NIS2 Incident Reporting Deadlines and Notification Duty in Germany
Who must report an incident under the German BSI Act?
Germany has transposed NIS2 through the German BSI Act (BSIG). The incident notification duty applies to two categories of organisations defined in § 28 BSIG:
- besonders wichtige Einrichtung (essential entity)
- wichtige Einrichtung (important entity)
Both categories are required under § 32 BSIG to report *erhebliche Sicherheitsvorfälle* (significant security incidents). Operators of critical installations (Betreiber kritischer Anlagen) have an additional obligation to supply information on the type of installation affected, the critical service, and the impact of the incident on that service (§ 32 Abs. 3).
If you are unsure which category applies to your company, the size and sector thresholds are set out in § 28 BSIG. A quick self-assessment against those criteria is the first practical step before you build any reporting process.
Why it matters: the notification obligation is not just administrative. Missing or late reports can trigger fines (see the section below), so knowing your status and having a process ready is a compliance essential.
The three reporting deadlines: 24 hours, 72 hours and one month
The core of the German incident notification duty is § 32 BSIG. It sets out a staged reporting process with the following deadlines, each counted from becoming aware of the incident (nach Kenntniserlangung):
| Stage | Deadline | Content |
|---|---|---|
| Early warning (frühe Erstmeldung) | without undue delay, at the latest within 24 hours | State whether the incident is suspected of being caused by unlawful or malicious acts, or could have cross-border effects |
| Incident notification (Meldung) | without undue delay, at the latest within 72 hours | Confirm or update the early warning, plus an initial assessment including severity, impact and, where available, indicators of compromise |
| Interim report (Zwischenmeldung) | on request of the BSI | Relevant status updates |
| Final report (Abschlussmeldung) | at the latest one month after the 72-hour notification | Detailed description, severity and impact, underlying cause, mitigation measures applied and ongoing, and any cross-border impact |
Ongoing incidents: if the incident is still ongoing when the one-month final report is due, the entity submits a progress report (Fortschrittsmeldung) instead, and provides the final report once it has completed its handling of the incident (§ 32 Abs. 2).
These deadlines mirror the reporting timeline in Article 23(4) of Directive (EU) 2022/2555, which likewise foresees an early warning within 24 hours, an incident notification within 72 hours, an intermediate report on request, and a final report no later than one month after the incident notification.
The obligation under § 32 applies at the earliest from the point the reporting channel has been set up (§ 32 Abs. 1).
Which authority and CSIRT receives the report?
Reports are not sent to a generic email address. Under § 32 Abs. 1 BSIG, significant security incidents go to a joint reporting office (gemeinsame Meldestelle) established by the Federal Office for Information Security (BSI) together with the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe.
The BSI plays several overlapping roles here:
- It is the national single point of contact and central reporting and contact office for essential and important entities (§ 40 Abs. 1).
- It acts as the national CSIRT (§ 5 Abs. 5).
- It is the competent supervisory authority for the NIS2 obligations (§ 59), with enforcement powers under §§ 61–62.
How to report in practice:
- Reports are submitted via the BSI portal at https://portal.bsi.bund.de
- Entities without a registration can report a significant incident via the online form of the joint reporting office: https://mip2.bsi.bund.de/de/meldungen/meldung-ohne-registrierung-erstellen/?meldestelle=10&formular=32
- General BSI contact: bsi@bsi.bund.de, phone +49 228 99 9582-0
The BSI forwards received reports to the relevant federal supervisory authorities without undue delay (§ 32 Abs. 5) and can offer support to reporting entities in remediating the incident (§ 32 Abs. 6).
Registration and the link to risk management
Incident reporting does not stand alone. Two related duties should be on your checklist:
Registration (§ 33 BSIG): essential and important entities, as well as Domain-Name-Registry service providers, must register with the BSI at the latest three months after they first (or again) qualify as such. Registration runs through the joint registration facility set up by the BSI and the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe and requires, among other things, the entity name (including legal form), contact details, the relevant sector, the EU Member States where services are provided, and the competent supervisory authorities.
Risk-management measures (§ 30 BSIG): the same entities must take appropriate and proportionate technical and organisational measures. § 30 Abs. 2 explicitly lists *Bewältigung von Sicherheitsvorfällen* (incident handling) among the required measures — so your incident response capability is what makes timely 24h/72h reporting possible in the first place. Management bodies are responsible for implementing and overseeing these measures (§ 38 Abs. 1).
Together, registration, risk management and incident reporting form the operational backbone of NIS2 compliance in Germany. A structured gap review across these three areas is the fastest way to see where you stand.
What happens if you report late — or not at all?
§ 65 BSIG treats failure to make a report correctly, completely and on time as an administrative offence (Ordnungswidrigkeit). Specifically:
- Failing to make the notification under § 32 Abs. 1 Satz 1 correctly, completely or on time (§ 65 Abs. 2 Nr. 4)
- Failing to submit the final report under § 32 Abs. 2 Satz 2 correctly, completely or on time (§ 65 Abs. 2 Nr. 5)
The fine levels under § 65 Abs. 5 for these reporting-related offences are:
- besonders wichtige Einrichtung: up to ten million euro
- wichtige Einrichtung: up to seven million euro
For entities with a total turnover of more than 500 million euro, turnover-based fines apply instead:
- besonders wichtige Einrichtung: up to 2 percent of worldwide total turnover of the previous financial year (§ 65 Abs. 6)
- wichtige Einrichtung: up to 1.4 percent (§ 65 Abs. 7 and Abs. 8)
The administrative authority is, as a rule, the BSI (§ 65 Abs. 10). Given these figures, treating incident reporting deadlines as hard operational triggers — not optional formalities — is a business necessity.
Next step: use our free scoping and gap tool to check whether your organisation qualifies as a besonders wichtige or wichtige Einrichtung and whether your incident-reporting process meets the § 32 BSIG deadlines.
Frequently asked questions
What is the first NIS2 reporting deadline in Germany?
Under § 32 Abs. 1 BSIG, the first deadline is an early warning (frühe Erstmeldung), which must be sent without undue delay and at the latest within 24 hours of becoming aware of a significant security incident. It indicates whether the incident is suspected to result from unlawful or malicious acts or could have cross-border effects.
Who receives NIS2 incident reports in Germany?
Reports go to the joint reporting office (gemeinsame Meldestelle) established by the BSI and the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe (§ 32 Abs. 1). The BSI is the national CSIRT (§ 5 Abs. 5) and the central reporting and contact office (§ 40 Abs. 1). Reports are filed via the BSI portal at https://portal.bsi.bund.de.
When is the final incident report due?
The final report (Abschlussmeldung) is due at the latest one month after the 72-hour incident notification (§ 32 Abs. 1 Nr. 4). If the incident is still ongoing at that point, the entity submits a progress report instead and provides the final report once it has finished handling the incident (§ 32 Abs. 2).
What are the fines for failing to report an incident?
Under § 65 Abs. 5 BSIG, failing to report correctly, completely or on time can lead to fines of up to ten million euro for a besonders wichtige Einrichtung and up to seven million euro for a wichtige Einrichtung. For entities with turnover above 500 million euro, turnover-based caps of 2 percent (§ 65 Abs. 6) and 1.4 percent (§ 65 Abs. 7) apply respectively.
Check your NIS2 compliance
This article is general information, not legal advice. A partner lawyer confirms your specific situation.