Law · German NIS2 Implementation Act / BSI Act

NIS2 in Germany Obligations for important and essential entities.

The EU NIS2 Directive applies in Germany through the new BSI Act. Since 6 December 2025, entities in scope must manage cyber risks, report significant incidents, register with the BSI and hold their management accountable.

At a glance

Legal basis
Directive (EU) 2022/2555, transposed by the NIS2UmsuCG (Federal Law Gazette 2025 I No. 301)
Applies since
6 December 2025, with no transition period
Supervision
Federal Office for Information Security (BSI)
Fines
Up to €10m (essential) or €7m (important entities); above €500m turnover up to 2% or 1.4% of worldwide turnover (Section 65 BSIG)

Who NIS2 applies to

  • Companies in 18 sectors, including energy, transport, health, digital infrastructure, waste management, chemicals, food and manufacturing.
  • As a rule from 50 employees or more than €10m in annual turnover and balance sheet total. Large companies in sectors of high criticality count as essential.
  • Some providers are covered regardless of size, such as DNS service providers or qualified trust service providers.
  • Whether you are in scope is for you to assess. The BSI offers an online check for this.
Briefing for management

What NIS2 requires

  • 01

    Risk management (Section 30 BSIG)

    Ten minimum measures, including risk analysis, incident handling, business continuity, supply chain security, access control and training.

  • 02

    Reporting (Section 32 BSIG)

    Significant incidents: early warning within 24 hours, notification with an initial assessment within 72 hours, final report no later than one month after the notification.

  • 03

    Registration (Section 33 BSIG)

    Registration with the BSI within three months. The deadline passed in March 2026. If you have not registered yet, do so without delay.

  • 04

    Management (Section 38 BSIG)

    Management must implement the measures, oversee their implementation and attend training regularly. If it culpably breaches these duties, it is liable to the entity for the damage.

Deadlines and dates

  1. Directive (EU) 2022/2555 enters into force

  2. NIS2UmsuCG and the new BSI Act apply

  3. BSI registration deadline passed

268testable requirements in UniqSuite

How UniqSuite helps

UniqSuite takes you through the requirements topic by topic, from registration through the ten minimum measures to the duties of management. Classify an incident as significant and UniqSuite shows the reports that are due and tracks the deadlines.

Frequently asked questions

Is ISO 27001 certification enough for NIS2?

No. It is strong evidence of working risk management, but it does not replace reporting, registration or the duties of management.

Is there a NIS2 certificate?

No. The law has no general certification. You must be able to demonstrate implementation when the BSI asks.

Does NIS2 apply to municipalities?

Municipal administrations fall under the rules of their federal state. Municipal companies, however, can fall directly under the BSI Act.

We supply an entity in scope. Does NIS2 apply to us?

Not directly, as long as you are not in scope of the BSI Act yourself. Entities in scope must, however, manage the security of their supply chain (Section 30(2) no. 4 BSIG). Expect security requirements in contracts and supplier assessments as a result.

Where should we start?

First check whether your organisation is in scope, then register with the BSI. Next, set up a reporting process that meets the 24-hour deadline and plan the risk management measures under Section 30 BSIG. The free UniqSuite quick check shows where you stand in about two minutes, with no sign-up.

See what is still open for you.

In half an hour we show you how UniqSuite organises the requirements, makes gaps visible and produces evidence.

→Demo request

Show us your questions.

We will get back to you within two working days and arrange a demo of about 30 minutes – built around your own requirements.

Please fill in.

Please fill in.

Please fill in.

Please enter a valid email address.

Please use digits, spaces and + ( ) / - only.

We use your details solely to answer your request. Details in our privacy policy.