NIS2 Incident Reporting Deadlines and Notification Duty in Germany

Published: · AIPOS OÜ · nis2europe.eu

Who must report an incident under the German BSI Act?

Germany has transposed NIS2 through the German BSI Act (BSIG). The incident notification duty applies to two categories of organisations defined in § 28 BSIG:

Both categories are required under § 32 BSIG to report *erhebliche Sicherheitsvorfälle* (significant security incidents). Operators of critical installations (Betreiber kritischer Anlagen) have an additional obligation to supply information on the type of installation affected, the critical service, and the impact of the incident on that service (§ 32 Abs. 3).

If you are unsure which category applies to your company, the size and sector thresholds are set out in § 28 BSIG. A quick self-assessment against those criteria is the first practical step before you build any reporting process.

Why it matters: the notification obligation is not just administrative. Missing or late reports can trigger fines (see the section below), so knowing your status and having a process ready is a compliance essential.

The three reporting deadlines: 24 hours, 72 hours and one month

The core of the German incident notification duty is § 32 BSIG. It sets out a staged reporting process with the following deadlines, each counted from becoming aware of the incident (nach Kenntniserlangung):

StageDeadlineContent
Early warning (frühe Erstmeldung)without undue delay, at the latest within 24 hoursState whether the incident is suspected of being caused by unlawful or malicious acts, or could have cross-border effects
Incident notification (Meldung)without undue delay, at the latest within 72 hoursConfirm or update the early warning, plus an initial assessment including severity, impact and, where available, indicators of compromise
Interim report (Zwischenmeldung)on request of the BSIRelevant status updates
Final report (Abschlussmeldung)at the latest one month after the 72-hour notificationDetailed description, severity and impact, underlying cause, mitigation measures applied and ongoing, and any cross-border impact

Ongoing incidents: if the incident is still ongoing when the one-month final report is due, the entity submits a progress report (Fortschrittsmeldung) instead, and provides the final report once it has completed its handling of the incident (§ 32 Abs. 2).

These deadlines mirror the reporting timeline in Article 23(4) of Directive (EU) 2022/2555, which likewise foresees an early warning within 24 hours, an incident notification within 72 hours, an intermediate report on request, and a final report no later than one month after the incident notification.

The obligation under § 32 applies at the earliest from the point the reporting channel has been set up (§ 32 Abs. 1).

Which authority and CSIRT receives the report?

Reports are not sent to a generic email address. Under § 32 Abs. 1 BSIG, significant security incidents go to a joint reporting office (gemeinsame Meldestelle) established by the Federal Office for Information Security (BSI) together with the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe.

The BSI plays several overlapping roles here:

How to report in practice:

The BSI forwards received reports to the relevant federal supervisory authorities without undue delay (§ 32 Abs. 5) and can offer support to reporting entities in remediating the incident (§ 32 Abs. 6).

Registration and the link to risk management

Incident reporting does not stand alone. Two related duties should be on your checklist:

Registration (§ 33 BSIG): essential and important entities, as well as Domain-Name-Registry service providers, must register with the BSI at the latest three months after they first (or again) qualify as such. Registration runs through the joint registration facility set up by the BSI and the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe and requires, among other things, the entity name (including legal form), contact details, the relevant sector, the EU Member States where services are provided, and the competent supervisory authorities.

Risk-management measures (§ 30 BSIG): the same entities must take appropriate and proportionate technical and organisational measures. § 30 Abs. 2 explicitly lists *Bewältigung von Sicherheitsvorfällen* (incident handling) among the required measures — so your incident response capability is what makes timely 24h/72h reporting possible in the first place. Management bodies are responsible for implementing and overseeing these measures (§ 38 Abs. 1).

Together, registration, risk management and incident reporting form the operational backbone of NIS2 compliance in Germany. A structured gap review across these three areas is the fastest way to see where you stand.

What happens if you report late — or not at all?

§ 65 BSIG treats failure to make a report correctly, completely and on time as an administrative offence (Ordnungswidrigkeit). Specifically:

The fine levels under § 65 Abs. 5 for these reporting-related offences are:

For entities with a total turnover of more than 500 million euro, turnover-based fines apply instead:

The administrative authority is, as a rule, the BSI (§ 65 Abs. 10). Given these figures, treating incident reporting deadlines as hard operational triggers — not optional formalities — is a business necessity.

Next step: use our free scoping and gap tool to check whether your organisation qualifies as a besonders wichtige or wichtige Einrichtung and whether your incident-reporting process meets the § 32 BSIG deadlines.

Frequently asked questions

What is the first NIS2 reporting deadline in Germany?

Under § 32 Abs. 1 BSIG, the first deadline is an early warning (frühe Erstmeldung), which must be sent without undue delay and at the latest within 24 hours of becoming aware of a significant security incident. It indicates whether the incident is suspected to result from unlawful or malicious acts or could have cross-border effects.

Who receives NIS2 incident reports in Germany?

Reports go to the joint reporting office (gemeinsame Meldestelle) established by the BSI and the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe (§ 32 Abs. 1). The BSI is the national CSIRT (§ 5 Abs. 5) and the central reporting and contact office (§ 40 Abs. 1). Reports are filed via the BSI portal at https://portal.bsi.bund.de.

When is the final incident report due?

The final report (Abschlussmeldung) is due at the latest one month after the 72-hour incident notification (§ 32 Abs. 1 Nr. 4). If the incident is still ongoing at that point, the entity submits a progress report instead and provides the final report once it has finished handling the incident (§ 32 Abs. 2).

What are the fines for failing to report an incident?

Under § 65 Abs. 5 BSIG, failing to report correctly, completely or on time can lead to fines of up to ten million euro for a besonders wichtige Einrichtung and up to seven million euro for a wichtige Einrichtung. For entities with turnover above 500 million euro, turnover-based caps of 2 percent (§ 65 Abs. 6) and 1.4 percent (§ 65 Abs. 7) apply respectively.

Check your NIS2 compliance

Start the free scoping test

Run the free gap analysis Run the free surface scan

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home