NIS2 Country Guide

NIS2 Germany: NIS2UmsuCG, BSI Registration & Penalties

Germany transposed the NIS2 Directive through the NIS2-Umsetzungsgesetz (NIS2UmsuCG), whose Article 1 is the rewritten BSI-Gesetz (BSIG). It was published on 5 December 2025 and entered into force on 6 December 2025. Around 29,500 entities are now supervised by the BSI, up from roughly 4,500 under the old law.

In force: 6 Dec 2025 Law: NIS2UmsuCG / BSIG (BGBl. 2025 I Nr. 301) Authority: BSI Registration deadline: passed Last updated: 2 Aug 2026

Introduction: NIS2 Directive & the German context

Germany already had one of the EU's more developed cybersecurity regimes before NIS2, built on the IT-Sicherheitsgesetz and the KRITIS rules for critical infrastructure. Those covered roughly 4,500 entities.

The NIS2-Umsetzungsgesetz (NIS2UmsuCG) changed the scale rather than the philosophy. Its Article 1 replaced the BSI-Gesetz of 2009 with a new BSIG, and the number of organisations under BSI supervision rose to about 29,500. Most of them had never dealt with the BSI before.

The obligations are already live. There was no general transition period: registration, risk management and incident reporting all applied from the day the law took effect.

What you must do in Germany

Six duties, each with its own statutory hook and its own penalty if missed. The deadlines are counted from the moment you first qualify as an in-scope entity, not from a single national date.

  1. Determine your own status. Germany uses self-identification: no authority writes to tell you that you are in scope. You are either a besonders wichtige Einrichtung (essential entity) or a wichtige Einrichtung (important entity) under § 28 BSIG, or neither.
  2. Register with the BSI within three months of first qualifying (§ 33(1)). For entities already in scope when the law took effect, that deadline was 6 March 2026 and has passed. See Registering with the BSI.
  3. Implement the ten risk-management measures in § 30(2), proportionate to your risk exposure, size and the cost of implementation — and document that you have done so. The documentation duty is written into § 30(1) as a separate obligation.
  4. Be able to report an incident within 24 hours. The chain runs 24 hours, 72 hours, then a final report one month later. See Incident reporting.
  5. Get your management trained, and keep them involved. Under § 38 the Geschäftsleitung must implement and supervise the measures personally, and attend training regularly. This is not delegable to the IT department.
  6. Keep your registration current. Changes to the data you filed must reach the BSI within two weeks (§ 33(5)).
If you are a KRITIS operator, a second statute applies alongside this one. The KRITIS-Dachgesetz took effect on 17 March 2026 and covers physical resilience. See How Germany differs.

NIS2 Directive implementation in Germany

Germany transposed the NIS2 Directive through the NIS2-Umsetzungsgesetz (NIS2UmsuCG). The Bundestag passed it on 13 November 2025 and the Bundesrat approved it on 21 November 2025. It was published in the Federal Law Gazette as BGBl. 2025 I Nr. 301 on 5 December 2025 and, under its Article 30, entered into force the following day, 6 December 2025.

The distinction matters because both dates circulate. 5 December is the date of publication; 6 December is the date the obligations began. Germany transposed almost fourteen months after the EU deadline of 17 October 2024.

Article 1 of the NIS2UmsuCG is a complete replacement of the BSI-Gesetz, so the operative rules are cited as sections of the BSIG rather than of the NIS2UmsuCG itself. The BSIG has since been amended three times: by the KRITIS-Dachgesetz of 11 March 2026, and by two further acts of 21 and 23 July 2026.

Status

In force since 6 December 2025. Published 5 December 2025 as BGBl. 2025 I Nr. 301. No general transition period was granted.

Supervising authority

The Bundesamt für Sicherheit in der Informationstechnik (BSI) supervises, audits and receives reports. Registration and incident reporting run through a facility operated jointly with the BBK, the federal civil-protection agency.

Scale

About 29,500 entities are in scope. By 2 April 2026, 15,477 had registered — roughly half. The BSI has published no newer figure.

NIS2 Germany: compliance requirements

Germany follows the two-tier NIS2 structure, but names it in its own terms and sets its own thresholds. An besonders wichtige Einrichtung is an essential entity; a wichtige Einrichtung is an important entity. Which one you are decides how the BSI supervises you and how large a fine you face.

