NIS2 Germany: NIS2UmsuCG, BSI Registration & Penalties
Germany transposed the NIS2 Directive through the NIS2-Umsetzungsgesetz (NIS2UmsuCG), whose Article 1 is the rewritten BSI-Gesetz (BSIG). It was published on 5 December 2025 and entered into force on 6 December 2025. Around 29,500 entities are now supervised by the BSI, up from roughly 4,500 under the old law.
Introduction: NIS2 Directive & the German context
Germany already had one of the EU's more developed cybersecurity regimes before NIS2, built on the IT-Sicherheitsgesetz and the KRITIS rules for critical infrastructure. Those covered roughly 4,500 entities.
The NIS2-Umsetzungsgesetz (NIS2UmsuCG) changed the scale rather than the philosophy. Its Article 1 replaced the BSI-Gesetz of 2009 with a new BSIG, and the number of organisations under BSI supervision rose to about 29,500. Most of them had never dealt with the BSI before.
The obligations are already live. There was no general transition period: registration, risk management and incident reporting all applied from the day the law took effect.
What you must do in Germany
Six duties, each with its own statutory hook and its own penalty if missed. The deadlines are counted from the moment you first qualify as an in-scope entity, not from a single national date.
- Determine your own status. Germany uses self-identification: no authority writes to tell you that you are in scope. You are either a besonders wichtige Einrichtung (essential entity) or a wichtige Einrichtung (important entity) under § 28 BSIG, or neither.
- Register with the BSI within three months of first qualifying (§ 33(1)). For entities already in scope when the law took effect, that deadline was 6 March 2026 and has passed. See Registering with the BSI.
- Implement the ten risk-management measures in § 30(2), proportionate to your risk exposure, size and the cost of implementation — and document that you have done so. The documentation duty is written into § 30(1) as a separate obligation.
- Be able to report an incident within 24 hours. The chain runs 24 hours, 72 hours, then a final report one month later. See Incident reporting.
- Get your management trained, and keep them involved. Under § 38 the Geschäftsleitung must implement and supervise the measures personally, and attend training regularly. This is not delegable to the IT department.
- Keep your registration current. Changes to the data you filed must reach the BSI within two weeks (§ 33(5)).
NIS2 Directive implementation in Germany
Germany transposed the NIS2 Directive through the NIS2-Umsetzungsgesetz (NIS2UmsuCG). The Bundestag passed it on 13 November 2025 and the Bundesrat approved it on 21 November 2025. It was published in the Federal Law Gazette as BGBl. 2025 I Nr. 301 on 5 December 2025 and, under its Article 30, entered into force the following day, 6 December 2025.
The distinction matters because both dates circulate. 5 December is the date of publication; 6 December is the date the obligations began. Germany transposed almost fourteen months after the EU deadline of 17 October 2024.
Article 1 of the NIS2UmsuCG is a complete replacement of the BSI-Gesetz, so the operative rules are cited as sections of the BSIG rather than of the NIS2UmsuCG itself. The BSIG has since been amended three times: by the KRITIS-Dachgesetz of 11 March 2026, and by two further acts of 21 and 23 July 2026.
Status
In force since 6 December 2025. Published 5 December 2025 as BGBl. 2025 I Nr. 301. No general transition period was granted.
Supervising authority
The Bundesamt für Sicherheit in der Informationstechnik (BSI) supervises, audits and receives reports. Registration and incident reporting run through a facility operated jointly with the BBK, the federal civil-protection agency.
Scale
About 29,500 entities are in scope. By 2 April 2026, 15,477 had registered — roughly half. The BSI has published no newer figure.
NIS2 Germany: compliance requirements
Germany follows the two-tier NIS2 structure, but names it in its own terms and sets its own thresholds. An besonders wichtige Einrichtung is an essential entity; a wichtige Einrichtung is an important entity. Which one you are decides how the BSI supervises you and how large a fine you face.
Scope thresholds (§ 28 BSIG)
Besonders wichtige Einrichtungen (essential):
- Operators of kritische Anlagen (KRITIS installations).
- Qualified trust service providers, TLD name registries and DNS service providers — at any size.
- Annex 1 entity types with at least 250 staff, or turnover above €50m and a balance sheet total above €43m.
