Skip to content

NIS 2 IN GERMANY

NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG) — the national act transposing Directive (EU) 2022/2555 in Germany. Supervised by Bundesamt für Sicherheit in der Informationstechnik (BSI).

DRAFT PUBLISHED

Key facts

In force
Not yet in force
National law
NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG)
Primary supervisor
Bundesamt für Sicherheit in der Informationstechnik (BSI)
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Covered entities must register with the BSI; the federal portal requires entity classification, sector, and contact for incident reporting.

Scope and national nuance

The NIS2UmsuCG significantly broadens the prior KRITIS regime, bringing an estimated 29,000 German entities into scope across the eighteen NIS 2 sectors. Federal administration is explicitly covered; Länder administration scope is set by state law.

Sector supervisors

SectorAuthorityAcronym
EnergyBundesnetzagenturBNetzA
Telecommunications and digital infrastructureBundesnetzagenturBNetzA
Financial servicesBundesanstalt für FinanzdienstleistungsaufsichtBaFin
Federal administrationBundesamt für Sicherheit in der InformationstechnikBSI

What is specific to Germany

DSI Advisory — NIS 2 Programme

Move from reading the law to evidencing compliance

Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to BSI’s supervisory expectations.

NIS 2 Scorecard →Scope & gap assessment →NIS 2 reference page →