Scope thresholds (§ 28 BSIG)

Besonders wichtige Einrichtungen (essential):

  • Operators of kritische Anlagen (KRITIS installations).
  • Qualified trust service providers, TLD name registries and DNS service providers — at any size.
  • Annex 1 entity types with at least 250 staff, or turnover above €50m and a balance sheet total above €43m.

Wichtige Einrichtungen (important):

  • Trust service providers not covered above.
  • Annex 1 and Annex 2 entity types with at least 50 staff, or turnover above €10m and a balance sheet total above €10m.

The ten measures (§ 30(2) BSIG)

  • Risk analysis and information-security policies.
  • Incident handling.
  • Business continuity: backup management, disaster recovery, crisis management.
  • Supply-chain security, including the security aspects of relationships with direct suppliers.
  • Security in acquisition, development and maintenance, including vulnerability handling and disclosure.
  • Procedures to assess whether the measures actually work.
  • Basic cyber-hygiene training and awareness.
  • Policies on the use of cryptography.
  • Personnel security, access control and asset management.
  • Multi-factor or continuous authentication, secured voice, video and text communication, and secured emergency communications where relevant.

§ 30(1) adds a separate duty: you must document your compliance. Failure to do so is independently punishable.

Certification & standards

No certification is mandatory. The BSI's own position is that a certificate alone is not sufficient to discharge the BSIG duties, though ISO 27001 or IT-Grundschutz can be a building block towards the § 30 measures.

Ordinary entities only have to prove compliance when the BSI asks. Operators of kritische Anlagen are different: under § 39 they must submit audits, tests or certifications on a cycle, without being asked.

Two significant carve-outs. Under § 28(6), financial entities already covered by DORA are exempt from the core BSIG duties (§§ 30, 31, 32, 35, 36, 38 and 39), because DORA occupies the same ground. Under § 28(5), telecoms providers and energy network operators governed by §§ 5c–5e EnWG are likewise carved out of those duties plus the supervision provisions. Both carve-outs fall away for any additional activity that brings you back into Annex 1 or 2.

Competent authorities & CSIRT

Germany centralises far more than most member states. The BSI is the supervisor, the national CSIRT and the single point of contact, and it also runs the registration and reporting infrastructure jointly with the BBK.

RoleAuthorityNotes
Supervisory authority BSI — Bundesamt für Sicherheit in der Informationstechnik Supervises all in-scope entities under § 59 BSIG. Can order audits, demand evidence and impose fines.
National CSIRT BSI (CERT-Bund) Operates the national computer security incident response capability.
Single point of contact Nationale Verbindungsstelle at the BSI § 40 BSIG. Handles EU-wide liaison and cross-border coordination.
Registration & reporting BSI jointly with the BBK §§ 32 and 33 require a facility operated jointly with the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe, the federal civil-protection agency.
EU-wide competence for digital providers BSI § 60 BSIG. For cloud, data centre, CDN, managed service, marketplace, search and social network providers, jurisdiction follows the main establishment in the EU.

Registering with the BSI

Registration is the single most commonly missed duty in Germany, and the route to it is not obvious: it runs through the tax administration's identity system before it ever reaches the BSI.

1. Get an ELSTER organisation certificate

Apply for an ELSTER-Organisationszertifikat through the federal Mein Unternehmenskonto service. This is the German business identity credential, originally built for tax filing. Without it you cannot open a BSI portal account.

2. Register in the BSI-Portal

Use the certificate to register at portal.bsi.bund.de. The same portal is later used for incident reports.

3. Keep it current

Any change to the information you filed must reach the BSI within two weeks (§ 33(5) BSIG).

What you have to supply (§ 33(1) BSIG)

  • Entity name, including legal form and, where applicable, the Handelsregister number.
  • Address and current contact details, including email address and telephone numbers.
  • Public IP address ranges. This one regularly surprises organisations — it is a statutory requirement, not an optional field.
  • The relevant sector, and where applicable sub-sector, from Annex 1 or Annex 2.
  • Every EU member state in which you provide the services that put you in scope.
  • The federal and state supervisory authorities competent for those activities.
The deadline has passed, and it was never 31 July 2026. § 33(1) gives you three months from the moment you first qualify. For entities already in scope when the law took effect, that meant 6 March 2026. The BSI confirms there is no general transition period, and its NIS2 pages now state plainly that the statutory registration deadline has expired. A widely reprinted claim that the BSI extended the deadline to 31 July 2026 traces back to a line on the BSI's statistics page announcing when that page would next be updated. It is not, and never was, a deadline.

