Germany

← All Member States
Transposed, in force
NIS2 status
Transposed, in force
National law
NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG), BGBl. 2025 I Nr. 301 (published 2025-12-05)
Competent authority
Bundesamt für Sicherheit in der Informationstechnik (BSI)
CSIRT
CERT-Bund (BSI)
Last verified
2026-07-16

Germany

✅ NIS2 transposed and in force.

NIS2 transposition

  • National law: NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG), BGBl. 2025 I Nr. 301 (published 2025-12-05)
  • Status / entry into force: In force 2025-12-06 (no transition period)

Competent authority & CSIRT

  • Competent authority: Bundesamt für Sicherheit in der Informationstechnik (BSI)
  • CSIRT / incident response: CERT-Bund (BSI)
  • Registration: BSI Melde- und Informationsportal; registration deadline 2026-03-06

Incident reporting

Follows the NIS2 cascade: early warning within 24h, notification within 72h, final report within one month, submitted to the national CSIRT / competent authority. Assume national-language submission unless the authority states otherwise.

Penalties & board liability

  • Essential entities: up to €10M or 2% of worldwide turnover (directive minimum, adopted here).
  • Important entities: up to €7M or 1.4% of worldwide turnover.
  • Management-body accountability applies per NIS2 Art. 20; national enforcement mechanisms vary.

CER Directive

Critical-entities resilience is transposed in parallel (often via the same or a connected authority). Member States had to identify critical entities by 2026-07-17. ⚠️ VERIFY national CER instrument.

Notes

~29,500 entities across 18 sectors. 14-month delay driven by the late-2024 collapse of the Ampel coalition. Personal liability for Geschäftsführer/Vorstand incl. possible fines and management-function bans.

Sources