack detection systems, introduced by the German IT Security Act 2.0, applies to KRITIS operators (§ 8a(1a) BSIG, old version).
Guidance version 1.1
The BSI issues version 1.1, editorially revised compared with the first edition; it still refers to the previous legal situation.
NIS2 Implementation Act in force
The deployment obligation is now set out in § 31(2) BSIG. Evidence under § 39 BSIG is due every three years (previously every two years).
MITRE ATT&CK v19
Version 19 of the Enterprise matrix describes 15 tactics, 222 techniques and 475 sub-techniques. Mapping your own rules to ATT&CK makes it transparent which attack techniques are detected – and where gaps remain.
The Essentials at a Glance
Six topic blocks — tap to expand.
The interplay of technology building blocks
SIEM, EDR and NDR compared – no single tool fulfils the requirements on its own; what matters is documented coverage of the entire scope.
- Centrally collects and correlates log data from heterogeneous sources.
- Delivers the required continuous, automated analysis with alerting when thresholds are exceeded.
- Provides detailed telemetry and response capabilities on endpoints and servers.
- The guidance additionally and specifically requires centrally managed malware detection.
- Detects anomalies in network traffic and thus also covers areas where agents cannot be installed – such as OT environments or embedded systems.
- At the transitions between internal and external networks, the guidance requires network-based intrusion detection systems (NIDS).
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Gesetz über das Bundesamt für Sicherheit in der Informationstechnik und über die Sicherheit in der Informationstechnik von Einrichtungen (BSIG)
New version enacted through the NIS2 Implementation Act, in force since 06.12.2025; the key provisions are § 2 (legal definition of SzA), § 31(2) (deployment obligation for operators of critical facilities) and § 39 (evidence every three years).
Orientierungshilfe zum Einsatz von Systemen zur Angriffserkennung, Version 1.1
Specifies the MUST, SHOULD and MAY requirements for logging, detection and response and defines the implementation-level model 0–5 for providing evidence.
MITRE ATT&CK v19 (Updates – April 2026)
Current version of the knowledge base; Enterprise matrix with 15 tactics, 222 techniques and 475 sub-techniques as the reference taxonomy for detection coverage mapping.
About Sigma – Sigma Detection Format
Documentation of the open, YAML-based signature format for log events, including conversion into SIEM query languages via sigma-cli and pySigma.
SigmaHQ/sigma – Main Sigma Rule Repository
Community-maintained rule repository whose detection rules can be translated into product-specific SIEM queries.
Ready to make your attack detection audit-proof?
We support you with the gap analysis against the BSI guidance, with detection engineering and with providing evidence under § 39 BSIG. Contact us for a no-obligation initial consultation.