Two further points. If you do not register, § 33(3) lets the BSI register you itself, in agreement with the competent supervisory authority. And a distinct track exists under § 34 for DNS providers, TLD registries, cloud and data-centre providers, CDNs, managed service and managed security service providers, online marketplaces, search engines and social network platforms: they file a different data set, also within three months, which the BSI forwards to ENISA.

How many have actually registered

The BSI publishes running totals. At 2 April 2026, its last published figures:

MeasureCount
Registrations in the BSI portal15,477
— of which wichtige Einrichtungen (important)9,894
— of which besonders wichtige Einrichtungen (essential)5,583
— of which KRITIS operators (a subset of the essential entities)1,260
Registered secondary establishments / cross-border214
Total registrations15,691
Initial incident reports filed248
All incident reports via the portal (initial plus follow-up)541

Against roughly 29,500 entities expected in scope, that is about half. The gap is the single clearest indicator of where German enforcement attention is likely to go first.

Incident reporting: the 24 / 72 / one-month chain

§ 32 BSIG sets a three-stage chain for any erheblicher Sicherheitsvorfall (significant security incident). Reports go to the reporting office run jointly by the BSI and the BBK, through the same portal used for registration.

Within 24 hours of becoming aware — an early warning (frühe Erstmeldung) stating whether you suspect the incident was caused by unlawful or malicious acts, or could have cross-border effects.
Within 72 hours — a full notification confirming or updating the early warning, with an initial assessment of severity and impact and, where available, indicators of compromise.
On request — interim reports with relevant status updates, whenever the BSI asks for them.
One month after the 72-hour notification — a final report: full description, severity and impact, the underlying threat or root cause, the remediation taken and under way, and any cross-border effects.
If the incident is still running at the one-month mark, you file a progress report instead, and the final report follows once you have closed the incident out.
The clock starts when an employee finds out. The BSI defines Kenntniserlangung as a member of staff becoming aware of a significant incident during working hours. Its stated approach is speed over completeness: if you cannot supply everything within 24 hours, file what you have and mark it as an initial report. The statute reinforces this by requiring reports to be made unverzüglich — without undue delay — in addition to the fixed deadlines.

Operators of kritische Anlagen supply more: under § 32(3) they must also state the type of installation and critical service affected, and the effect on that service. The BSI acknowledges receipt within 24 hours where possible, and can offer technical support and advice on remediation (§ 36).

One nuance worth knowing: § 32(1) provides that the reporting duty applies at the earliest from the point the reporting channel exists. Voluntary reports are also possible through the portal.

NIS2 timeline & key dates (Germany)

27 Dec 2022 — Directive (EU) 2022/2555 (NIS2) is published in the Official Journal of the European Union.
17 Oct 2024 — EU transposition deadline. Germany missed it by almost fourteen months.
13 Nov 2025 — The Bundestag passes the NIS2UmsuCG.
21 Nov 2025 — The Bundesrat approves it.
5 Dec 2025 — Published in the Federal Law Gazette as BGBl. 2025 I Nr. 301. This is the publication date, not the date the duties began.
6 Dec 2025The new BSIG enters into force under Article 30 of the NIS2UmsuCG, replacing the BSIG of 2009. Registration, risk-management and reporting duties all start here; there is no general transition period.
6 Mar 2026 — Three-month registration deadline for entities that were already in scope on 6 December 2025 (§ 33(1)).
17 Mar 2026 — The KRITIS-Dachgesetz takes effect, adding a parallel physical-resilience regime for operators of kritische Anlagen.
2 Apr 2026 — BSI reports 15,477 registrations, roughly half the entities expected in scope.
6 Dec 2028 — The earliest date on which the BSI may order essential entities in general to submit evidence of compliance (§ 61(3)). Targeted audits can be ordered at any time.

