What Is the NIS2UmsuCG? Germany's NIS2 Law Explained

The NIS2UmsuCG has been in force since December 2025 and obligates more than 29,000 companies. What Germany's law regulates, who it affects, and how it differs from the EU Directive.
The NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) is Germany's transposition of the EU NIS2 Directive and has been in force since December 6, 2025. It obligates more than 29,000 companies to register, implement risk management measures, and comply with reporting duties. NIS2Compass organizes these obligations into a structured implementation path, and the Pre-Check shows within minutes whether your company is affected.
What Is the NIS2UmsuCG and When Did It Take Effect?
The NIS2UmsuCG is the German law that transposes the EU NIS2 Directive (EU 2022/2555) into national law. The Bundestag passed it on November 13, 2025. Promulgated on December 5, 2025 in the Federal Law Gazette (BGBl. I Nr. 301), it has been in force since December 6, 2025, with no transition periods.
The EU Directive's actual transposition deadline had already expired on October 17, 2024. Germany passed the NIS2UmsuCG a good 13 months later, after several drafts were revised during the legislative process at the Federal Ministry of the Interior. However, this delay only affected national lawmaking: only with the NIS2UmsuCG do directly binding, legally enforceable obligations arise for German companies. As EU law, the NIS2 Directive itself initially binds only the German legislature, not individual companies directly.
In terms of content, the NIS2UmsuCG primarily amends the BSI Act (BSIG). It introduces the categories of entities of particular importance and important entities, each with its own set of obligations. It also significantly broadens the scope of affected sectors compared to the previous KRITIS regime, ranging from energy and healthcare to waste management and digital infrastructure. Companies that previously fell outside the KRITIS regime may now fall within scope for the first time as a result of this expansion.
No transition periods means: all obligations under the NIS2UmsuCG have applied immediately since December 6, 2025, with no phase-in by company size or sector. Companies within scope must implement risk management measures, reporting processes, and BSI registration from this date, regardless of how far their own preparations have progressed. NIS2Compass maps this timeline directly in the Guide and assigns each obligation to the matching implementation step.
A complete overview of deadlines, scope, and obligations is available in the foundational article NIS2 in Germany: What Companies Need to Know in 2026. It places the individual obligations from the NIS2UmsuCG chronologically along the timeline described here.
Which Laws Does the NIS2UmsuCG Amend?
The NIS2UmsuCG primarily amends the BSI Act (BSIG), which contains the core obligations for companies. It also adjusts the Telecommunications Act (§165 TKG) and the Energy Industry Act (new §5c EnWG). Further cross-reference changes affect, among others, the BND Act and the TTDSG.
The central change comes via Article 1 of the transposition act: the newly drafted BSIG 2025. It is structured into nine parts with 66 sections plus two annexes. Part 2 (§§3-27) governs the tasks and powers of the Federal Office. Part 3 (§§28-48) contains the IT security obligations of affected entities, the practical core of the law. Part 7 (§§59-64) describes supervision, and Part 8 (§65) the fine provisions.
In the Telecommunications Act, the revised §165 TKG obligates telecommunications service providers to implement additional technical and organizational security measures. In the Energy Industry Act, the new §5c EnWG requires energy operators to comply with sector-specific IT security catalogs.
There are also minor cross-reference changes that have no practical relevance for most companies:
- BND Act: Adjustment of responsibilities related to the federal government's cybersecurity architecture.
- TTDSG: Editorial cross-reference adjustments to the new BSIG structure.
For day-to-day implementation work, the BSIG is therefore almost the only relevant law. The remaining legal changes affect specific sectors such as telecommunications and energy, or regulatory responsibilities, not the general obligations under §30 BSIG.
Who Does the NIS2UmsuCG Apply To?
The NIS2UmsuCG distinguishes between two new categories: entities of particular importance (around 8,250 companies) and important entities (around 21,600 companies), in addition to existing KRITIS operators. In total, more than 29,000 companies in Germany are affected. What matters is the sector, company size, and in some cases the activity regardless of size.
