Compliance / BSI
BSI Cryptography Compliance (TR-02102)
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
We curated 16 rules from BSI TR-02102-1, the German federal office's cryptographic recommendations: key-size floors, approved hashes and modes, and quantum-safe hybrid guidance. Each rule is tagged against BSI TR-02102 and NIS2, so one finding serves both the German baseline and the EU directive.
What does TR-02102 require?
- RSA and discrete-log systems: at least 3000 bit
- Elliptic-curve cryptography: at least 250 bit
- Hashes: SHA-256 or stronger; MD5 and SHA-1 out
- Authenticated encryption modes over bare CBC / ECB
- Quantum-safe hybrid key exchange recommended for new systems
- TR-02102-2 applies the same logic to TLS configuration
TR-02102-1 thresholds and the rules that enforce them
The rule IDs below are the ones that appear in a Korthex finding, so a TR-02102 question in an audit can be answered by grepping the CBOM rather than by reading the report.
| Requirement | What Korthex looks for | Rule ID | Status |
|---|---|---|---|
| RSA key length | 3072 bit and above | ASYM-E-RSA3072 | recommended |
| RSA key length | 2048 bit, below the TR-02102 floor | ASYM-E-RSA2048 | acceptable |
| RSA key length | 1024 bit, 80-bit security | ASYM-E-RSA1024 | disallowed |
| Elliptic curves | brainpoolP256r1, BSI recommended | ASYM-E-ECDSABP256 | acceptable |
| Elliptic curves | P-192, below the floor | ASYM-E-ECDSAP192 | disallowed |
| Signature schemes | DSA, no new keys permitted | ASYM-E-DSA | disallowed |
| Block ciphers | 3DES, Sweet32 birthday attack | SYM-E-3DES | disallowed |
| Hash functions | SHA-1, SHAttered collision | HASH-E-SHA1 | deprecated |
| Hash functions | MD5, collisions since 2004 | HASH-E-MD5 | disallowed |
The Korthex BSI channel
We curated 16 rules from TR-02102-1 and put BSI second in the authority priority order, behind NIST and ahead of IETF. They are re-checked on the 24-hour cycle and shipped as signed updates. Because we co-tag the BSI rules with NIS2 alongside ANSSI, an EU critical-infrastructure operator activates exactly these two channels to grade against the directive's state-of-the-art expectation.
Beyond the baseline: Grundschutz evidence
TR-02102 defines the numbers; IT-Grundschutz building block CON.1 demands the documented Kryptokonzept around them. The BSI IT-Grundschutz deep dive covers how the CBOM serves as the living inventory annex to that concept.
Frequently asked questions
How does the BSI channel relate to IT-Grundschutz?
The channel grades algorithms against TR-02102-1. IT-Grundschutz (CON.1 Kryptokonzept) is the process framework around it; the dedicated Grundschutz page covers the evidence workflow.
Does the BSI channel help with NIS2?
Yes. BSI rules carry the NIS2 framework tag (alongside ANSSI), so findings translate directly into NIS2 state-of-the-art evidence for critical-infrastructure operators.
Are reports available in German?
Reports are in English; every finding carries the TR-02102 reference regardless of language, and German requirement identifiers are preserved verbatim.