Wichtige Einrichtungen (important):
- Trust service providers not covered above.
- Annex 1 and Annex 2 entity types with at least 50 staff, or turnover above €10m and a balance sheet total above €10m.
The ten measures (§ 30(2) BSIG)
- Risk analysis and information-security policies.
- Incident handling.
- Business continuity: backup management, disaster recovery, crisis management.
- Supply-chain security, including the security aspects of relationships with direct suppliers.
- Security in acquisition, development and maintenance, including vulnerability handling and disclosure.
- Procedures to assess whether the measures actually work.
- Basic cyber-hygiene training and awareness.
- Policies on the use of cryptography.
- Personnel security, access control and asset management.
- Multi-factor or continuous authentication, secured voice, video and text communication, and secured emergency communications where relevant.
§ 30(1) adds a separate duty: you must document your compliance. Failure to do so is independently punishable.
Certification & standards
No certification is mandatory. The BSI's own position is that a certificate alone is not sufficient to discharge the BSIG duties, though ISO 27001 or IT-Grundschutz can be a building block towards the § 30 measures.
Ordinary entities only have to prove compliance when the BSI asks. Operators of kritische Anlagen are different: under § 39 they must submit audits, tests or certifications on a cycle, without being asked.
Registering with the BSI
Registration is the single most commonly missed duty in Germany, and the route to it is not obvious: it runs through the tax administration's identity system before it ever reaches the BSI.
1. Get an ELSTER organisation certificate
Apply for an ELSTER-Organisationszertifikat through the federal Mein Unternehmenskonto service. This is the German business identity credential, originally built for tax filing. Without it you cannot open a BSI portal account.
2. Register in the BSI-Portal
Use the certificate to register at portal.bsi.bund.de. The same portal is later used for incident reports.
3. Keep it current
Any change to the information you filed must reach the BSI within two weeks (§ 33(5) BSIG).
What you have to supply (§ 33(1) BSIG)
- Entity name, including legal form and, where applicable, the Handelsregister number.
- Address and current contact details, including email address and telephone numbers.
- Public IP address ranges. This one regularly surprises organisations — it is a statutory requirement, not an optional field.
- The relevant sector, and where applicable sub-sector, from Annex 1 or Annex 2.
- Every EU member state in which you provide the services that put you in scope.
- The federal and state supervisory authorities competent for those activities.
Two further points. If you do not register, § 33(3) lets the BSI register you itself, in agreement with the competent supervisory authority. And a distinct track exists under § 34 for DNS providers, TLD registries, cloud and data-centre providers, CDNs, managed service and managed security service providers, online marketplaces, search engines and social network platforms: they file a different data set, also within three months, which the BSI forwards to ENISA.
How many have actually registered
The BSI publishes running totals. At 2 April 2026, its last published figures:
| Measure | Count |
|---|---|
| Registrations in the BSI portal | 15,477 |
| — of which wichtige Einrichtungen (important) | 9,894 |
| — of which besonders wichtige Einrichtungen (essential) | 5,583 |
| — of which KRITIS operators (a subset of the essential entities) | 1,260 |
| Registered secondary establishments / cross-border | 214 |
| Total registrations | 15,691 |
| Initial incident reports filed | 248 |
| All incident reports via the portal (initial plus follow-up) | 541 |
Against roughly 29,500 entities expected in scope, that is about half. The gap is the single clearest indicator of where German enforcement attention is likely to go first.
Incident reporting: the 24 / 72 / one-month chain
§ 32 BSIG sets a three-stage chain for any erheblicher Sicherheitsvorfall (significant security incident). Reports go to the reporting office run jointly by the BSI and the BBK, through the same portal used for registration.
Operators of kritische Anlagen supply more: under § 32(3) they must also state the type of installation and critical service affected, and the effect on that service. The BSI acknowledges receipt within 24 hours where possible, and can offer technical support and advice on remediation (§ 36).
One nuance worth knowing: § 32(1) provides that the reporting duty applies at the earliest from the point the reporting channel exists. Voluntary reports are also possible through the portal.
