NIS 2 — Germany
NIS 2 IN GERMANY
NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG) — the national act transposing Directive (EU) 2022/2555 in Germany. Supervised by Bundesamt für Sicherheit in der Informationstechnik (BSI).
DRAFT PUBLISHED
Key facts
In force
Not yet in force
Primary supervisor
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Covered entities must register with the BSI; the federal portal requires entity classification, sector, and contact for incident reporting.
Scope and national nuance
The NIS2UmsuCG significantly broadens the prior KRITIS regime, bringing an estimated 29,000 German entities into scope across the eighteen NIS 2 sectors. Federal administration is explicitly covered; Länder administration scope is set by state law.
Sector supervisors
| Sector | Authority | Acronym |
|---|---|---|
| Energy | Bundesnetzagentur | BNetzA |
| Telecommunications and digital infrastructure | Bundesnetzagentur | BNetzA |
| Financial services | Bundesanstalt für Finanzdienstleistungsaufsicht | BaFin |
| Federal administration | Bundesamt für Sicherheit in der Informationstechnik | BSI |
What is specific to Germany
- Federal administration is mandatory in scope and supervised directly by the BSI; Länder administration scope is left to state law, creating uneven national coverage.
- BSI takes the central registration and incident-reporting role; sector supervisors (BNetzA for energy and telecom, BaFin for finance) retain sector enforcement.
- Significant fines are explicitly available against managing directors personally where they breach their cyber-risk-management oversight duty — a German-law twist on the directive's management accountability clause.
- The act tightens supply-chain documentation obligations on critical components beyond the directive's baseline, building on the prior KRITIS architecture.
DSI Advisory — NIS 2 Programme
Move from reading the law to evidencing compliance
Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to BSI’s supervisory expectations.