NIS2 in Germany: What Do Companies Need to Know in 2026?

The NIS2 Implementation Act has been in force since December 2025. Around 29,500 companies in Germany must now comply with registration, reporting, and risk management obligations. Duties, deadlines, fines, and implementation — the complete overview.
The NIS2 Implementation Act (NIS2UmsuCG) has been in force since December 6, 2025, with no transition period. Around 29,500 companies in Germany must now fulfill registration, reporting, and risk management obligations. Violations carry fines of up to EUR 10 million. NIS2Compass' Pre-Check identifies the biggest gaps in your NIS2 compliance in under 5 minutes.
What Is the NIS2 Implementation Act, and When Did It Take Effect?
The NIS2UmsuCG transposes the EU NIS2 Directive (EU 2022/2555) into German law and fundamentally overhauls the BSI Act (BSIG). All obligations have applied immediately since December 6, 2025. Germany exceeded the EU deadline of October 17, 2024, by over a year. Instead of the previous 4,500, the BSI now regulates approximately 29,500 entities.
From EU Directive to German law: The EU NIS2 Directive sets a binding framework that member states must transpose into national law. In Germany, this is done through the NIS2UmsuCG, which fundamentally amends the BSI Act (BSIG). The key point: the NIS2UmsuCG is the authoritative law for German companies, not the EU Directive itself.
Legislative process at a glance:
- November 13, 2025: Bundestag passes the NIS2UmsuCG
- December 5, 2025: Publication in the Bundesgesetzblatt (BGBl. I No. 301)
- December 6, 2025: Entry into force: all obligations apply immediately, no transition periods
No grace period: Unlike previous regulatory initiatives, there is no phased introduction. Companies that fall under the law have been fully required to comply since December 6, 2025.
Significant expansion beyond previous KRITIS regulation: The former IT Security Act covered around 4,500 entities. With the NIS2UmsuCG, that number rises to approximately 29,500, an increase of over 550 percent. BSI President Claudia Plattner commented on the entry into force: "With this law, Germany has reached an important milestone on the path to a resilient cyber nation."
Background and official context is also provided by the German Federal Government in its overview of the NIS2 Directive. For the specific obligations that apply to your company, NIS2Compass' NIS2 Guide walks you through all eight chapters step by step.
Is My Company Affected by NIS2?
NIS2 applies to companies with at least 50 employees or EUR 10 million in annual revenue operating in one of 18 regulated sectors. In Germany, around 29,500 entities fall under the new law. You can determine whether you are affected by checking the thresholds and sector classification. The BSI provides an online tool for this purpose.
What Thresholds Apply?
The NIS2UmsuCG distinguishes between two categories of entities. The determining factor is the size-cap rule as defined in EU Recommendation 2003/361/EC.
Essential entities (§28 para. 1 BSIG): 250 or more employees, or annual revenue exceeding EUR 50 million and a balance sheet total exceeding EUR 43 million, exclusively in sectors listed in Annex 1.
Important entities (§28 para. 2 BSIG): 50 or more employees, or annual revenue exceeding EUR 10 million and a balance sheet total exceeding EUR 10 million, in sectors listed in Annex 1 and Annex 2.
Note: Certain entities fall under the regulation regardless of these thresholds. These include qualified trust service providers, DNS services, and TLD registries.
Which Sectors Are Regulated?
The BSIG covers a total of 14 sectors, divided into two annexes with different requirement levels.
Annex 1 — Sectors of high criticality:
- Energy: Electricity, gas, heating, oil, hydrogen
- Transport: Air, rail, water, road
- Finance: Credit institutions, financial market infrastructures
- Healthcare: Hospitals, laboratories, research institutions
- Water: Drinking water supply and wastewater disposal
- Digital infrastructure: Data center operators, cloud providers, internet exchange points
- Space: Operators of ground infrastructure
Annex 2 — Other critical sectors:
- Postal and courier services
- Waste management
- Chemicals: Production and trade of hazardous substances
- Food: Wholesale and production
- Manufacturing sector: Medical devices, machinery, vehicles, electronics
- Digital services: Online marketplaces, search engines, social networks
- Research: Research institutions
The BSI provides an online tool for checking whether you are affected. According to BSI estimates, around 29,500 entities in Germany are affected. Once you have confirmed that you are affected, the Pre-Check from NIS2Compass shows where compliance gaps exist in your organization. For a deeper look at sector classification, see the article Am I affected by NIS2?.
What Obligations Must Companies Fulfill Under NIS2?
The NIS2UmsuCG requires affected companies to meet three core obligations: registration with the BSI, reporting significant security incidents within 24 hours, and implementing 10 risk management measures under §30 BSIG. Executive management is personally liable for compliance.
What Does the Registration Obligation Involve?