NIS2 timeline & key dates (Germany)
Sector-specific notes for Germany
- Energy: operators of energy networks, installations and digital energy services governed by §§ 5c–5e EnWG are carved out of the core BSIG duties under § 28(5), because that regime already covers them. The carve-out ends if they operate other kritische Anlagen. 2,070 registrations.
- Health: the largest registered sector by some distance, at 3,004 registrations.
- Digital infrastructure: 2,044 registrations. DNS providers, TLD registries and qualified trust service providers are essential entities regardless of size.
- Finance: entities already covered by DORA are exempt from §§ 30, 31, 32, 35, 36, 38 and 39 under § 28(6). 740 registrations.
- Manufacturing: the largest Annex 2 sector, at 3,509 registrations — a population that had essentially no prior contact with the BSI.
- Food: 1,568 registrations. Waste management: 793. Chemicals: 663. Water: 678. Transport: 599 across both annexes.
- Telecoms: like energy, carved out of the core duties by § 28(5), with the same condition attached.
How Germany differs from the NIS2 baseline
Germany's transposition is close to the Directive in structure but makes several choices that materially change what compliance looks like on the ground.
- Two statutes, not one. NIS2 became the BSIG; the CER Directive on physical resilience became the separate KRITIS-Dachgesetz, in force since 17 March 2026. KRITIS operators sit under both. Registration of kritische Anlagen is meant to move to § 8 KRITIS-Dachgesetz, but that switch is not yet live: § 66 BSIG suspends it until an implementing ordinance is issued.
- Percentage fines apply only above €500 million turnover. The familiar "€10 million or 2% of turnover, whichever is higher" is not how German law works. See Penalties.
- Management liability runs to the company, not to the regulator. Under § 38(2) the Geschäftsleitung is liable to its own entity for culpably caused damage, under the company-law rules for its legal form. The BSIG liability is only subsidiary, applying where company law has no equivalent rule.
- Group thresholds are unusually generous. § 28(4) applies the EU SME definition but excludes Article 3(4) of its Annex, and disapplies the normal aggregation of partner and linked company data where the entity is genuinely independent in how its IT systems are built and run. A subsidiary of a large group can therefore fall outside scope where it would be captured elsewhere.
- Registration runs through the tax identity system. The ELSTER organisation certificate and Mein Unternehmenskonto are prerequisites. No other member state routes NIS2 registration this way.
- Civil protection is a joint owner. Registration and incident reporting are operated jointly with the BBK, reflecting Germany's treatment of cyber and physical resilience as one problem.
German terms you will meet
The portal, correspondence and the statute itself are German-only. The BSI publishes no English-language NIS2 guidance, so these are the strings you will actually encounter.
| German | English |
|---|---|
| NIS2-Umsetzungsgesetz (NIS2UmsuCG) | NIS2 Implementation Act |
| BSI-Gesetz (BSIG) | The BSI Act — Article 1 of the NIS2UmsuCG, where the duties live |
| besonders wichtige Einrichtung (bwE) | Essential entity |
| wichtige Einrichtung (wE) | Important entity |
| kritische Anlage | Critical installation (KRITIS) |
| Registrierungspflicht | Duty to register |
| Meldepflicht | Duty to report incidents |
| erheblicher Sicherheitsvorfall | Significant security incident |
| Kenntniserlangung | Becoming aware — when the reporting clock starts |
| Geschäftsleitung | Management body |
| Nachweispflicht | Duty to submit evidence (KRITIS operators) |
| Betroffenheitsprüfung | The BSI's official scope self-check tool |
| Bußgeld | Administrative fine |
Penalties under NIS2UmsuCG
§ 65 BSIG does not set one maximum. It sets six tiers, and which one applies depends on which duty you breached — not on how serious the consequences were.
| Maximum fine | What triggers it |
|---|---|
| €10m essential €7m important |
Failing to take the § 30 risk-management measures; failing to document them; missing the 24-hour or 72-hour report; missing the final report; failing to notify service recipients of a significant cyber threat. |
| €5m | Failing to notify on the use of critical components (§ 41(5)). |
| €2m | Breaching certain enforceable orders of the BSI. |
| €1m | KRITIS evidence not submitted, or submitted late. |
| €500,000 | Failing to register, or filing registration data late, incorrectly or incompletely (§§ 33, 34). |
| €100,000 | Not remaining reachable; refusing inspectors entry, documents or information. |
- Coercive penalties are separate. Where the BSI enforces an order by Zwangsgeld, § 63 raises the ceiling to €100,000, above the standard administrative-enforcement limit.
