Skip to content
Call, 0511 – 47 55 58 11

NIS2 and the new German BSI Act

Nobody checks the scope for you. Entities caught by the new BSI Act had to register themselves and put the measures in place without a transition period.

The German act implementing NIS2 and strengthening cybersecurity entered into force on 6 December 2025 and rebuilt the BSI Act from the ground up. The circle of entities under obligation grew several times over.

entities under BSI supervision, up from around 4500
29500
hours to the first report of a significant incident
24
million euro at the upper end of the fine range, or 2 per cent of turnover
10

The duties in the order they arise

  1. Step 1: Establish scope

    Check sector, size and special rules, take affiliated undertakings into account and record the result in writing. A negative result also needs reasons.

  2. Step 2: Register

    Entities in scope register with the BSI and keep their details current. The duty applies regardless of how far the technical implementation has come.

  3. Step 3: Set up risk management

    Technical and organisational measures reflecting the state of the art, proportionate to the risk, including security in the supply chain.

  4. Step 4: Build reporting paths

    Significant incidents are reported in stages, starting with an initial report within 24 hours. The process has to be rehearsed before it is needed.

  5. Step 5: Involve management

    Approval of the measures, supervision of implementation, training. This needs documenting, or it cannot be evidenced later.

What gets overlooked

Where both apply, two reporting paths run in parallel. What matters when reporting a personal data breach is set out under data breach.

How we help

We assess scope properly, group structure included, and support the registration. For implementation we sort out which measures are legally owed and which go beyond that, and we carry the requirements into the contracts with service providers.

Unsure whether NIS2 applies?

We assess the scope and say what comes first.

Have the scope assessed

Frequently asked questions

How do we establish whether we are in scope?

Through three questions. Does the activity fall into one of the listed sectors, are the thresholds for headcount or turnover met, and is there a special rule that applies regardless of size? It gets difficult in group structures, because figures of affiliated undertakings may be aggregated. A self-assessment that ignores the group structure regularly goes wrong.

We missed the registration. What now?

Catch up, and document it. The duty to register continues and does not lapse when the deadline passes. Registering late on your own initiative, with an explanation for the delay, is a different position from being found out. In parallel, check whether the security measures are actually in place, because registration is the visible duty, not the demanding one.

What falls on management personally?

Management must approve the risk management measures and supervise their implementation, and cannot shed that task by delegating it. A training duty comes on top. Responsibility is therefore no longer a matter for the IT department alone.

Related