Skip to main content
In forceNIS2

NIS2 in Germany

Germany's NIS2UmsuCG (rewriting the BSI-Gesetz) entered into force on 6 December 2025 with no transition period. Around 29,500 entities are in scope and the BSI expects registration by 31 July 2026.

Transposition law
NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG), Neufassung des BSIG
In force since
6 December 2025
Competent authority
Federal Office for Information Security (BSI)
Max fine (Essential)
€10 Mio. oder 2 % des weltweiten Jahresumsatzes
Max fine (Important)
€7 Mio. oder 1,4 % des weltweiten Jahresumsatzes
Law adopted
6 December 2025

Key Deadlines

NIS2UmsuCG in force (no transition period)
6 December 2025
BSI registration portal opens
6 January 2026
Original registration deadline
6 March 2026
BSI expects registration completed
31 July 2026

Competent Authority

Federal Office for Information Security (BSI)
Primary NIS2 supervisory authority for most sectors
https://www.bsi.bund.de

The BSI conducts proactive inspections for Essential Entities and reactive (complaint-driven) oversight for Important Entities. Organisations must self-register via the BSI portal.

Registration Process

Register via the BSI's MELDEPLATTFORM portal at meldeplattform.bsi.bund.de. You will need your company registration number (Handelsregisternummer), sector classification, and a designated security contact.

📊 Quick Test

Find out if your company is in scope

Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?

Check NIS2 Scope →

Key Requirements

  • 1Self-registration with the BSI — the original 6 March 2026 deadline has passed and the BSI expects registration by 31 July 2026
  • 2ISMS based on ISO 27001 or BSI IT-Grundschutz recommended
  • 324-hour early warning to BSI for significant incidents
  • 472-hour full notification with impact assessment
  • 5Monthly final report within 1 month
  • 6Management board personal liability for compliance
  • 7Supplier / supply chain risk assessments mandatory
  • 8Multi-factor authentication required for remote access

National Additions

KRITIS-Dachgesetz introduces physical resilience requirements for critical infrastructure operators alongside NIS2 cybersecurity obligations
Germany extended NIS2 scope to include certain mid-sized energy and water sector operators below EU thresholds
Federal agencies (Bundesbehörden) are included under the German NIS2 implementation

FAQ: NIS2 in Germany

Does Germany require ISO 27001 certification?
ISO 27001 is not legally mandatory under NIS2UmsuCG, but it is strongly recommended by the BSI as a way to demonstrate compliance with Article 21 security measures. IT-Grundschutz (BSI's own framework) is an equally accepted alternative.
Who must register with the BSI?
All Essential and Important Entities falling under NIS2UmsuCG must self-register. This includes operators in energy, transport, water, digital infrastructure, health, banking, and financial market sectors meeting the size thresholds.
Are smaller German companies affected?
The standard thresholds apply (250+ employees or €50M+ turnover for Essential Entities; 50+ employees or €10M+ for Important Entities). However, Germany extended scope for some energy and water sub-sectors below these thresholds.

Ready to assess your NIS2 compliance?

Use our free tools to check your NIS2 scope and run a gap assessment.

Currency and sources

The legal details on this page were last checked on 25 July 2026.