When Is a Security Incident Reportable? (§ 32 BSIG)

A significant security incident under § 2 no. 11 BSIG: when you have to report to the BSI, and why the 500,000 euro threshold binds only eleven types of digital service provider.
Written by the NIS2Compass editorial team | Last updated: August 2026
Under § 2 no. 11 BSIG, a significant security incident is one that causes or could cause serious operational disruption. The much-quoted 500,000 euro threshold comes from Implementing Regulation (EU) 2024/2690 and binds only eleven types of digital infrastructure and digital service provider. Whether it applies to you is answered by the NIS2Compass Pre-Check.
What Counts as a Significant Security Incident Under the BSIG?
§ 2 no. 11 BSIG defines the term through two alternatives; the reporting obligation sits in § 32 BSIG. Alternative a) covers serious operational disruption or financial loss for the entity, alternative b) substantial material or non-material damage to third parties. Both trigger on the mere capability of causing harm.
This division of labour is frequently confused: § 32 BSIG creates the duty, § 2 no. 11 BSIG supplies the term it attaches to. To see whether an incident is reportable, look up § 2, not § 32.
The wording reads as follows (translated from the German original):
"a security incident that a) has caused or is capable of causing serious operational disruption of the services or financial loss for the entity concerned, or b) has affected or is capable of affecting other natural or legal persons by causing substantial material or non-material damage, unless a more specific definition is laid down by the statutory instrument pursuant to § 56 (5)"
No such statutory instrument has been issued to date.
Three features of this wording decide cases in practice:
- "or is capable of causing": The capability to cause harm is enough. An incident can be reportable before any damage occurs. The most overlooked clause in the provision.
- "or": The two alternatives stand side by side. Either one alone is enough.
- No figure in the statute: § 2 no. 11 BSIG names no euro amount, no downtime, no number of users. Anyone looking for a figure ends up at the Implementing Regulation, which may not apply to their company.
Upstream sits the basic term: § 2 no. 40 BSIG separately defines "security incident" as an event compromising the availability, integrity or confidentiality of data or services. Every significant security incident is first a security incident. The NIS2Compass Implementation Guide follows the same two steps: incident first, significance second.
The obligation has applied since the NIS2UmsuCG took effect on 6 December 2025. As of 2 April 2026, the BSI had recorded 541 NIS-2 reports via its portal, including 248 it classifies as initial notifications, across 15,477 registered companies (BSI, NIS-2 in Zahlen). Which report goes to whom and when is covered in the NIS2 reporting obligations overview.
Who Does the 500,000 Euro Threshold From the EU Implementing Regulation Apply To?
The BSIG knows no single significance threshold in euros. Implementing Regulation (EU) 2024/2690 has applied since 7 November 2024 and binds exclusively eleven types of digital infrastructure and digital service provider. For all other sectors, § 2 no. 11 BSIG remains the yardstick, and the Regulation's criteria are an indicator pointing upwards there, not a floor.
NIS2 is an EU Directive, transposed by the NIS2UmsuCG. Implementing Regulation (EU) 2024/2690 is, by contrast, a regulation and applies directly. Under its Article 1 it specifies the technical risk management requirements and the cases of a significant security incident, but only for the entities named there.
Which Entities Does the Implementing Regulation Bind?
The numerical thresholds of Implementing Regulation (EU) 2024/2690 bind, under Article 1, exclusively the following entities:
- DNS service providers
- TLD name registries
- Cloud computing service providers
- Data centre service providers
- Content delivery network providers
- Managed service providers
- Managed security service providers
- Providers of online marketplaces
- Online search engines
- Social networking services platforms
- Trust service providers
Not covered by the Regulation's thresholds are, among others:
- Manufacturing and mechanical engineering
- Food production and food trade
- Healthcare
- Transport and logistics
- Energy and water supply
- Telecommunications providers: not included in the catalogue of Article 1, see BSI on IT and telecoms. Often assigned incorrectly.
For the second group, § 2 no. 11 BSIG applies alone, for all essential entities (besonders wichtige Einrichtungen) and important entities (wichtige Einrichtungen) regardless of sector. Whether your company falls under NIS2 at all is covered in Am I affected by NIS2?.
What Figures Does Article 3(1) of the Regulation Name?
For these eleven entity types, a security incident is significant under Article 3(1) in cases including:
- Direct financial loss above 500,000 euros or 5 % of the previous year's total annual turnover, incurred or possible. The lower value counts.
- Exfiltration of trade secrets.
- Death or serious harm to the health of a natural person.
- Successful, presumably malicious and unauthorised access to network and information systems that is capable of causing serious operational disruption.
