NIS2 in Germany: am I affected – and what do I need to do now?
The German NIS2 implementation act has applied since December 2025. Who is affected, what registration with the BSI means and which obligations follow.
By Frank Maier · Last checked: 4 October 2026 ·2 min read
With the NIS2 Implementation and Cybersecurity Strengthening Act, Germany has transposed the European NIS2 directive. The act entered into force on 6 December 2025 and significantly widens the circle of regulated companies – from a few hundred critical infrastructure operators to many thousands of businesses.
Who is affected
The act covers “important” and “essential” entities in defined sectors, including energy, transport, health, digital infrastructure, finance, waste management, food and parts of manufacturing. As a rough rule of thumb, companies in these sectors with 50 or more employees or €10 million annual turnover should check whether they are in scope. For some types of entity the act applies regardless of size.
The German Federal Office for Information Security (BSI) offers a free online scope check for this.
Registration with the BSI
Companies in scope must register with the BSI. The statutory deadline has passed; according to the BSI, anyone who has not yet registered should do so immediately. Registration first requires an ELSTER organisation certificate, followed by sign-up in the BSI portal.
Which obligations follow
- Risk management: appropriate technical and organisational measures, such as backup and contingency planning, access control, multi-factor authentication, vulnerability management and supply-chain security.
- Reporting: significant security incidents must be reported to the BSI within staged deadlines.
- Management accountability: management must approve the measures, oversee their implementation and take part in regular training.
How we help
We work out with you whether and how you are affected and implement the obligations pragmatically – as part of our IT and security check or within ongoing managed IT.
This article is not legal advice.