Sector-specific notes for Germany

  • Energy: operators of energy networks, installations and digital energy services governed by §§ 5c–5e EnWG are carved out of the core BSIG duties under § 28(5), because that regime already covers them. The carve-out ends if they operate other kritische Anlagen. 2,070 registrations.
  • Health: the largest registered sector by some distance, at 3,004 registrations.
  • Digital infrastructure: 2,044 registrations. DNS providers, TLD registries and qualified trust service providers are essential entities regardless of size.
  • Finance: entities already covered by DORA are exempt from §§ 30, 31, 32, 35, 36, 38 and 39 under § 28(6). 740 registrations.
  • Manufacturing: the largest Annex 2 sector, at 3,509 registrations — a population that had essentially no prior contact with the BSI.
  • Food: 1,568 registrations. Waste management: 793. Chemicals: 663. Water: 678. Transport: 599 across both annexes.
  • Telecoms: like energy, carved out of the core duties by § 28(5), with the same condition attached.

How Germany differs from the NIS2 baseline

Germany's transposition is close to the Directive in structure but makes several choices that materially change what compliance looks like on the ground.

  1. Two statutes, not one. NIS2 became the BSIG; the CER Directive on physical resilience became the separate KRITIS-Dachgesetz, in force since 17 March 2026. KRITIS operators sit under both. Registration of kritische Anlagen is meant to move to § 8 KRITIS-Dachgesetz, but that switch is not yet live: § 66 BSIG suspends it until an implementing ordinance is issued.
  2. Percentage fines apply only above €500 million turnover. The familiar "€10 million or 2% of turnover, whichever is higher" is not how German law works. See Penalties.
  3. Management liability runs to the company, not to the regulator. Under § 38(2) the Geschäftsleitung is liable to its own entity for culpably caused damage, under the company-law rules for its legal form. The BSIG liability is only subsidiary, applying where company law has no equivalent rule.
  4. Group thresholds are unusually generous. § 28(4) applies the EU SME definition but excludes Article 3(4) of its Annex, and disapplies the normal aggregation of partner and linked company data where the entity is genuinely independent in how its IT systems are built and run. A subsidiary of a large group can therefore fall outside scope where it would be captured elsewhere.
  5. Registration runs through the tax identity system. The ELSTER organisation certificate and Mein Unternehmenskonto are prerequisites. No other member state routes NIS2 registration this way.
  6. Civil protection is a joint owner. Registration and incident reporting are operated jointly with the BBK, reflecting Germany's treatment of cyber and physical resilience as one problem.

German terms you will meet

The portal, correspondence and the statute itself are German-only. The BSI publishes no English-language NIS2 guidance, so these are the strings you will actually encounter.

GermanEnglish
NIS2-Umsetzungsgesetz (NIS2UmsuCG)NIS2 Implementation Act
BSI-Gesetz (BSIG)The BSI Act — Article 1 of the NIS2UmsuCG, where the duties live
besonders wichtige Einrichtung (bwE)Essential entity
wichtige Einrichtung (wE)Important entity
kritische AnlageCritical installation (KRITIS)
RegistrierungspflichtDuty to register
MeldepflichtDuty to report incidents
erheblicher SicherheitsvorfallSignificant security incident
KenntniserlangungBecoming aware — when the reporting clock starts
GeschäftsleitungManagement body
NachweispflichtDuty to submit evidence (KRITIS operators)
BetroffenheitsprüfungThe BSI's official scope self-check tool
BußgeldAdministrative fine
Supervision is asymmetric, and the date is fixed. For essential entities the BSI can order audits and certifications proactively (§ 61(1)), but for essential entities generally it may only demand evidence of compliance from 6 December 2028 — three years after entry into force (§ 61(3)). For important entities, § 62 allows the BSI to act only where facts justify the assumption that duties are not being met. In practice that means reactive supervision for the larger group, and it makes the registration gap the most likely trigger.

Penalties under NIS2UmsuCG

§ 65 BSIG does not set one maximum. It sets six tiers, and which one applies depends on which duty you breached — not on how serious the consequences were.

