(2) As part of its tasks under Section 3 (1) second sentence no. 10, the Federal Office shall provide
technical guidelines which the federal bodies shall take into account as a framework for developing
appropriate requirements for contractors (suitability) and IT products (specifications) when conducting
contract award procedures. The provisions of public procurement law and on confidentiality shall remain
unaffected.
(3) IT security products provided by the Federal Office in accordance with Section 3 (1) second sentence
no. 11 shall be developed by the Federal Office or after conducting contract award procedures on the
basis of the relevant identification of need. IT security products developed by the Federal Office may be
made available only in justified exceptional cases. The provisions of public procurement law shall remain
unaffected. When the Federal Office provides IT security products, the federal authorities may request
these products from the Federal Office. The Council of Chief Information Officers of the federal ministries
may decide that the federal authorities shall be required to request these products from the Federal
Office. In this case, other federal authorities may procure their own products only when their specific
requirements make the use of other products necessary. Sentences 5 and 6 shall not apply to the courts
and constitutional bodies referred to in Section 2 (3) second sentence.
table of contents
Section 9
Certification
(1) The Federal Office shall be the national certification authority of the federal administration for IT
security.
(2) For certain products or services, security or personal certification or certification as a provider of IT
security services may be applied for at the Federal Office. Applications shall be processed in the order in
which they were received; the Federal Office may deviate from this if the number and extent of
applications awaiting examination prevent it from examining the applications within a reasonable period
of time and issuing a certificate is in the public interest. The applicant shall provide the Federal Office with
the documents and information necessary to test and evaluate the system or the components or the
suitability of the person and to issue the certificate.
(3) The examination and assessment may be carried out by expert bodies recognized by the Federal
Office.
(4) The security certificate shall be issued if
1. information technology systems, components, products or protection profiles meet the criteria defined
by the Federal Office and
2. the Federal Ministry of the Interior has determined that issuing a certificate would not conflict with any
overriding public interests, in particular security concerns of the Federal Republic of Germany.
(5) Subsection 4 shall apply to the certification of persons and providers of IT security services
accordingly.
(6) Expert bodies shall be recognized as referred to in subsection 3 if
9/10