NIS2 Fines and Sanctions in Germany: What Companies Face Under the BSIG

Published: · AIPOS OÜ · nis2europe.eu

Who supervises and enforces NIS2 in Germany?

In Germany, NIS2 is transposed through the German BSI Act (BSIG). The competent supervisory authority is the Federal Office for Information Security (BSI) (§ 59). The BSI is also the national single point of contact and the central reporting and contact point (§ 40 Abs. 1), and it holds supervisory and enforcement powers over regulated entities (§§ 61–62).

The law distinguishes two categories of regulated organisations:

Your classification under § 28 directly determines the maximum fine you may face — so knowing which category you fall into is the first step in understanding your exposure.

Maximum fines: essential vs important entities

The administrative fine framework is set out in § 65 BSIG. The two headline maximums, tied to the most serious categories of infringement (e.g. failure to implement risk-management measures under § 30, or reporting failures under § 32), are:

CategoryFixed maximum fine (§ 65 Abs. 5 Nr. 1)
besonders wichtige Einrichtung (essential)up to ten million euros
wichtige Einrichtung (important)up to seven million euros

Beyond these fixed ceilings, § 65 also sets lower tiers for other types of violations, depending on the specific breach:

The exact ceiling that applies depends on which obligation was breached and how — which is why a precise mapping of your obligations matters.

Turnover-based fines for large organisations

For larger organisations, § 65 introduces an alternative, turnover-based penalty that can exceed the fixed euro ceilings.

Where the total turnover exceeds 500 million euros, the following percentage-based maximums apply for the most serious infringements (the cases in § 65 Abs. 2 Nr. 1 Buchstabe d, Nr. 2 bis 5 und 9):

CategoryTurnover-based maximum
besonders wichtige Einrichtung (essential)up to 2 percent of total turnover (§ 65 Abs. 6)
wichtige Einrichtung (important)up to 1.4 percent of total turnover (§ 65 Abs. 7)

Under § 65 Abs. 8, total turnover means the sum of all worldwide revenues achieved by the undertaking to which the entity belongs, in the financial year preceding the authority's decision. The total turnover may be estimated.

In practice this means: for a large group, the percentage of worldwide turnover can produce a far higher figure than the fixed ten- or seven-million-euro caps. The administrative authority is, as a rule, the Federal Office for Information Security (§ 65 Abs. 10).

Management responsibility and personal liability

NIS2 in Germany is not only about corporate fines — it places direct duties on the management body.

Under § 38 Abs. 1 BSIG, the management (Geschäftsleitungen) of besonders wichtige Einrichtungen and wichtige Einrichtungen must implement the risk-management measures under § 30 and oversee their implementation.

Key consequences:

As a further enforcement lever, where an essential entity fails to comply with BSI orders despite a deadline, the competent supervisory authority may — as a last resort — temporarily prohibit unreliable management from exercising their management function (§ 61 Abs. 9). This underlines that responsibility for NIS2 compliance sits firmly at leadership level, not only in the IT department.

How to reduce your fine exposure

The size of a potential fine is closely linked to whether you have actually implemented the required measures. The core obligations that carry the highest fine tiers include:

A practical starting point is to confirm whether you are in scope at all, and if so, whether you qualify as a besonders wichtige Einrichtung or a wichtige Einrichtung under § 28 — because that determines both your obligations and your maximum fine.

Use our free scoping and gap-analysis tool to check your likely classification and identify where your current measures fall short of § 30 and § 32 requirements — before the BSI does.

Frequently asked questions

What is the maximum NIS2 fine in Germany?

Under § 65 Abs. 5 BSIG, a besonders wichtige Einrichtung (essential entity) can face a fine of up to ten million euros, and a wichtige Einrichtung (important entity) up to seven million euros. For organisations with a total turnover of more than 500 million euros, turnover-based maximums apply instead: up to 2 percent of total turnover for essential entities (§ 65 Abs. 6) and up to 1.4 percent for important entities (§ 65 Abs. 7).

Can managers be held personally liable under NIS2 in Germany?

Yes. Under § 38 Abs. 1 BSIG, management must implement and oversee the risk-management measures under § 30. Under § 38 Abs. 2, managers who breach these duties are liable to their own entity for culpably caused damage according to the company-law rules for the entity's legal form. Article 20(1) of Directive (EU) 2022/2555 similarly provides that management bodies can be held liable for the entity's infringements of Article 21.

Which authority imposes NIS2 fines in Germany?

The administrative authority is, as a rule, the Federal Office for Information Security (BSI) under § 65 Abs. 10 BSIG. The BSI is also the competent supervisory authority for NIS2 obligations under § 59 and holds supervisory and enforcement powers under §§ 61–62.

Does turnover affect the fine amount?

Yes, for large organisations. Where the total turnover exceeds 500 million euros, the most serious infringements can be sanctioned with up to 2 percent of total turnover for essential entities (§ 65 Abs. 6) or up to 1.4 percent for important entities (§ 65 Abs. 7). Under § 65 Abs. 8, total turnover is the worldwide revenue of the undertaking in the financial year preceding the authority's decision, and it may be estimated.

Check your NIS2 compliance

Start the free scoping test

Run the free gap analysis Run the free surface scan

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home