Entities of particular importance: This covers companies with at least 250 employees or more than EUR 50 million in annual revenue plus more than EUR 43 million in balance sheet total in the highly critical sectors listed in Annex 1 to §28 BSIG. Regardless of size, qualified trust service providers, TLD name registries, DNS service providers, and medium-sized and larger telecommunications providers also fall into this category. All KRITIS operators are automatically included in this category as well, though they legally form their own separate group.
Important entities: Here the threshold is 50 or more employees or more than EUR 10 million in revenue plus more than EUR 10 million in balance sheet total, based on Annex 1 and Annex 2. Trust service providers and telecommunications providers are subject to the obligation regardless of their size.
The sector annexes determine whether a company falls within scope at all. Annex 1 lists highly critical sectors such as energy, transport, finance, healthcare, water, digital infrastructure, and space. Annex 2 covers other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing, digital services, research, and, newly added, social security. The complete sector list is provided by the BSI on NIS2-regulated companies.
Whether your own organization is actually affected cannot be answered categorically in detail. The article Am I Affected by NIS2? How to Check walks you step by step through the self-assessment. The NIS2Compass Pre-Check assigns your company to the right category within minutes.
What Obligations Does the NIS2UmsuCG Specifically Impose?
The NIS2UmsuCG obligates affected companies to take four core actions: register with the BSI, implement risk management measures across ten areas, comply with staged reporting duties for security incidents, and fulfill the management board's personal oversight obligations. Each of these obligations is anchored in the law under its own section. Once you understand these four blocks, you can structure implementation step by step.
- Registration (§§33-34 BSIG): Companies must register with the BSI within three months of identifying themselves as an affected entity. For companies already in existence when the law took effect on December 6, 2025, a separate registration deadline expired on March 6, 2026. Both deadlines apply independently of each other. NIS2 BSI Registration: Missed the Deadline — Now What?
- Risk management measures (§30 BSIG): The law prescribes ten minimum areas, including risk analysis and ISMS, incident management, business continuity, supply chain security, vulnerability management, multi-factor authentication, training, and cryptography. In-depth explanations of the individual §30 measures are available in the NIS2Compass Knowledge Hub.
- Reporting duties (§32 BSIG): For significant security incidents, an initial notification is required within 24 hours, a follow-up notification within 72 hours, and a final report within one month. The BSI is the central reporting authority. NIS2 Reporting Duties: When, What, and Whom to Notify
- Management (§38 BSIG): Management bears a personal oversight obligation and is liable for breaches of duty. The training obligation is explicitly non-delegable. §38 BSIG: Personal Liability of Management
A mid-sized mechanical engineering company with 140 employees is classified as an important entity under the NIS2UmsuCG for the first time. IT leadership had previously had little contact with regulatory compliance and suddenly faces all four obligation blocks at once. Using a structured guide like NIS2Compass, the company works through registration, risk management measures, reporting processes, and management training systematically within a few months, instead of tackling each area in isolation and without prioritization.
"The four obligation blocks may look abstract at first glance, but in practice they can be worked through cleanly, one after another," says the NIS2Compass Compliance Team. "The key is to start with the risk analysis: it provides the foundation for all further measures, from reporting processes to management training."
How Does the NIS2UmsuCG Differ From the EU NIS2 Directive?
The EU NIS2 Directive (2022/2555) sets the framework, and the NIS2UmsuCG makes it concrete for Germany. The German law lists sectors and thresholds in its own annexes, additionally regulates the federal administration, and contains a national security exemption that the EU Directive does not have. In practice, what matters for companies is the national law, not the Directive itself.
The most important differences at a glance:
- Sector definition: The EU Directive describes affected sectors in fairly generic terms. The NIS2UmsuCG spells them out in its own annexes to the BSIG (Annex 1 and Annex 2), including concrete thresholds by company size.
- §37 BSIG, national security exemption: The German legislature creates an exemption for areas of national security and defense. The EU Directive does not provide for a comparable clause.
- §41 BSIG, prohibition right for critical components: The Federal Ministry of the Interior receives its own independent right to prohibit the use of certain critical components. This, too, is a purely national addition.
- §29 and §§43-48 BSIG, federal administration: The NIS2UmsuCG additionally regulates the cybersecurity of the federal administration, including a dedicated federal CISO. This regulatory layer does not exist in the EU Directive.
