Skip to main content
Informationssicherheit / NIS2

German NIS2 Implementation Act

The German NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) transposes Directive (EU) 2022/2555 into German law, rewrites the BSI Act and obliges in-scope entities to register, manage cyber risk and report incidents under BSI supervision.

The NIS2UmsuCG is an omnibus act whose centrepiece is a complete rewrite of the German BSI Act (BSIG). It transposes Directive (EU) 2022/2555 (NIS 2), whose transposition deadline expired on 17 October 2024; Germany missed that date by a wide margin, prompting infringement proceedings by the European Commission. Following adoption by the Bundestag in November 2025 and passage through the Bundesrat, the act entered into force around the turn of the year 2025/2026. It expands the regulated population from a few thousand critical-infrastructure operators to an estimated several tens of thousands of organisations and distinguishes between "essential entities" (besonders wichtige Einrichtungen) and "important entities" (wichtige Einrichtungen) under section 28 BSIG. Scope depends on sector allocation — energy, transport, health, digital infrastructure, waste management, chemicals, food, manufacturing, postal services and ICT service management, among others — combined with the size thresholds of the EU SME definition. There is generally no official designation letter: organisations must assess and document their own in-scope status.

In practice the first obligation is registration with the BSI (section 33 BSIG): in-scope entities must register through the BSI portal within three months of the point at which they become subject to the act, providing details of the entity, its sector, contact data and a round-the-clock security contact point, and must keep those details up to date. Extended registration details apply to certain digital service and digital infrastructure providers — DNS service providers, TLD registries, cloud computing, data centre and CDN providers, managed service providers as well as online marketplaces, search engines and social networks. If an entity fails to register, the BSI may register it on its own initiative. Substantively, the act requires a risk-based baseline of technical and organisational measures (section 30 BSIG: risk analysis and security policies, incident handling, business continuity and backup, supply chain security, cryptography, access control, multi-factor authentication and training), a three-stage reporting chain for significant incidents (early warning within 24 hours, incident notification within 72 hours, final report within one month, section 32 BSIG) and explicit management duties to approve the measures, oversee their implementation and attend regular cybersecurity training (section 38 BSIG).

The supervisory authority is the Federal Office for Information Security (BSI). The act mirrors the directive's supervisory model: essential entities face proactive supervision including inspections without specific cause, on-site checks and security audits as well as periodic evidence obligations, whereas important entities are in principle supervised only reactively — after an incident or where there are indications of non-compliance. The BSI may demand information and documentation, order the remediation of deficiencies and, for serious breaches, escalate up to a temporary ban on individuals exercising management functions. Fine ranges follow the directive: up to EUR 10 million or 2 percent of worldwide annual turnover for essential entities and up to EUR 7 million or 1.4 percent for important entities. The NIS2UmsuCG should not be confused with the planned German KRITIS umbrella act, which governs the physical resilience of critical entities under the CER Directive (EU) 2022/2557 and is being legislated separately — the two regimes interlock for critical-infrastructure operators but do not replace one another.

Legal Basis

NIS2UmsuCG (revised BSI Act, in particular sections 28, 30, 32, 33, 38, 39 BSIG); Directive (EU) 2022/2555 (NIS 2)

Practical Example

A mechanical engineering company with 450 employees and EUR 90 million in annual turnover concludes from its scoping assessment that, as a manufacturer of machinery and equipment, it falls under the manufacturing sector and therefore qualifies as an "important entity" under the revised BSIG. The information security officer documents the assessment in a traceable way, registers the company through the BSI portal within the three-month deadline and nominates a security contact point reachable around the clock. He then maps the existing ISMS against the measure catalogue of section 30 BSIG, closes the gaps identified in multi-factor authentication, supplier assurance and backup restore testing, embeds the 24-hour and 72-hour reporting chain into the emergency organisation including an on-call rota, and has the remediation plan formally approved by the managing directors, who also complete documented cybersecurity training so that compliance with section 38 BSIG can be evidenced.

FAQ

Registration is mandatory for every entity that qualifies as an essential or important entity by sector and size thresholds, and — irrespective of size — for certain digital infrastructure providers and critical-infrastructure operators. Registration runs through the BSI portal within three months of the entity becoming subject to the act. No authority notifies companies that they are in scope: the self-assessment and its documentation are the organisation's own responsibility.
The BSI can request information and evidence, carry out inspections and order the remediation of deficiencies. For serious breaches the act provides for fines of up to EUR 10 million or 2 percent of worldwide annual turnover for essential entities and up to EUR 7 million or 1.4 percent for important entities. On top of that, management bears personal responsibility for approving and monitoring the risk management measures.
The EU transposition deadline expired on 17 October 2024; the German act was adopted considerably later and entered into force around the turn of the year 2025/2026. Registration and reporting duties apply immediately from entry into force, or from the moment an entity becomes in scope, while longer periods apply to the evidence obligations. Because individual transitional rules and sub-statutory specifications are still being refined, the current status should be verified before finalising an implementation plan.

How preeco supports you

Learn how our software supports you with this topic.

Learn more