• Blog
  • BSI Minimum Standard as a Contract Basis: What Now?

BSI Minimum Standard as a Contract Basis: What Now?

BSI minimum standards are increasingly moving into service descriptions and contracts. What this means for contractors, where the typical pitfalls lie, and what a reliable commitment looks like.

Person hält Stift vor Laptop, digitale Checklisten mit grünen Häkchen erscheinen über dem Bildschirm.
Jonathan Bauer

Jonathan Bauer

CEO FC-X

The article explains why BSI minimum standards are increasingly appearing in service descriptions, what obligations arise from this for contractors, and how a blanket promise can be turned into a reliable agreement.

The article explains why BSI minimum standards are increasingly appearing in service descriptions, what obligations arise from this for contractors, and how a blanket promise can be turned into a reliable agreement.

At a glance

  • Minimum standards are internal administrative requirements – as part of the contract, they become enforceable performance obligations.

  • A blanket compliance assurance regularly assumes obligations that are not the contractor's responsibility.

  • Key elements are version reference, responsibility delineation, form of proof, and a change process.

From administrative tool to contract clause

Minimum standards of BSI are not a new tool. The Federal Office specifies the minimum security level that the federal administration must adhere to in specific areas – such as in the use of external cloud services, in logging and detection, in web browsers, in Transport Layer Security, in mobile device management, or in video conferencing services. They are binding for federal authorities and the federal's public IT service providers. With the NIS-2 implementation law that came into effect on December 6, 2025, the BSI Act was revised; the legal basis can now be found in § 44 para. 1 sentence 1 BSIG.

What's new is something else: These standards are moving into procurement. They appear in service descriptions, in EVB-IT contracts, in framework agreements, and in grant notifications. They are moving out of the internal administrative realm. What was a requirement to the authority becomes a contractual performance obligation of the contractor – including proof obligations, audit rights, and, if in doubt, termination and liability consequences.

Not only conventional IT service providers are affected anymore. Those who operate specialized applications, host planning data, provide managed services, connect building control technology, or provide project platforms for public clients now regularly find the clause in their documents.

Why assumption rarely works smoothly

Minimum standards are written for the operation of an authority, not for a contractual relationship between two parties. They describe roles, processes, and decisions that cannot be transferred one-to-one to a work or service contract. Part of the requirements systematically targets the client – such as determining the need for protection or deciding on the use of a service.

Anyone who nevertheless assures the "compliance with the relevant minimum standards of BSI" takes on obligations that they can neither control nor fulfill.

The pitfalls are similar in almost all procedures:

  • Blanket assurance without delineation of responsibility for each requirement.

  • Dynamic references "in the current version" without regulation for version changes.

  • No agreed form of proof – fulfillment is claimed, but not verifiable.

  • Mixing with ISO 27001 or BSI baseline protection without specifying the differences.

  • Requirements are not passed through to subcontractors and sub-service providers.

  • Deadlines that ignore the actual implementation effort.

The result is rarely a security incident. It is a dispute about responsibilities – usually exactly when an audit is pending or an incident needs to be resolved.

The requirement is fulfillable – if it is translated.

The constructive way is not to negotiate the clause until it is contentless. It is to translate it: from a general reference to a specific, understandable task distribution.

Practically, this means assigning each individual requirement of the relevant minimum standard to a responsibility – client, contractor, or jointly –, accompanying it with a form of proof, and referring it to a specific version with a date. What arises today in many projects as an annex to the contract is essentially a responsibility matrix. It involves a singular effort and saves a significant part of the coordination over the contract's duration.

The effort is also worthwhile for a second reason: minimum standards are well-documented, verifiable, and reusable. Those who have once mapped them cleanly onto their own services have a reliable target image – which can be used again in further procurement procedures and also describes a convincing security level outside of the federal framework.

What companies should do now

Monitoring Files

Review contracts

Systematically review existing and ongoing procurement documents for references and their scope.

Individual Plan Icon

Align requirements

Map each requirement of the relevant standard against your own performance and the actual state.

Icon klinische Notiz

Delineate responsibilities

Define the client, contractor, and joint responsibilities in a binding matrix.

Konzept

Build proofs

For each assumed obligation, determine what will substantiate it – concept, protocol, report, or review.

Icon Schema

Bind the supply chain

Contractually pass through requirements to subcontractors and used services.

Icon Balkendiagramm Trend aufwaerts

Manage changes

Agree on a process on how new versions will be evaluated, scheduled, and compensated.

Frequently Asked Questions

Conclusion

Referencing a BSI minimum standard is not formalism but a substantive obligation with significant impact. Signing it unchecked shifts an unclear risk into the contract period. Translating it – into concrete requirements, clear responsibilities, and verifiable proofs – yields a double benefit: legal certainty in the ongoing project and a security level that becomes an argument in the next procurement procedure.

How we support

The FC-Gruppe supports contractors and public clients in exactly this translation: analyzing contract and procurement documents, mapping requirements to services provided, building the responsibility matrix, designing the proof process, and implementing the technical measures. Contact us if you have such a clause on the table.

Written by Jonathan Bauer

More On This Topic

Realise projects with us?

Speak directly with our experts.

FC-Gruppe GmbH

Administration
Contact Data

Am Storrenacker 8 76139 Karlsruhe