Law · German NIS2 Implementation Act / BSI Act
NIS2 in Germany Obligations for important and essential entities.
The EU NIS2 Directive applies in Germany through the new BSI Act. Since 6 December 2025, entities in scope must manage cyber risks, report significant incidents, register with the BSI and hold their management accountable.
At a glance
- Legal basis
- Directive (EU) 2022/2555, transposed by the NIS2UmsuCG (Federal Law Gazette 2025 I No. 301)
- Applies since
- 6 December 2025, with no transition period
- Supervision
- Federal Office for Information Security (BSI)
- Fines
- Up to €10m (essential) or €7m (important entities); above €500m turnover up to 2% or 1.4% of worldwide turnover (Section 65 BSIG)
Who NIS2 applies to
- Companies in 18 sectors, including energy, transport, health, digital infrastructure, waste management, chemicals, food and manufacturing.
- As a rule from 50 employees or more than €10m in annual turnover and balance sheet total. Large companies in sectors of high criticality count as essential.
- Some providers are covered regardless of size, such as DNS service providers or qualified trust service providers.
- Whether you are in scope is for you to assess. The BSI offers an online check for this.

What NIS2 requires
- 01
Risk management (Section 30 BSIG)
Ten minimum measures, including risk analysis, incident handling, business continuity, supply chain security, access control and training.
- 02
Reporting (Section 32 BSIG)
Significant incidents: early warning within 24 hours, notification with an initial assessment within 72 hours, final report no later than one month after the notification.
- 03
Registration (Section 33 BSIG)
Registration with the BSI within three months. The deadline passed in March 2026. If you have not registered yet, do so without delay.
- 04
Management (Section 38 BSIG)
Management must implement the measures, oversee their implementation and attend training regularly. If it culpably breaches these duties, it is liable to the entity for the damage.
Deadlines and dates
Directive (EU) 2022/2555 enters into force
NIS2UmsuCG and the new BSI Act apply
BSI registration deadline passed
How UniqSuite helps
UniqSuite takes you through the requirements topic by topic, from registration through the ten minimum measures to the duties of management. Classify an incident as significant and UniqSuite shows the reports that are due and tracks the deadlines.
Frequently asked questions
Is ISO 27001 certification enough for NIS2?
No. It is strong evidence of working risk management, but it does not replace reporting, registration or the duties of management.
Is there a NIS2 certificate?
No. The law has no general certification. You must be able to demonstrate implementation when the BSI asks.
Does NIS2 apply to municipalities?
Municipal administrations fall under the rules of their federal state. Municipal companies, however, can fall directly under the BSI Act.
We supply an entity in scope. Does NIS2 apply to us?
Not directly, as long as you are not in scope of the BSI Act yourself. Entities in scope must, however, manage the security of their supply chain (Section 30(2) no. 4 BSIG). Expect security requirements in contracts and supplier assessments as a result.
Where should we start?
First check whether your organisation is in scope, then register with the BSI. Next, set up a reporting process that meets the 24-hour deadline and plan the risk management measures under Section 30 BSIG. The free UniqSuite quick check shows where you stand in about two minutes, with no sign-up.
See what is still open for you.
In half an hour we show you how UniqSuite organises the requirements, makes gaps visible and produces evidence.