- Management liability is to the entity. § 38(2) makes the Geschäftsleitung liable to its own organisation for culpably caused damage, under the company-law rules applicable to its legal form — not to a personal fine from the BSI. The BSIG rule applies only where company law provides none.
- No double punishment with the GDPR. § 65(11) bars a BSIG fine for conduct already fined by a data-protection authority under Article 58(2)(i) GDPR.
How to prepare for NIS2 in Germany
- Run the BSI's own Betroffenheitsprüfung first. It is free, anonymous and follows the statute's decision tree. It is explicitly non-binding and does not replace your own self-identification, but it is the fastest way to a defensible first answer.
- Check the thresholds properly, including the group question. § 28(4) may keep an independent subsidiary out of scope where the usual EU aggregation rules would pull it in.
- Register, even if you are late. The deadline has passed, but the exposure for not registering (€500,000) does not decrease with time, and the BSI can register you itself.
- Get the ELSTER certificate moving early. It is issued by the tax administration, not the BSI, and it gates everything else.
- Build the 24-hour reporting path before you need it. Decide now who can file, and how they reach the portal outside office hours.
- Put management training on the calendar. § 38(3) requires it regularly, and it is one of the few duties the BSI can check against a document.
- Document as you go. § 30(1) makes documentation a duty in its own right, separately punishable from the measures themselves.
- Map the overlaps. If DORA or the EnWG rules already cover you, § 28(5) and (6) may remove most of the BSIG duties — but only for those activities.
If you operate in more than one EU country
NIS2 is a directive, so each member state has its own act, its own regulator and its own portal. Germany is covered by the BSIG; the same group operating in Poland answers to a different statute with different deadlines.
- German establishment is the test. The BSI's position is that what matters is whether the undertaking is established in Germany or has appointed a representative there — not whether the relevant services are delivered in Germany. A company can be in scope in Germany for services provided elsewhere.
- Registration asks where else you operate. § 33(1) requires a list of every member state in which you provide the services that bring you into scope, and the authorities competent for them.
- Digital providers follow their main establishment. For cloud, data centre, CDN, managed service and managed security service providers, marketplaces, search engines and social networks, § 60 assigns jurisdiction to the member state of the main EU establishment. Registered once under § 34, that data is forwarded to ENISA and shared across the EU.
- Thresholds and penalties do not travel. The €500 million turnover threshold for percentage fines is a German choice. Others apply the percentage from the first euro.
For the position in the other member states we cover, see the NIS2 country guides.
Official links & resources
FAQ: NIS2 in Germany
Is NIS2 already in force in Germany?
What was the registration deadline, and has it passed?
How do we actually register?
What happens if we never registered?
Are the fines really 2% of global turnover?
Can our directors be fined personally?
Does NIS2 replace the German KRITIS rules?
We are already subject to DORA. Do we still have to do all this?
Is ISO 27001 enough?
Sources & verification
Every date, figure and section reference on this page was read from the enacted statute text or from the BSI's own pages, and checked on 2 August 2026. Third-party NIS2 trackers contradict each other and are not used as sources.
- BSIG, consolidated text — entry into force (Art. 30 NIS2UmsuCG, BGBl. 2025 I Nr. 301), scope and thresholds (§ 28), measures and documentation (§ 30), reporting (§ 32), registration (§§ 33–34), management duties and liability (§ 38), KRITIS evidence (§ 39), supervision (§§ 61–62), fines (§ 65) and the transitional rule (§ 66).
- BSI — NIS-2 in Zahlen — the registration and incident-report figures as at 2 April 2026.
- BSI NIS-2 FAQ — the source for the absence of a general transition period, the legislative dates, the definition of Kenntniserlangung, and the position on certification.
- BSI press release of 13 November 2025 — the source for roughly 29,500 entities in scope, against about 4,500 under the previous law.
- KRITIS-Dachgesetz — BGBl. 2026 I Nr. 66, in force 17 March 2026.