On top of that come recurring incidents under Article 4 and the sector-specific criteria of Articles 5 to 14, which set downtimes and user shares by service type. Article 3(2) expressly excludes planned interruptions and the effects of maintenance.
What Follows From This for All Other Sectors?
On the NIS-2 reporting obligation, the BSI writes (our translation):
"For entities in other sectors, it can be assumed that a significant security incident is present if at least one of the criteria of Commission Implementing Regulation (EU) 2024/2690, Article 3(1), is met."
So for other sectors these criteria are sufficient: meet one and you may assume significance. Necessary they are not. Meeting none does not automatically release you from the reporting obligation.
A loss of 80,000 euros can be a significant security incident for a company with 40 million euros in turnover, even though it is far below 500,000 euros. The widespread reading "only report from 500,000 euros upwards" is the expensive mistake.
The BSI adds in the same place (our translation): "Furthermore, a significant security incident is always to be assumed where the provision of critical services has failed or been impaired."
How Do You Decide in a Concrete Case Whether an Incident Is Significant?
The significance assessment runs in five steps, answered in this order. It starts with whether there is a security incident at all under § 2 no. 40 BSIG, and ends with documenting the result. If genuine uncertainty remains after step four, the BSI principle applies: speed before completeness.
1. Is there a security incident at all? Does the event compromise the availability, integrity or confidentiality of data or services? No means the assessment ends here, internal documentation is enough. Yes means: on to step 2.
2. Does your entity fall within the scope of Implementing Regulation 2024/2690? Compare against the eleven entity types listed above. Yes means the criteria of Articles 3 to 14 are the binding yardstick and the assessment largely becomes arithmetic. No means the yardstick is § 2 no. 11 BSIG, so on to step 3.
3. Does the incident meet one of the criteria in Article 3(1)? If so, you may assume significance on the BSI's reading, and the assessment ends with a yes. If not: keep going, do not stop.
4. Test the two alternatives of § 2 no. 11 BSIG separately. That produces three questions:
- Alternative a), the internal view: serious operational disruption of your own services or financial loss, incurred or possible. Is a production or service line down, and for how long? If a critical service is affected, the BSI reading quoted above applies.
- Alternative b), the external view: substantial material or non-material damage to third parties, incurred or possible. Has customer, patient or employee data been exfiltrated, or could third parties be affected in the services they receive?
- The yardstick is your own size, not an absolute euro amount. Would this loss be serious for a company of your size?
5. Record the result and give reasons. Note yes or no, with date, time, decision-maker and the reasoning that carried the decision.
An incident should "be reported as early as possible […], irrespective of the information available", the BSI writes (our translation). An uncertain assessment is therefore no reason to postpone the report; corrections run through follow-up notifications.
The NIS2Compass Implementation Guide carries this determination as its own step in Chapter 4 (Incident management and reporting obligations), backed by the matching templates.
Three Typical Incidents: What Is Significant and What Is Not?
For a company with no digital-services connection, significance turns solely on § 2 no. 11 BSIG's wording. Ransomware on a production system is practically always reportable, a blocked phishing attempt practically never. In between lie the cases that call for a reasoned individual assessment.
All three cases take place at a food producer with around 210 employees.
Is Ransomware on the Production Control System a Significant Security Incident?
The production control system is encrypted, two filling lines stand still for 36 hours and only restart after restoring from backup.
Yes. § 2 no. 11 letter a) BSIG requires serious operational disruption of the services provided, and that is exactly what happened. The BSI reading on critical services cited above supports the result, and Article 3(1)(e) of the Regulation would be met too. The incident is significant under both yardsticks, whatever the size of the loss.
Do I Have to Report a Phishing Attack With No Data Exfiltration?
An employee enters their credentials on a fake login page. The account is locked within minutes; no access to systems or data takes place.
No. § 2 no. 11 BSIG requires serious operational disruption, financial loss or substantial damage to third parties, in each case incurred or possible. None of those is present. If the facts change — a successful login, mailbox access — the assessment flips. The case belongs in your internal incident register anyway.
Is an Attack Reportable if It Was Stopped After the Attacker Was Already Inside the Network?
Through an unpatched VPN component, an attacker reaches the internal network. Monitoring detects the session and cuts it before they move laterally. Such entry points are multiplying: between July 2024 and June 2025, newly discovered vulnerabilities per day rose 24 percent, according to the BSI situation report 2025.
A pure near miss with no impairment is not a security incident under § 2 no. 40 BSIG, and therefore not a significant one. But this is not that case: the unauthorised access succeeded. That brings the clause "is capable of causing" in § 2 no. 11 BSIG into play — damage already sustained is not required. The incident is more likely reportable than not.
The three cases are constructed examples. No published fine notices or court decisions on NIS2 reporting violations exist to date.