Maximum fineWhat triggers it
€10m essential
€7m important
Failing to take the § 30 risk-management measures; failing to document them; missing the 24-hour or 72-hour report; missing the final report; failing to notify service recipients of a significant cyber threat.
€5mFailing to notify on the use of critical components (§ 41(5)).
€2mBreaching certain enforceable orders of the BSI.
€1mKRITIS evidence not submitted, or submitted late.
€500,000Failing to register, or filing registration data late, incorrectly or incompletely (§§ 33, 34).
€100,000Not remaining reachable; refusing inspectors entry, documents or information.
The turnover percentages have a threshold most summaries omit. The 2% (essential) and 1.4% (important) caps in § 65(6) and (7) apply only to entities whose total worldwide group turnover exceeds €500 million. Below that, the fixed euro amounts above are the ceiling. The common shorthand — "€10 million or 2% of turnover, whichever is higher" — is simply wrong for the large majority of the 29,500 entities in scope.
  • Coercive penalties are separate. Where the BSI enforces an order by Zwangsgeld, § 63 raises the ceiling to €100,000, above the standard administrative-enforcement limit.
  • Management liability is to the entity. § 38(2) makes the Geschäftsleitung liable to its own organisation for culpably caused damage, under the company-law rules applicable to its legal form — not to a personal fine from the BSI. The BSIG rule applies only where company law provides none.
  • No double punishment with the GDPR. § 65(11) bars a BSIG fine for conduct already fined by a data-protection authority under Article 58(2)(i) GDPR.

How to prepare for NIS2 in Germany

  1. Run the BSI's own Betroffenheitsprüfung first. It is free, anonymous and follows the statute's decision tree. It is explicitly non-binding and does not replace your own self-identification, but it is the fastest way to a defensible first answer.
  2. Check the thresholds properly, including the group question. § 28(4) may keep an independent subsidiary out of scope where the usual EU aggregation rules would pull it in.
  3. Register, even if you are late. The deadline has passed, but the exposure for not registering (€500,000) does not decrease with time, and the BSI can register you itself.
  4. Get the ELSTER certificate moving early. It is issued by the tax administration, not the BSI, and it gates everything else.
  5. Build the 24-hour reporting path before you need it. Decide now who can file, and how they reach the portal outside office hours.
  6. Put management training on the calendar. § 38(3) requires it regularly, and it is one of the few duties the BSI can check against a document.
  7. Document as you go. § 30(1) makes documentation a duty in its own right, separately punishable from the measures themselves.
  8. Map the overlaps. If DORA or the EnWG rules already cover you, § 28(5) and (6) may remove most of the BSIG duties — but only for those activities.

If you operate in more than one EU country

NIS2 is a directive, so each member state has its own act, its own regulator and its own portal. Germany is covered by the BSIG; the same group operating in Poland answers to a different statute with different deadlines.

  • German establishment is the test. The BSI's position is that what matters is whether the undertaking is established in Germany or has appointed a representative there — not whether the relevant services are delivered in Germany. A company can be in scope in Germany for services provided elsewhere.
  • Registration asks where else you operate. § 33(1) requires a list of every member state in which you provide the services that bring you into scope, and the authorities competent for them.
  • Digital providers follow their main establishment. For cloud, data centre, CDN, managed service and managed security service providers, marketplaces, search engines and social networks, § 60 assigns jurisdiction to the member state of the main EU establishment. Registered once under § 34, that data is forwarded to ENISA and shared across the EU.
  • Thresholds and penalties do not travel. The €500 million turnover threshold for percentage fines is a German choice. Others apply the percentage from the first euro.

For the position in the other member states we cover, see the NIS2 country guides.

Official links & resources

BSIG — full consolidated text (gesetze-im-internet.de). The operative law: § 28 scope, § 30 measures, § 32 reporting, § 33 registration, § 38 management duties, § 65 fines.
BSI — NIS-2 regulated companies. The regulator's own hub, including registration guidance and running statistics.
BSI NIS-2-Betroffenheitsprüfung — the official, free, anonymous scope self-check.
BSI-Portal — where registration and incident reports are filed.
KRITIS-Dachgesetz — the parallel physical-resilience act, in force since 17 March 2026.

