NIS2 in Germany
Germany's NIS2UmsuCG (rewriting the BSI-Gesetz) entered into force on 6 December 2025 with no transition period. Around 29,500 entities are in scope and the BSI expects registration by 31 July 2026.
Key Deadlines
Competent Authority
The BSI conducts proactive inspections for Essential Entities and reactive (complaint-driven) oversight for Important Entities. Organisations must self-register via the BSI portal.
Registration Process
Register via the BSI's MELDEPLATTFORM portal at meldeplattform.bsi.bund.de. You will need your company registration number (Handelsregisternummer), sector classification, and a designated security contact.
Find out if your company is in scope
Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?
Key Requirements
- 1Self-registration with the BSI — the original 6 March 2026 deadline has passed and the BSI expects registration by 31 July 2026
- 2ISMS based on ISO 27001 or BSI IT-Grundschutz recommended
- 324-hour early warning to BSI for significant incidents
- 472-hour full notification with impact assessment
- 5Monthly final report within 1 month
- 6Management board personal liability for compliance
- 7Supplier / supply chain risk assessments mandatory
- 8Multi-factor authentication required for remote access
National Additions
FAQ: NIS2 in Germany
Does Germany require ISO 27001 certification?
Who must register with the BSI?
Are smaller German companies affected?
Ready to assess your NIS2 compliance?
Use our free tools to check your NIS2 scope and run a gap assessment.
Currency and sources
The legal details on this page were last checked on 25 July 2026.