NIS2 vs. the German BSIG: How the EU Directive Becomes National Law

Published: · AIPOS OÜ · nis2europe.eu

From EU Directive to German Law

The EU NIS2 Directive (Directive (EU) 2022/2555) sets out cybersecurity obligations for essential and important entities across the Union. But a directive is not directly binding on companies — each Member State must transpose it into national law.

In Germany, this transposition is carried out through the German BSI Act (BSIG). This is the law your organisation must actually comply with. The directive sets the framework; the BSIG turns that framework into concrete, enforceable rules for entities established in Germany.

In practice this means:

For a business, the key takeaway is simple: you follow the BSIG, and the BSIG reflects the requirements of Directive (EU) 2022/2555.

The Competent Authority: the BSI

Germany has designated a clear supervisory body. The Federal Office for Information Security (BSI) is the competent authority for the NIS2 obligations (Part 3 of the BSIG) — for besonders wichtige Einrichtungen and wichtige Einrichtungen established in Germany, for operators of critical installations, and for federal administration bodies (§ 59).

The BSI wears several hats under the law:

Reports of significant incidents go to the joint reporting office run by the BSI together with the Federal Office for Civil Protection and Disaster Assistance (§ 32 Abs. 1). The general BSI contact is bsi@bsi.bund.de, +49 228 99 9582-0.

The Statutory Classification: besonders wichtige and wichtige Einrichtungen

Where the NIS2 Directive speaks of *essential* and *important* entities, the BSIG uses the German statutory terms:

The classification is set out in § 28 BSIG. For example, a besonders wichtige Einrichtung includes operators of critical installations, qualified trust service providers, and larger organisations in the sectors listed in Anlage 1 that employ at least 250 staff or exceed €50 million annual turnover together with a balance-sheet total above €43 million (§ 28 Abs. 1).

A wichtige Einrichtung includes, among others, entities in the sectors of Anlagen 1 and 2 that employ at least 50 staff or exceed €10 million in both annual turnover and balance-sheet total (§ 28 Abs. 2).

Getting this classification right matters, because it determines which duties, supervision regime and penalty ceilings apply to you.

What the German Law Adds on Top of the Directive

The BSIG doesn't just repeat the directive — it operationalises it with concrete German deadlines, procedures and sanctions. Key additions include:

Risk-management measures (§ 30). Essential and important entities must implement appropriate, proportionate and effective technical and organisational measures — mirroring the all-hazards approach of the directive and covering areas such as incident handling, business continuity, supply chain security, cryptography and multi-factor authentication.

Registration duty (§ 33). Entities must register with the BSI within three months of first (or again) qualifying as an essential or important entity — via the registration facility jointly set up by the BSI and the Federal Office for Civil Protection and Disaster Assistance.

Incident reporting deadlines (§ 32). Significant incidents follow a staged timeline:

StepDeadline
Early warningwithin 24 hours of becoming aware
Incident notificationwithin 72 hours
Intermediate reporton request of the BSI
Final reportwithin one month of the 72-hour notification

Management accountability (§ 38). Management bodies must implement and oversee the risk-management measures and attend regular training.

Fines (§ 65). For besonders wichtige Einrichtungen, fines can reach up to €10 million or, where global annual turnover exceeds €500 million, up to 2 % of that turnover (§ 65 Abs. 6). For wichtige Einrichtungen, up to €7 million or up to 1,4 % of global turnover (§ 65 Abs. 7). The administering authority is generally the BSI (§ 65 Abs. 10).

Tip: Start by confirming whether you qualify under § 28, then map your registration and reporting obligations. A free scoping/gap tool can help you identify where you stand before the deadlines apply to you.

Frequently asked questions

What is the German law that transposes NIS2?

It is the German BSI Act (BSIG). The BSIG implements the NIS2 Directive (Directive (EU) 2022/2555) into German national law, so your organisation complies with the BSIG rather than the directive directly.

Which authority supervises NIS2 compliance in Germany?

The Federal Office for Information Security (BSI). It is the competent supervisory authority for the NIS2 obligations under Part 3 of the BSIG (§ 59), and also acts as the national single point of contact, central reporting/contact point (§ 40 Abs. 1) and national CSIRT (§ 5 Abs. 5).

What are the incident reporting deadlines under the BSIG?

Under § 32 BSIG: an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, an intermediate report on request of the BSI, and a final report within one month of the 72-hour notification.

How high can fines be under the German BSIG?

Under § 65 BSIG, besonders wichtige Einrichtungen face fines up to €10 million or up to 2 % of global annual turnover (where turnover exceeds €500 million), and wichtige Einrichtungen up to €7 million or up to 1,4 % of global turnover. Lower tiers of €5 million, €2 million, €1 million, €500,000 and €100,000 apply depending on the type of infringement.

Check your NIS2 compliance

Start the free scoping test

Run the free gap analysis Run the free surface scan

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home