FAQ: NIS2 in Germany

Is NIS2 already in force in Germany?
Yes. The NIS2UmsuCG was published on 5 December 2025 and the new BSIG entered into force on 6 December 2025. Both dates circulate; 6 December is when the duties began.
What was the registration deadline, and has it passed?
§ 33(1) BSIG gives three months from the point you first qualify. For entities already in scope when the law took effect, that was 6 March 2026, and it has passed. There was no general transition period. Reports of an extension to 31 July 2026 are a misreading of the BSI's statistics page, which simply announced when it would next be updated.
How do we actually register?
Apply for an ELSTER-Organisationszertifikat through Mein Unternehmenskonto, then register at portal.bsi.bund.de. You will need your legal form, Handelsregister number, contact details, sector, the EU states you serve and your public IP address ranges.
What happens if we never registered?
Failure to register carries a fine of up to €500,000 under § 65(5), and § 33(3) allows the BSI to register you itself. Registering late does not remove the exposure, but it does stop it growing.
Are the fines really 2% of global turnover?
Only above a threshold. The 2% and 1.4% caps apply only to entities with worldwide group turnover above €500 million (§ 65(6),(7)). Below that, the fixed maximums apply — €10m for essential and €7m for important entities on the most serious breaches, and considerably less for most others.
Can our directors be fined personally?
Not by the BSI. § 38(2) makes the Geschäftsleitung liable to its own entity for damage it culpably causes, under the company-law rules for that legal form. The BSIG rule is subsidiary and applies only where company law has no equivalent provision.
Does NIS2 replace the German KRITIS rules?
No. KRITIS operators are essential entities under the BSIG and covered by the separate KRITIS-Dachgesetz, in force since 17 March 2026, which deals with physical resilience. They also carry the § 39 duty to submit audits or certifications on a three-year cycle without being asked.
We are already subject to DORA. Do we still have to do all this?
Largely no. § 28(6) exempts financial entities covered by DORA from §§ 30, 31, 32, 35, 36, 38 and 39. The same applies under § 28(5) to telecoms and to energy network operators governed by §§ 5c–5e EnWG. The exemption is activity-specific: other activities can still bring you back in.
Is ISO 27001 enough?
No. The BSI's stated position is that a certification alone does not discharge the BSIG obligations, though ISO 27001 or IT-Grundschutz can be a component of the § 30 measures.

Sources & verification

Every date, figure and section reference on this page was read from the enacted statute text or from the BSI's own pages, and checked on 2 August 2026. Third-party NIS2 trackers contradict each other and are not used as sources.

  • BSIG, consolidated text — entry into force (Art. 30 NIS2UmsuCG, BGBl. 2025 I Nr. 301), scope and thresholds (§ 28), measures and documentation (§ 30), reporting (§ 32), registration (§§ 33–34), management duties and liability (§ 38), KRITIS evidence (§ 39), supervision (§§ 61–62), fines (§ 65) and the transitional rule (§ 66).
  • BSI — NIS-2 in Zahlen — the registration and incident-report figures as at 2 April 2026.
  • BSI NIS-2 FAQ — the source for the absence of a general transition period, the legislative dates, the definition of Kenntniserlangung, and the position on certification.
  • BSI press release of 13 November 2025 — the source for roughly 29,500 entities in scope, against about 4,500 under the previous law.
  • KRITIS-Dachgesetz — BGBl. 2026 I Nr. 66, in force 17 March 2026.
Five things we deliberately do not state. We do not repeat the claim that the BSI extended the registration deadline to 31 July 2026: that date is the announced next update of the BSI's statistics page, not a deadline, and reprinting it as one would give readers false comfort. We do not present the registration numbers as current — they are explicitly as at 2 April 2026, the last figures the BSI has published. We do not give a more precise share than "about half", because the 29,500 figure is itself the government's own estimate rather than a count. We do not say management can be fined personally by the BSI, because § 38(2) creates liability to the entity under company law; the draft bill's non-waiver clause did not survive into the enacted text. And we do not describe the KRITIS registration route under § 8 KRITIS-Dachgesetz as operational, because § 66 BSIG suspends it until an implementing ordinance is in force, and none has been issued.
General guidance, not legal advice. The BSIG has been amended three times since it entered into force and further ordinances are expected under the KRITIS-Dachgesetz — check the primary sources listed above before acting on a deadline.