§30 of the revised BSI Act is the centerpiece of NIS2 implementation in Germany. It defines ten specific areas of measures that affected companies must implement. Many of them have a direct connection to email security – the No. 1 attack vector. The legal framework around these ten measures, from scope to reporting deadlines, is set out in the NIS2 overview.
The 10 Measures at a Glance
No. 1: Risk Analysis and Security Concepts
Legal requirement: Concepts for risk analysis and security for information systems.
Email relevance: Email is the most important attack vector. Every risk analysis must centrally consider the email infrastructure:
- What sensitive data is sent via email?
- What threats exist (phishing, BEC, malware)?
- What protective measures are implemented?
Conbool solution: The dashboard provides real-time transparency across the entire mail flow. Compliance reports provide the basis for risk analysis.
No. 2: Management of Security Incidents
Legal requirement: Detection, analysis, containment, and management of security incidents.
Email relevance: Most incidents start via email. Required are:
- Real-time detection of phishing, malware, and anomalous behavior
- Automatic quarantine of suspicious emails
- Complete traceability through tracing
- Reporting processes: 24h early warning, 72h full report
Conbool solution: MailGuard detects threats with AI-based analysis. Quarantine, tracing, and audit logs enable rapid incident management.
No. 3: Business Continuity, Backup Management
Legal requirement: Business continuity management and crisis management.
Email relevance: Email availability is business-critical. Backup strategies for email configurations and archiving are required.
No. 4: Supply Chain Security
Legal requirement: Security in the supply chain including security-related aspects of relationships between entities and their service providers.
Email relevance: Communication with suppliers and partners must be encrypted. Even small suppliers without their own encryption must be included.
Conbool solution: The Message Portal enables encrypted communication with partners – even without their own S/MIME or PGP infrastructure.
No. 5: Security in Acquisition, Development, and Maintenance
Legal requirement: Vulnerability management and disclosure.
Email relevance: Email systems must be regularly checked for vulnerabilities and updated. Gateway solutions handle updates automatically.
No. 6: Effectiveness Assessment
Legal requirement: Concepts for assessing the effectiveness of risk management measures.
Email relevance: The effectiveness of spam filters, encryption, and access controls must be regularly evaluated. Audit logs and reports are essential for this purpose.
No. 7: Cyber Hygiene and Training
Legal requirement: Basic cyber hygiene practices and cybersecurity training.
Email relevance: Employee training on phishing detection is mandatory. Technical measures like MailGuard complement the human line of defense.
No. 8: Cryptography
Legal requirement: Concepts and procedures for the use of cryptographic methods and, where applicable, encryption.
Email relevance – THE central measure for email:
- Encryption in transit: TLS for all email connections, configurable per domain
- Content encryption: S/MIME and/or PGP for sensitive emails
- Key management: Secure generation, storage, distribution, and destruction
- Cryptography policy: Documentation of all methods in use
- BSI TR-02102: Only current, considered-secure algorithms
Conbool solution: SecureMail automates all email encryption. Central certificate and key management with MPKI integration. BSI TR-02102 compliant algorithms.
No. 9: Personnel Security and Access Control
Legal requirement: Personnel security, access control concepts, and asset management.
Email relevance: Access to email administration and quarantine must be role-based. MFA for administrative access.
Conbool solution: Role-based access management with Entra ID/LDAP integration and SAML SSO.
No. 10: Secure Communication
Legal requirement: Use of multi-factor authentication solutions, secured voice, video, and text communication, as well as secured emergency communication.
Email relevance:
- Secured email as the primary text communication channel
- Encryption solution for recipients without their own infrastructure
- Verifiable delivery with audit trail
- Alternative communication when the email system is compromised
Conbool solution: Gateway encryption + Secure Message Portal for external recipients. Verifiable delivery with complete audit trail.
BSI TR-02102: The Permitted Algorithms
The cryptographic methods used must reflect the state of the art. The BSI Technical Guideline TR-02102 defines the approved algorithms:
Permitted:
- AES-128, AES-192, AES-256 (symmetric)
- RSA from 2048 bit (asymmetric)
- ECDSA with at least 250 bit
- SHA-256, SHA-384, SHA-512
No longer permitted:
- MD5, SHA-1 (for security-critical applications)
- RSA below 2048 bit
- 3DES (no longer recommended since 2023)
Conbool SecureMail exclusively uses BSI TR-02102 compliant algorithms and automatically updates when new recommendations are issued.
Documentation Requirements
§30 BSIG requires not only the implementation but also the documentation of measures. For email, this means:
- Cryptography policy: Which methods are used, for which communication?
- Key management documentation: How are keys generated, distributed, and revoked?
- Incident response plan: How are email security incidents handled?
- Audit logs: Tamper-proof logs of all security-relevant events
Conclusion: Email Is the NIS2 Focal Point
Of the 10 mandatory measures under §30 BSIG, at least 6 directly affect email security. Email is not a peripheral topic of NIS2 compliance – it is the central attack point where encryption, threat protection, and auditing converge.
Conbool makes implementation simple: One platform for all email requirements, set up in minutes and auditable.
Further reading:



