§ 39 is every three years. Critical infrastructure is every day.
Healthcare operators of critical infrastructure must regularly prove their IT security, since the NIS2 implementation act under § 39 BSIG and now only every three years. The longer the interval, the larger the gap between two snapshots. Why the B3S catalog only describes the WHAT, the real work sits in the HOW, and how the audit sprint becomes a continuously measured state.
Healthcare operators of critical infrastructure must regularly prove that their IT security matches the state of the art. Since the NIS2 implementation act, this duty sits in § 39 BSIG, formerly § 8a, and the evidence cycle has grown from two to three years. In practice this has become a ritual anyone recognizes who has been through it: months before the audit date, the great gathering begins, across departments and systems. The audit is passed, and afterwards everything falls back into daily business until the next cycle starts.
Three-year interval, but the threat does not keep to the beat
The cycle is a deadline, not a security level. And the longer it gets, the larger the gap between two snapshots: three years is a long time for new systems, new vulnerabilities, new attackers. Evidence produced at a single point in time says little about how things look on any given Tuesday in the years between. Yet that is exactly when a hospital gets hit.
The catalog states the WHAT, the work sits in the HOW
The sector-specific security standard B3S Hospital states the WHAT very precisely: 269 requirements in MUST, SHOULD and MAY, across 41 chapters. That is the clearer part. The real work is the HOW, namely to prove for every requirement that it is met. And that evidence almost never sits in one place. It is in the asset inventory, the risk register, the policies, emergency management and the attack detection systems. The audit sprint largely consists of gathering it back together from there.
How isidaten makes the sprint unnecessary
The B3S module ships the hospital catalog, plus statutory health and care insurance, as a structured standard. You define your scope with critical service, CI classification and evidence cycle and derive the statement of applicability. Then an auto-check engine tests the requirements continuously against as-is data from the platform, instead of someone gathering it for the deadline. RUN implementation level for ISMS, BCMS and attack detection is calculated continuously, and the report for the § 39 evidence emerges from operations. The three-year tour de force becomes a report on a state you already know every day.
What the module can do in detail is shown on the B3S module page. And if you want to move your critical-infrastructure evidence from a sprint to a running state, talk to us.
Questions about this update?
Talk to us – we are happy to show you this feature in a demo.