The registration obligation arises from §33-34 BSIG. Affected companies must register on the BSI portal within three months of determining that they are subject to the regulation. Changes to the registered information must be reported within two weeks.
The following information is required for registration:
- ELSTER organizational certificate for secure identification
- Company details (name, address, legal form)
- NIS2 point of contact as the central contact person for the BSI
- Sector and industry in accordance with the annexes of the NIS2UmsuCG
- IP address ranges of the network infrastructure in use
How Does Incident Reporting Work?
§32 BSIG governs the reporting obligation for significant security incidents. An incident is considered significant if it causes serious operational disruptions or substantial financial losses (§2 No. 11 BSIG). The law prescribes a three-stage reporting process:
- 24 hours: Early initial notification after becoming aware of the incident, with a preliminary assessment
- 72 hours: Follow-up report with details on the cause, scope, and measures taken
- 30 days: Final report with a complete description and evaluation of the incident
What Are the 10 Risk Management Measures Required by §30 BSIG?
§30 BSIG defines ten mandatory areas of measures that all affected companies must implement. Executive management bears personal responsibility under §38 BSIG. This liability is non-waivable and cannot be delegated to subordinate positions.
The ten areas of measures at a glance:
- Risk analysis and IT security policies
- Incident response — handling security incidents
- Business continuity management — including backup and disaster recovery
- Supply chain security — security for service providers and suppliers
- Security in system development, procurement, and maintenance
- Effectiveness assessments of implemented measures
- Training and awareness — cyber hygiene for employees
- Cryptography and encryption
- Personnel security, access control, and asset management
- Multi-factor authentication and secured communications
Executive managers are also required to attend cybersecurity training on a regular basis. For documenting these measures, the Template Library from NIS2Compass provides ready-made templates. Detailed explanations of each requirement are available in the Knowledge Hub.
What Penalties Apply for NIS2 Violations?
Violations of the NIS2UmsuCG can result in fines of up to EUR 10 million or 2% of global annual revenue. For important entities, the ceiling is EUR 7 million or 1.4%. Even a late registration with the BSI can cost up to EUR 500,000.
How High Are the Fines Under §65 BSIG?
§65 BSIG provides a tiered penalty framework based on entity type and severity of the violation:
- Up to EUR 10 million: Essential entities for violations of core obligations, or 2% of global annual revenue if it exceeds EUR 500 million
- Up to EUR 7 million: Important entities for violations of core obligations, or 1.4% of annual revenue for companies of corresponding size
- Up to EUR 500,000: Violations of the registration obligation or incident reporting requirements
- Up to EUR 100,000: Formal violations, such as missing or incomplete documentation
The amount of the fine is always based on the actual damage, the severity of the violation, and the degree of fault. Companies with high annual revenue risk the percentage-based amount, which can significantly exceed the absolute ceiling.
Why Is Executive Liability So Critical?
§38 BSIG explicitly requires executive management to approve, initiate, and oversee risk management measures. This has far-reaching consequences:
- Personal liability with private assets, not just the company
- This liability cannot be contractually excluded; waiver and settlement agreements are void
- Training obligation at least every three years to maintain the required expertise
- Applies to board members of stock corporations (AG), managing directors of limited liability companies (GmbH), and expressly also to de facto managing directors
According to an analysis by Security Insider, only 38.5% of affected companies had registered with the BSI by the registration deadline of March 6, 2026. Over 18,000 entities are therefore overdue and risk administrative proceedings.
For a detailed breakdown of the fines for specific violations and how authorities calculate them, see the NIS2Compass article NIS2 Fines: What Penalties Can You Expect?.
What Deadlines Apply in 2026 and Beyond?
The most important deadlines have already passed: the NIS2UmsuCG has been in force since December 6, 2025, and the BSI registration deadline expired on March 6, 2026. Companies that have not yet registered risk fines of up to EUR 500,000. The next relevant deadline concerns KRITIS compliance evidence, due no earlier than 2027.
A chronological overview shows how the implementation has unfolded:
- January 16, 2023: EU NIS2 Directive (EU 2022/2555) enters into force
- October 17, 2024: EU transposition deadline expired. Germany was over a year late
- November 13, 2025: Bundestag passes the NIS2UmsuCG
- December 5, 2025: Publication in the Bundesgesetzblatt (BGBl. I No. 301)
- December 6, 2025: Entry into force: all obligations apply immediately, no transition periods
- January 6, 2026: BSI portal for registration and incident reporting goes live
- March 6, 2026: BSI registration deadline expired. Fines possible
- From 2027 (earliest): First KRITIS compliance evidence requirements (3 years after entry into force)
- Recurring: Executive management training at least every 3 years
Over 18,000 companies missed the registration deadline on March 6, 2026. This represents a significant risk of fines, as the BSI can already sanction violations of the registration obligation. If you have missed the deadline, you should complete registration immediately. The sooner this happens, the lower the risk of regulatory action.
