NIS2 · National implementation
NIS2 in Germany
Germany transposed NIS2 through the NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG), published in BGBl. 2025 I Nr. 301 and in force since 6 December 2025. Rather than a standalone act, it rewrites the existing BSIG (BSI Act), so German obligations are read out of the amended BSIG.
- National law
- NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG)
- NIS2 Implementation Act, amending the BSIG
- Status
- In force
- In force
- 6 December 2025
- Authority
- BSI
Supervision
The BSI (Bundesamt für Sicherheit in der Informationstechnik) is the central supervisory authority. Its Betroffenheitsprüfung, an official online self-check, is the standard way for German organisations to determine whether they are in scope, and its result documentation is worth keeping as evidence.
Registration
In-scope entities register with the BSI. The BSI operates the reporting portal for the three-stage incident reports.
What is specific to Germany
Germany kept and integrated its pre-existing KRITIS regime: operators of critical Anlagen (installations) above the KRITIS thresholds carry additional, stricter duties (including systems for attack detection) on top of the NIS2 baseline. The German act also details management liability (Geschäftsleitung) with an express duty to approve and oversee risk measures and undergo training, and it phases in evidence and audit duties for different entity classes. Penalty ceilings follow the directive's EUR 10m/2% and EUR 7m/1.4% structure.
Official sources
Primary references: the national statute book at www.recht.bund.de and the national cybersecurity authority at www.bsi.bund.de.
NIS2 in Germany: frequently asked questions
Last reviewed:
Related reading
Definitions
