NIS2Compass — NIS2-Compliance-Plattform
Use CasesPricing
Go to platform

Weiterführende Seiten

  • Blog
  • FAQ
  • Glossar
  • Use Cases
  • Branchen
  • Preisgestaltung

Offizielle Quellen

  • BSI – Bundesamt für Sicherheit in der Informationstechnik
  • NIS2-Richtlinie (EUR-Lex)
  • NIS2UmsuCG (Bundesgesetzblatt)
NIS2Compass — NIS2-Compliance-Plattform

Ihr Navigator durch die NIS2-Compliance

Rechtliches

  • Datenschutzerklärung
  • Allgemeine Geschäftsbedingungen
  • Cookie-Richtlinie
  • Impressum

Ressourcen

  • Blog
  • Use Cases
  • Branchen
  • Preise
  • FAQ
  • Glossar

Kontakt

Kontakt

kontakt@nis2compass.de

NIS2Compass bietet Informationen und Orientierungshilfen zur NIS2-Compliance. Die Inhalte stellen keine Rechtsberatung im Sinne des Rechtsdienstleistungsgesetzes (RDG) dar und ersetzen keine individuelle rechtliche oder fachliche Beratung.

© Copyright 2026 NIS2Compass. Alle Rechte vorbehalten.

Entwickelt in DeutschlandAllianz für Cyber-Sicherheit — Teilnehmer
Home/Blog/What Happens After You Report to the BSI?
Guide

What Happens After You Report to the BSI?

Authored by NIS2Compass Redaktion, NIS2 Compliance Expert
Last updated:August 20, 20267 min read
What Happens After You Report to the BSI?

What happens after a BSI report: acknowledgment of receipt, possible audit, customer notification duty — and why you can't withdraw it.

Written by the NIS2Compass editorial team | Last updated: August 2026

After you submit a BSI report, you first receive an acknowledgment of receipt, typically within 24 hours, with optional guidance on remediation measures on request. Automatic publication or an audit is not triggered by the report itself — that depends on your organization's classification and on concrete indications. NIS2Compass guides you through the entire reporting process in the NIS2 Guide.

What does the BSI send back after receiving your report?

Under Section 36 (1) BSIG, the BSI confirms receipt of your report without delay, where possible within 24 hours. On request, it provides guidance or operational advice on remediation measures and can offer additional technical support. This does not trigger any automatic publication.

This response is explicitly not an automatic on-site reaction. The authority initially only confirms receipt and becomes active in an advisory capacity only once the reporting organization explicitly requests it. Without such a request, the BSI does not independently intervene on site. Operational handling of the incident remains with the affected organization; the BSI supports only on request.

A further legal basis is found in Section 32 (6) BSIG: the BSI may provide additional support in accordance with Section 36 (1) BSIG, but again only at the request of the reporting entity. Together, both provisions define the scope of what the BSI may do after a report is filed.

This process picks up exactly where the report itself ends. If you drafted your report using these sample texts, this is precisely the response process from the BSI that follows. If there was previously uncertainty about whether an incident was reportable at all, that question has already been resolved by this stage. NIS2Compass places this step within the overall reporting-obligation process in the NIS2 Guide.

Is a BSI report automatically made public?

No. Publication is only possible in two narrow cases: the BSI can, after a hearing, require an organization to inform the public if this is necessary to manage the incident or is in the public interest, or it can inform the public itself under the same conditions. The default is confidential handling.

This exception follows from Section 36 (2) BSIG and in every case requires a prior hearing of the affected organization. Without both of these conditions being met, a report stays internal.

This is distinct from the customer notification duty under Section 35 BSIG. Under that provision, organizations must, under certain conditions, inform their own customers about an incident. That involves a different group of addressees and a different legal basis than official publication under Section 36; more on that in the next section.

Within the administration, however, a report is passed on: under Section 32 (5) BSIG, the BSI forwards incoming reports without delay to the responsible federal supervisory authorities. This is internal administrative coordination, not publication.

At the European level, the BSI aggregates reporting data. Under Section 58 (4) BSIG, it submits a summary report to ENISA every quarter, on January 18, April 18, July 18, and October 18. This report contains exclusively anonymized and aggregated data on reported incidents — your company will not be identifiable by name in it.

A third rule applies to cross-border incidents. Section 40 (4) No. 3 BSIG obliges the BSI to forward information to the central points of contact of other affected EU member states and, where applicable, to ENISA, while safeguarding the economic interests of the organization and the confidentiality of the information provided. This protective formula is not equivalent to the anonymization required under Section 58 (4).

What information a report under Section 32 BSIG must actually contain is explained in the article When, What, and to Whom Do You Report?

When must you inform your customers about an incident?

The BSI can instruct you under Section 35 (1) BSIG to inform affected customers without delay about a significant security incident that could impair the provision of your service. For the financial sector, social security, digital infrastructure, ICT service management, and digital services sectors, a separate notification duty additionally applies for significant cyber threats.

Section 35 (1) BSIG does not create an automatic reporting duty toward customers — it grants the BSI the power to issue such an order. You only need to act once the authority actually issues such an order. The BSI also informs the responsible federal supervisory authority in parallel. Customers can be informed via a notice published on the organization's own website; individually notifying every single customer is not mandatory.

The situation is different under Section 35 (2) BSIG: for the five sectors named above, there is an independent duty that does not depend on a BSI order. Affected organizations must inform potentially affected service recipients and the BSI without delay about remediation measures and the cyber threat itself, provided a balancing of interests favors the recipients.

For a typical NIS2Compass customer outside these five sectors, an independent customer notification duty under paragraph 2 generally does not apply. A notification duty can, however, arise from a BSI order under paragraph 1, depending on the specific significant security incident and its impact on your services. There is no automatic duty triggered by every Section 32 report.

