NIS2 Fines and Sanctions in Germany: What Companies Face Under the BSIG
Who supervises and enforces NIS2 in Germany?
In Germany, NIS2 is transposed through the German BSI Act (BSIG). The competent supervisory authority is the Federal Office for Information Security (BSI) (§ 59). The BSI is also the national single point of contact and the central reporting and contact point (§ 40 Abs. 1), and it holds supervisory and enforcement powers over regulated entities (§§ 61–62).
The law distinguishes two categories of regulated organisations:
- besonders wichtige Einrichtung (essential entity), defined in § 28 Abs. 1
- wichtige Einrichtung (important entity), defined in § 28 Abs. 2
Your classification under § 28 directly determines the maximum fine you may face — so knowing which category you fall into is the first step in understanding your exposure.
Maximum fines: essential vs important entities
The administrative fine framework is set out in § 65 BSIG. The two headline maximums, tied to the most serious categories of infringement (e.g. failure to implement risk-management measures under § 30, or reporting failures under § 32), are:
| Category | Fixed maximum fine (§ 65 Abs. 5 Nr. 1) |
|---|---|
| besonders wichtige Einrichtung (essential) | up to ten million euros |
| wichtige Einrichtung (important) | up to seven million euros |
Beyond these fixed ceilings, § 65 also sets lower tiers for other types of violations, depending on the specific breach:
- up to five million euros (§ 65 Abs. 5 Nr. 2)
- up to two million euros (§ 65 Abs. 5 Nr. 3)
- up to one million euros (§ 65 Abs. 5 Nr. 4)
- up to five hundred thousand euros (§ 65 Abs. 5 Nr. 5)
- up to one hundred thousand euros (§ 65 Abs. 5 Nr. 6)
The exact ceiling that applies depends on which obligation was breached and how — which is why a precise mapping of your obligations matters.
Turnover-based fines for large organisations
For larger organisations, § 65 introduces an alternative, turnover-based penalty that can exceed the fixed euro ceilings.
Where the total turnover exceeds 500 million euros, the following percentage-based maximums apply for the most serious infringements (the cases in § 65 Abs. 2 Nr. 1 Buchstabe d, Nr. 2 bis 5 und 9):
| Category | Turnover-based maximum |
|---|---|
| besonders wichtige Einrichtung (essential) | up to 2 percent of total turnover (§ 65 Abs. 6) |
| wichtige Einrichtung (important) | up to 1.4 percent of total turnover (§ 65 Abs. 7) |
Under § 65 Abs. 8, total turnover means the sum of all worldwide revenues achieved by the undertaking to which the entity belongs, in the financial year preceding the authority's decision. The total turnover may be estimated.
In practice this means: for a large group, the percentage of worldwide turnover can produce a far higher figure than the fixed ten- or seven-million-euro caps. The administrative authority is, as a rule, the Federal Office for Information Security (§ 65 Abs. 10).
Management responsibility and personal liability
NIS2 in Germany is not only about corporate fines — it places direct duties on the management body.
Under § 38 Abs. 1 BSIG, the management (Geschäftsleitungen) of besonders wichtige Einrichtungen and wichtige Einrichtungen must implement the risk-management measures under § 30 and oversee their implementation.
Key consequences:
- Personal liability for damages: Under § 38 Abs. 2, managers who breach their duties under Abs. 1 are liable to their entity for culpably caused damage, in line with the company-law rules applicable to the entity's legal form.
- Mandatory training: Under § 38 Abs. 3, management must regularly attend training to acquire sufficient knowledge and skills to identify and assess risks and risk-management practices in information security.
- This is echoed at EU level. Article 20(1) of Directive (EU) 2022/2555 requires management bodies of essential and important entities to approve the cybersecurity risk-management measures, oversee their implementation, and provides that they can be held liable for the entity's infringements of Article 21.
As a further enforcement lever, where an essential entity fails to comply with BSI orders despite a deadline, the competent supervisory authority may — as a last resort — temporarily prohibit unreliable management from exercising their management function (§ 61 Abs. 9). This underlines that responsibility for NIS2 compliance sits firmly at leadership level, not only in the IT department.
How to reduce your fine exposure
The size of a potential fine is closely linked to whether you have actually implemented the required measures. The core obligations that carry the highest fine tiers include:
- Risk-management measures under § 30 (covering, among others, incident handling, business continuity, supply chain security, cryptography, access control and multi-factor authentication).
- Incident reporting under § 32, with an early warning within 24 hours, a notification within 72 hours, and a final report within one month.
- Registration with the BSI within three months of first qualifying as a regulated entity (§ 33).
A practical starting point is to confirm whether you are in scope at all, and if so, whether you qualify as a besonders wichtige Einrichtung or a wichtige Einrichtung under § 28 — because that determines both your obligations and your maximum fine.
Use our free scoping and gap-analysis tool to check your likely classification and identify where your current measures fall short of § 30 and § 32 requirements — before the BSI does.
Frequently asked questions
What is the maximum NIS2 fine in Germany?
Under § 65 Abs. 5 BSIG, a besonders wichtige Einrichtung (essential entity) can face a fine of up to ten million euros, and a wichtige Einrichtung (important entity) up to seven million euros. For organisations with a total turnover of more than 500 million euros, turnover-based maximums apply instead: up to 2 percent of total turnover for essential entities (§ 65 Abs. 6) and up to 1.4 percent for important entities (§ 65 Abs. 7).
Can managers be held personally liable under NIS2 in Germany?
Yes. Under § 38 Abs. 1 BSIG, management must implement and oversee the risk-management measures under § 30. Under § 38 Abs. 2, managers who breach these duties are liable to their own entity for culpably caused damage according to the company-law rules for the entity's legal form. Article 20(1) of Directive (EU) 2022/2555 similarly provides that management bodies can be held liable for the entity's infringements of Article 21.
Which authority imposes NIS2 fines in Germany?
The administrative authority is, as a rule, the Federal Office for Information Security (BSI) under § 65 Abs. 10 BSIG. The BSI is also the competent supervisory authority for NIS2 obligations under § 59 and holds supervisory and enforcement powers under §§ 61–62.
Does turnover affect the fine amount?
Yes, for large organisations. Where the total turnover exceeds 500 million euros, the most serious infringements can be sanctioned with up to 2 percent of total turnover for essential entities (§ 65 Abs. 6) or up to 1.4 percent for important entities (§ 65 Abs. 7). Under § 65 Abs. 8, total turnover is the worldwide revenue of the undertaking in the financial year preceding the authority's decision, and it may be estimated.
Check your NIS2 compliance
This article is general information, not legal advice. A partner lawyer confirms your specific situation.