NIS2 · National implementation

NIS2 in Germany

Germany transposed NIS2 through the NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG), published in BGBl. 2025 I Nr. 301 and in force since 6 December 2025. Rather than a standalone act, it rewrites the existing BSIG (BSI Act), so German obligations are read out of the amended BSIG.

National law
NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG)
NIS2 Implementation Act, amending the BSIG
Status
In force
In force
6 December 2025
Authority
BSI

Supervision

The BSI (Bundesamt für Sicherheit in der Informationstechnik) is the central supervisory authority. Its Betroffenheitsprüfung, an official online self-check, is the standard way for German organisations to determine whether they are in scope, and its result documentation is worth keeping as evidence.

Registration

In-scope entities register with the BSI. The BSI operates the reporting portal for the three-stage incident reports.

What is specific to Germany

Germany kept and integrated its pre-existing KRITIS regime: operators of critical Anlagen (installations) above the KRITIS thresholds carry additional, stricter duties (including systems for attack detection) on top of the NIS2 baseline. The German act also details management liability (Geschäftsleitung) with an express duty to approve and oversee risk measures and undergo training, and it phases in evidence and audit duties for different entity classes. Penalty ceilings follow the directive's EUR 10m/2% and EUR 7m/1.4% structure.

Official sources

Primary references: the national statute book at www.recht.bund.de and the national cybersecurity authority at www.bsi.bund.de.

NIS2 in Germany: frequently asked questions

Last reviewed:

Related reading

All 27 EU member states