Directive NIS2 European Union
DE · Member state

NIS2 in Germany


What binds you in Germany is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.

Transposition
Transposed
Competent authority
BSI
National CSIRT
VAT on your purchase
19%

Reviewed . Verify against the national official journal before relying on this for a filing.

The text that actually binds you

National transposition


National law

NIS2UmsuCG — Act implementing the NIS2 Directive and regulating essential features of information security management in the federal administration

In force

The act comprehensively amends the BSI Act (BSIG), which is where the operative obligations now sit. It applied immediately on entry into force, with no transition period — unusually harsh among the transpositions.

Registration

BSI portal

The BSI registration and incident reporting portal went live on 6 January 2026, and entities in scope had to complete registration by 6 March 2026. The BSI has said it will not enforce that date before 31 July 2026. Read that as forbearance, not as a new deadline: the legal date remains 6 March, and an entity that missed it has been in breach since. Entities coming into scope later register on coming into scope.

National assessment framework · Binding on the federal administration; the de facto benchmark for all

IT-Grundschutz — IT-Grundschutz-Kompendium

Edition 2025, transitioning to Grundschutz++ by Bundesamt für Sicherheit in der Informationstechnik (BSI). Built on BSI-Standards 200-1 (management), 200-2 (methodology), 200-3 (risk analysis) and 200-4 (business continuity).

IT-Grundschutz is formally binding only on the federal administration. In practice it is the benchmark German auditors and insurers apply to operators and large enterprises, which makes it the de facto reference even where it is not legally required.

A label is not compliance

IT-Grundschutz is formally binding only on the federal administration. The NIS2UmsuCG does not make it mandatory for private entities. It is, however, the benchmark German auditors and insurers apply in practice, which makes it the de facto reference even where no law requires it — and the reason a German implementation plan that ignores it tends to be re-done.

IT-Grundschutz in full — levels, controls and what it does not cover →

Who supervises you

BSI is the competent authority designated by Germany. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.

Incident notifications under article 23 normally go to CERT-Bund, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.

What differs from the directive

Because NIS2 is a directive, Germany legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:

  • Registration. The portal, the information required and the deadline are national.
  • Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
  • Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
  • Reporting format. Deadlines are fixed by the directive; the form and the language are national.

If you operate in several member states

You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.

Cart 0