Does a report automatically trigger a BSI audit?

No, and this depends heavily on the type of organization. For important entities, the BSI may only conduct an audit under Section 62 BSIG if concrete facts justify the assumption that obligations are not being met, or not being met correctly. For entities of particular importance, Section 61 BSIG grants broader audit powers, including ones that do not require a specific trigger.

For important entities, oversight is therefore strictly trigger-based. The BSI can only review compliance with risk management measures under Section 30, reporting duties under Section 32, and management-body obligations under Section 38 if solid facts point to a breach of duty. A report filed properly and on time is the exact opposite of such an indication: it demonstrates that the reporting duty was fulfilled and is, by itself, no sign of misconduct.

For entities of particular importance, oversight reaches considerably further. The BSI can order audits, inspections, and certifications, and — starting three years after the law takes effect — generally demand evidence, selected based on risk exposure, size, and the severity of possible incidents. This general audit power is not tied to a specific trigger; it exists independently of any individual report.

Neither provision names the report itself as the trigger. The report as an event is something different from its content. What it discloses — for instance, recognizable systemic security shortcomings — can qualify as a fact under Section 62 BSIG and lead to an audit; the report itself never triggers one, only its content could, in exceptional cases.

Whether your company qualifies as an entity of particular importance or an important entity is clarified by the NIS2Compass Pre-Check.

Why can't you withdraw a report once it's been submitted?

Once a BSI report has been submitted, it cannot be withdrawn. The reporting procedure under Section 32 BSIG is designed as a chain of successive reporting stages under the same incident ID, not as a revocable single report. Corrections run exclusively through the next reporting stage: the 72-hour report or the final report.

The BSIG contains no explicit provision stating in so many words that "a report cannot be withdrawn." This follows from the structure of the procedure itself: Section 32 BSIG describes the 72-hour report explicitly as the step in which the information from the early initial notification is "confirmed or updated." The law thus provides for correction as a built-in procedural step, not as a withdrawal. There is no such thing as a new, independent report on the same incident, as also described in the sample texts for the reporting stages.

This explains why many companies hesitate to file a precautionary report. If you report out of caution and the incident later turns out less severe than first thought, the report doesn't disappear. It stays on record and gets corrected through the follow-up report — for example, when an IT service provider with 60 employees files an early initial notification after a phishing incident with no confirmed data exfiltration. The 72-hour report then clarifies that no data exfiltration occurred, and the final report closes the incident, with no damage having occurred.

This finality, not fear of the reporting process itself, is the real reason for hesitation before the early initial notification. Still, the honest answer is: when in doubt, report — for three reasons:

  • Incompleteness is permitted: an incomplete but timely early initial notification is explicitly allowed — the BSI works on the principle of speed over completeness.
  • Fines are for delay, not for correction: the fine-bearing breach of duty is a late or omitted report, not a later downward correction.
  • Over-reporting has no consequences: a precautionary report that turns out less serious than expected carries no automatic consequences — the follow-up report simply sets the record straight.

Because the decision is final, it's also a leadership matter. Under Section 38 BSIG, the management body must implement the risk management measures under Section 30 BSIG and oversee their implementation, so it already bears responsibility for the organization's information security. The "when in doubt, report" decision should therefore be made deliberately, not left solely to the IT department. NIS2Compass's NIS2 Guide walks you through exactly this decision — when and how to report.

Frequently asked questions

Do you get confirmation that your report reached the BSI?

Yes. The BSI confirms receipt of your report without delay, where possible within 24 hours. On request, you additionally receive guidance or operational advice on remediation measures and, where needed, technical support. These supplementary services are provided only on request from your organization, not automatically with every report.

Does the public find out about your report?

Generally, no. The BSI may only inform the public after a hearing of your organization, and only if this is necessary to manage the incident or is in the public interest. ENISA receives only anonymized, aggregated statistical data on a quarterly basis. Individual reports with identifiable company references are not passed on.

Do you have to expect a BSI audit after filing a report?

That depends on the type of your organization. For important entities, the BSI may only conduct an audit if concrete facts point to a breach of duty. A properly filed report alone is not sufficient grounds for one. Entities of particular importance are subject to broader audit powers that can apply even without a specific trigger.

Can you withdraw a BSI report you've already submitted?

No, withdrawal is not provided for in the procedure. The reporting procedure is designed for updates, not retraction: under Section 32 BSIG, the 72-hour report merely confirms or updates your initial notification. Corrections run through the next reporting stage, not through withdrawing the original report.

Do you have to inform your customers if you've reported an incident to the BSI?

Not automatically. The BSI can instruct you to inform affected customers if the incident could impair the provision of your service. An independent notification duty without a BSI order applies only to specific sectors: financial services, social security, digital infrastructure, ICT service management, and digital services, in the case of significant cyber threats.

Implement NIS2 step by step

NIS2Compass guides you step by step through implementation – with an Implementation Guide, templates and Knowledge Hub.

Get started

Ähnliche Artikel

guide

NIS2 Reporting Templates: §32 BSIG Notification Stages

The three §32 BSIG notification stages (early warning, initial notification, final report) with fully worded sample texts for ransomware, data exfiltration, and DDoS, ready to adapt.

12 Min. Lesezeit

guide

When Is a Security Incident Reportable? (§ 32 BSIG)

A significant security incident under § 2 no. 11 BSIG: when you have to report to the BSI, and why the 500,000 euro threshold binds only eleven types of digital service provider.

9 Min. Lesezeit

tips-tricks

Management Self-Check under Section 38 BSIG: The Free Excel Template

Free Management Self-Check under Section 38 BSIG as an Excel template: 20 yes/no questions, 5 sections, traffic-light status, no email gate.

6 Min. Lesezeit

Back to Blog