How Can Companies Start Their NIS2 Implementation?
The fastest way to get started involves three steps: check whether you are affected, complete your BSI registration, and conduct a gap analysis. NIS2Compass supports this process with the Pre-Check as a gap analysis and an 8-chapter guide for the structured implementation of all 10 areas of measures.
What Steps Lead to Compliance Most Quickly?
Getting started with NIS2 implementation follows a clear path, regardless of how far along your company already is.
- Check whether you are affected: Compare your sector and employee count against the NIS2UmsuCG thresholds. The BSI's online tool for checking applicability helps with classification.
- Complete BSI registration: Register on the BSI portal (ELSTER certificate required). The registration deadline expired on March 6, 2026. If you have not yet registered, do so without delay.
- Conduct a gap analysis: Systematically assess your current IT security posture and identify gaps against the requirements of §30 BSIG. The Pre-Check from NIS2Compass completes this in under 5 minutes.
- Create an action plan: Set priorities across the 10 areas of measures, ordered by implementation effort and risk.
- Build your documentation: Develop policies, processes, and evidence. Ready-made templates significantly reduce this effort.
What Does This Look Like in Practice?
A mid-sized manufacturing company in North Rhine-Westphalia with 180 employees and an IT team of five faced exactly this situation. The Pre-Check from NIS2Compass quickly revealed where the biggest gaps were: the company qualifies as an "important entity" in the manufacturing sector under the NIS2UmsuCG.
Their existing ISO 27001 certification already covered around 60% of the requirements. The NIS2 Guide helped identify the remaining gaps, particularly in incident reporting processes and supply chain security. Using the templates from the Template Library, the missing documentation was completed within four weeks.
This example shows: companies that already have structured security processes in place are often closer to compliance than they think. The real work lies in identifying and closing the remaining gaps.
According to the BSI Situation Report 2025, 80% of all ransomware attacks target SMEs. A structured NIS2 implementation is therefore not just a regulatory obligation but the most effective protection against the most common attack vectors. For more on how NIS2 interacts with existing security frameworks, see the article NIS2 and ISMS: What Your Existing System Doesn't Cover.
Frequently Asked Questions About NIS2 in Germany
What is the difference between the EU NIS2 Directive and the NIS2UmsuCG?
The EU NIS2 Directive (EU 2022/2555) is the European legal framework for cybersecurity. The NIS2UmsuCG is the German transposition, which amends the BSI Act. For German companies, only the NIS2UmsuCG is authoritative. It has been in force since December 6, 2025, with no transition periods.
How do I find out if my company is affected by NIS2?
Check two criteria: Does your company operate in one of the 18 regulated sectors? And do you meet the thresholds (50 or more employees or EUR 10 million in annual revenue)? The BSI provides an online tool for checking applicability. Once you know you are affected, the Pre-Check from NIS2Compass serves as a gap analysis to show where your biggest compliance gaps are.
What happens if I missed the BSI registration deadline?
The deadline was March 6, 2026. Companies that have not registered risk administrative proceedings and fines of up to EUR 500,000. Register immediately via the BSI portal. A late registration is better than none.
Is executive management personally liable for NIS2 violations?
Yes. Under §38 BSIG, executive management is required to approve risk management measures and oversee their implementation. In the event of a breach of duty, personal liability with private assets applies. This liability cannot be contractually excluded, and even a subsequent waiver is void.
Can I implement NIS2 without an external consultant?
Yes, with the right structure. The NIS2 Guide from NIS2Compass walks you through the entire implementation process in 8 chapters and approximately 124 steps. Ready-made templates from the Template Library further reduce the effort. External consulting can be useful for complex edge cases but is not strictly required.
Implement NIS2 step by step
NIS2Compass guides you step by step through implementation – with guide, templates and knowledge hub.
Get startedÄhnliche Artikel
When Is a Security Incident Reportable? (§ 32 BSIG)
A significant security incident under § 2 no. 11 BSIG: when you have to report to the BSI, and why the 500,000 euro threshold binds only eleven types of digital service provider.
9 Min. Lesezeit
Management Self-Check under Section 38 BSIG: The Free Excel Template
Free Management Self-Check under Section 38 BSIG as an Excel template: 20 yes/no questions, 5 sections, traffic-light status, no email gate.
6 Min. Lesezeit
NIS2 Guide: How 8 Chapters Lead to Compliance
The NIS2Compass NIS2 Guide walks you through 8 chapters, from registration to training, toward NIS2 compliance. What each chapter covers and how templates help.
10 Min. Lesezeit