- Review: Germany does not introduce its own additional review obligation, but instead refers to the periodic review carried out under the EU Directive itself.
This means the German law contains at least five independent regulatory areas that go beyond a mere transposition of the EU Directive, ranging from the defense exemption and the component ban to the federal administration.
A legal principle is decisive for business practice: directives bind only EU member states, not companies directly. Only the national transposition law, i.e., the NIS2UmsuCG, has direct effect for affected organizations in Germany. NIS2Compass therefore consistently follows the wording of the BSIG, not the EU Directive as such.
What Happens in Case of Violations of the NIS2UmsuCG?
Violations of the NIS2UmsuCG by entities of particular importance can be penalized with fines of up to EUR 10 million or 2 percent of worldwide annual revenue, whichever is higher. Important entities risk fines of up to EUR 7 million or 1.4 percent of revenue. Even registration violations alone can be penalized with fines of up to EUR 500,000.
The amount of the fine depends on the entity category and the type of violation:
- Entities of particular importance: up to EUR 10 million or 2% of worldwide annual revenue for companies with more than EUR 500 million in revenue, whichever is higher. This covers, among other things, unimplemented §30 measures, breached reporting duties, or omitted customer notifications.
- Important entities: up to EUR 7 million or 1.4% of worldwide annual revenue, analogous to the violations applicable to entities of particular importance.
- KRITIS operators: EUR 1 to 2 million for missing or incomplete evidence.
- Registration violations and other regulatory offenses: EUR 100,000 to 500,000, for example for refusing to provide information or disregarding BSI orders.
The exact legal basis can be found in §65 BSIG. A detailed breakdown of all fine provisions, responsibilities, and example calculations is available in the in-depth article NIS2 Fines: What Penalties Threaten for Violations?.
The NIS2Compass Guide walks you step by step through implementing the §30 measures, reducing the risk of a fine proceeding.
Frequently Asked Questions
Is the NIS2UmsuCG the Same as the NIS2 Directive?
No. The NIS2 Directive is EU law and initially binds only the member states. The NIS2UmsuCG is the German law that transposes this Directive into national law and directly obligates companies. It has been in force since December 2025.
Who Does the NIS2UmsuCG Apply To?
The NIS2UmsuCG applies to "entities of particular importance" and "important entities" in the legally listed sectors, more than 29,000 companies in Germany in total. The NIS2Compass Pre-Check checks your own applicability within minutes.
Do I Have to Register Under the NIS2UmsuCG?
Yes, affected companies must register with the BSI within three months of identification. For companies that already existed when the law took effect, this deadline expired on March 6, 2026; for companies newly falling within scope later, the general three-month rule continues to apply.
What Happens If My Company Does Not Comply With the NIS2UmsuCG?
For entities of particular importance, fines of up to EUR 10 million or 2 percent of worldwide annual revenue threaten. In addition, the BSI can issue orders and, in serious cases, hold management personally accountable.
Is There a Transition Period Under the NIS2UmsuCG?
No, the law has applied since December 6, 2025, with no transition periods for the core obligations. Only for registration and certain KRITIS evidence requirements are separate, staggered deadlines provided.
Implement NIS2 step by step
NIS2Compass guides you step by step through implementation – with guide, templates and knowledge hub.
Get startedÄhnliche Artikel
The KRITIS Umbrella Act and NIS2: What Applies to Whom?
Since July 2026, around 2,000 KRITIS operators must register in addition to NIS2. Who needs to comply with NIS2, the KRITIS Umbrella Act, or both — sectors, deadlines, and fines explained.
7 Min. Lesezeit
NIS2 ISO 27001 Mapping: Excel Checklist Download
ISO 27001 covers approximately 70% of NIS2 requirements. The mapping Excel shows at a glance what is already covered — and where the regulatory gap remains.
6 Min. Lesezeit
NIS2 BSI Registration: Missed the Deadline — What Now?
The statutory NIS2 registration deadline has expired, but the BSI is granting an extended deadline until 31 July 2026. How to complete your registration in the BSI portal step by step.
9 Min. Lesezeit