NIS2 and the new German BSI Act
Nobody checks the scope for you. Entities caught by the new BSI Act had to register themselves and put the measures in place without a transition period.
The German act implementing NIS2 and strengthening cybersecurity entered into force on 6 December 2025 and rebuilt the BSI Act from the ground up. The circle of entities under obligation grew several times over.
- entities under BSI supervision, up from around 4500
- 29500
- hours to the first report of a significant incident
- 24
- million euro at the upper end of the fine range, or 2 per cent of turnover
- 10
The duties in the order they arise
Step 1: Establish scope
Check sector, size and special rules, take affiliated undertakings into account and record the result in writing. A negative result also needs reasons.
Step 2: Register
Entities in scope register with the BSI and keep their details current. The duty applies regardless of how far the technical implementation has come.
Step 3: Set up risk management
Technical and organisational measures reflecting the state of the art, proportionate to the risk, including security in the supply chain.
Step 4: Build reporting paths
Significant incidents are reported in stages, starting with an initial report within 24 hours. The process has to be rehearsed before it is needed.
Step 5: Involve management
Approval of the measures, supervision of implementation, training. This needs documenting, or it cannot be evidenced later.
What gets overlooked
- The supply chain: requirements on service providers belong in the contracts, not only in an internal policy
- The evidence: measures without documentation are worthless towards the regulator
- The reporting threshold: what counts as significant must be defined beforehand, not during the incident
- The group view: subsidiaries are counted too small
- The overlap with data protection: an incident can be a personal data breach as well, with its own deadline
Where both apply, two reporting paths run in parallel. What matters when reporting a personal data breach is set out under data breach.
How we help
We assess scope properly, group structure included, and support the registration. For implementation we sort out which measures are legally owed and which go beyond that, and we carry the requirements into the contracts with service providers.
Unsure whether NIS2 applies?
We assess the scope and say what comes first.
Have the scope assessedFrequently asked questions
How do we establish whether we are in scope?
Through three questions. Does the activity fall into one of the listed sectors, are the thresholds for headcount or turnover met, and is there a special rule that applies regardless of size? It gets difficult in group structures, because figures of affiliated undertakings may be aggregated. A self-assessment that ignores the group structure regularly goes wrong.
We missed the registration. What now?
Catch up, and document it. The duty to register continues and does not lapse when the deadline passes. Registering late on your own initiative, with an explanation for the delay, is a different position from being found out. In parallel, check whether the security measures are actually in place, because registration is the visible duty, not the demanding one.
What falls on management personally?
Management must approve the risk management measures and supervise their implementation, and cannot shed that task by delegating it. A training duty comes on top. Responsibility is therefore no longer a matter for the IT department alone.