Who Makes the Assessment, and What Do You Have to Be Able to Show?
The significance assessment is the entity's own. Neither the BSIG nor the Implementing Regulation names a responsible role or a fixed procedure. It becomes subject to proof indirectly, via § 30 (1) sentence 3 BSIG, under which entities must document compliance with the risk management obligations.
Does the BSI Review Whether an Incident Was Significant?
No. The entity assesses; the BSI only receives the result, in the form of the report. The decision cuts both ways: a report you did not file needs just as much justification as one you did.
Where Does the Duty to Document the Assessment Come From?
The BSIG contains no express duty to document the significance assessment as such. Neither § 32 nor § 2 knows one.
It can be derived, though. § 30 (1) sentence 3 BSIG provides (our translation): "Compliance with the obligation under sentence 1 shall be documented by the entities." § 30 (2) BSIG lists ten areas of mandatory risk management measures; incident handling is number 2. If you have to document how incidents are handled, you also have to document why an incident was not reported.
What Belongs in the Assessment Documentation?
It becomes robust once it records the point of becoming aware, the facts, the alternatives of § 2 no. 11 BSIG tested and their result, the decision-maker and sign-off, and the outcome with a timestamp.
The point of becoming aware is frequently set too late. The BSI puts it early: what is meant is (our translation) "the point in time at which an employee of the entity (during working hours) becomes aware of a significant security incident". It is not the report to the information security officer that starts the clock, but awareness anywhere in the business. The edge cases remain open: awareness outside working hours, and attribution where a service provider knows first. Anyone who settles the internal escalation paths in advance and documents them is better placed, in case of doubt, than anyone waiting for clarification.
What Does Breaching the Reporting Obligation Cost?
A breach of the reporting obligation under § 32 (1) sentence 1 BSIG is penalised under § 65 BSIG with up to 10 million euros for essential entities and up to 7 million euros for important entities. The widely cited "up to 10 million euros or 2 percent" is not a blanket NIS2 figure: the 2 percent only bites above a total turnover of 500 million euros. The remaining fine brackets are covered in the article on NIS2 fines, the management's personal responsibility in the one on management liability under § 38 BSIG.
Frequently Asked Questions
What is the significance threshold under NIS2?
The BSIG knows no fixed significance threshold in euros. The yardstick is § 2 no. 11 BSIG: serious operational disruption or financial loss for your entity, or substantial damage to third parties, in each case incurred or possible. Concrete figures appear only in Implementing Regulation (EU) 2024/2690, which binds exclusively providers of digital infrastructure and digital services.
Does the 500,000 euro threshold apply to my company?
Only if your company is one of the eleven types of provider of digital infrastructure and digital services listed in Article 1 of Implementing Regulation 2024/2690. For all other sectors, § 2 no. 11 BSIG applies with no numerical threshold. A loss below 500,000 euros therefore does not rule out the reporting obligation.
Does the same significance threshold apply to important and essential entities?
Yes. § 2 no. 11 BSIG draws no distinction between important and essential entities. The definition applies to both alike and significance is tested identically. What differs is not the significance of an incident, but the supervision regime and the fine brackets.
Who decides on significance within my company?
The BSIG names no role. The decision rests with the entity, in practice usually the information security officer, with sign-off by the management. What matters is that responsibility is settled in advance and every assessment documented traceably. Without settled responsibility, the question of who decides comes up precisely when the clock is already running.
Does the assessment change if the incident happened at a service provider?
No. What counts is whether your services are seriously disrupted, not who caused the incident. § 2 no. 11 letter a) BSIG turns on disruption of the services of the entity concerned. Your reporting obligation exists whether or not the service provider is itself subject to one or files a report.
Which report follows within which deadline is covered in the overview of the NIS2 reporting obligations.
Implement NIS2 step by step
NIS2Compass guides you step by step through implementation – with guide, templates and knowledge hub.
Get startedÄhnliche Artikel
Management Self-Check under Section 38 BSIG: The Free Excel Template
Free Management Self-Check under Section 38 BSIG as an Excel template: 20 yes/no questions, 5 sections, traffic-light status, no email gate.
6 Min. Lesezeit
NIS2 Guide: How 8 Chapters Lead to Compliance
The NIS2Compass NIS2 Guide walks you through 8 chapters, from registration to training, toward NIS2 compliance. What each chapter covers and how templates help.
10 Min. Lesezeit
The Best ISMS Tool to Kick Off Strong After the 2026 Summer Lull
A comparison of the six leading ISMS tools for 2026: KaitoSec, Kertos, Vanta, Grasp, Athereon, and HiScout, with guidance on which tool fits which company profile.
11 Min. Lesezeit