What is the NIS2 Implementation Act (NIS-2-Umsetzungsgesetz)?
The NIS-2-Umsetzungsgesetz, Germany's NIS2 Implementation Act, transposes the NIS2 Directive into German law; at its core is a recast BSI Act (BSIG). Its official title is "Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung". In English: an act transposing the NIS2 Directive and setting out the main principles of information security management in the federal administration. It entered into force on 6 December 2025.
Article 41(1) of Directive (EU) 2022/2555 had set 18 October 2024 as the date on which Member States were to apply their measures. For German entities, the BSIG is what counts: anyone within its scope has been subject to its duties since 6 December 2025.
How organisations implement the requirements is covered in the NIS2 guide.
Who does the NIS2 Implementation Act cover?
§ 28 BSIG has two categories: besonders wichtige Einrichtungen (essential entities) and wichtige Einrichtungen (important entities). Operators of critical installations are not a third category; under § 28(1) no. 1 they count as essential entities.
| Category | Who falls under it |
|---|---|
| Essential entity (§ 28(1)) | operators of critical installations (no. 1); qualified trust service providers, top-level domain name registries and DNS service providers, regardless of size (no. 2); telecommunications providers with at least 50 employees or with annual turnover and balance sheet total each above €10 million (no. 3); types of entity under Annex 1 with at least 250 employees, or with annual turnover above €50 million and in addition a balance sheet total above €43 million (no. 4) |
| Important entity (§ 28(2)) | trust service providers (no. 1); smaller telecommunications providers (no. 2); types of entity under Annexes 1 and 2 with at least 50 employees, or with annual turnover and balance sheet total each above €10 million (no. 3) |
The Directive speaks of "essential" entities, the BSIG of "besonders wichtige" (particularly important) entities; both mean the same upper tier. Each organisation checks for itself whether it is covered; the steps are set out in the entry on NIS2 scope.
Four core duties under the BSIG
The BSIG places four duties on essential and important entities:
| Duty | Provision | What it requires |
|---|---|---|
| Risk management | § 30 BSIG | appropriate, proportionate and effective measures; paragraph 2 sentence 2 lists ten measures that must be covered "at least"; compliance must be documented |
| Reporting significant security incidents | § 32 BSIG | early initial notification within 24 hours, notification within 72 hours, both from becoming aware; final notification at the latest one month after the 72-hour notification; addressee is the joint reporting office of the BSI and the Federal Office of Civil Protection and Disaster Assistance (BBK) |
| Registration | § 33 BSIG | details due at the latest three months after the entity first or again qualifies; changes within two weeks |
| Duties of the management body | § 38 BSIG | implement the measures and oversee their implementation (paragraph 1); "regularly take part in training" (paragraph 3) |
The ten minimum measures are explained in the entry on NIS2 risk management measures. An intermediate notification under § 32(1) no. 3 is due only at the BSI's request. Deadlines and contents are detailed in the entry on NIS2 incident reporting.
Operators of critical installations carry three extra duties. They deploy attack detection systems (§ 31(2)) and add further details to their notifications (§ 32(3)). They also prove implementation to the BSI through audits, inspections or certifications (§ 39(1)). The BSI sets the first date, no earlier than three years after they first qualify; after that, every three years.
What fines does § 65 BSIG set?
§ 65 BSIG grades fines by offence and category. For the core duties, these maximums apply:
| Offence | Provision | Essential entity | Important entity |
|---|---|---|---|
| measures under § 30(1) sentence 1 not taken or not taken in time, compliance not documented, notification or final notification under § 32 missed | § 65(2) nos. 2 to 5, (5) sentence 1 no. 1 | up to €10 million | up to €7 million |
| the same offences with total turnover above €500 million | § 65(6) and (7) | up to 2% of total turnover | up to 1.4% of total turnover |
| registration details under § 33(1) not submitted, incorrect or late | § 65(2) no. 6, (5) sentence 1 no. 5 | up to €500,000 | up to €500,000 |
Under paragraph 8, total turnover is the worldwide turnover of the undertaking the entity belongs to, in the financial year before the authority's decision. If a data protection authority has already fined the same conduct under the GDPR, paragraph 11 rules out a further fine under the BSIG.
Exceptions for finance, telecoms and energy
For financial entities within the meaning of DORA, §§ 30, 31, 32, 35, 36, 38 and 39 BSIG do not apply (§ 28(6) no. 1). For them, the duties of Regulation (EU) 2022/2554 apply instead. Registration under § 33 is not affected.
§ 28(5) contains a second exception: §§ 30, 31, 32, 35, 36, 38, 39, 61 and 62 BSIG do not apply to operators of public telecommunications networks and services. The same holds for operators of energy supply networks, energy installations or digital energy services subject to §§ 5c to 5e of the Energy Industry Act (EnWG). The exception does not apply where these entities operate further critical installations or fall under Annex 1 or 2 through further activities.
The physical resilience of critical installations is governed by the KRITIS-Dachgesetz, the German critical infrastructure umbrella act, in force since 17 March 2026. Critical installations are registered under § 33(2) BSIG in accordance with § 8 of the KRITIS-Dachgesetz, with the BBK as the competent authority.
What Rizzqo models for NIS2 implementation
NIS2 is supported in Rizzqo; its catalogue is enabled when a customer needs it. Rizzqo models the asset register for this: systems, sites and service providers with an assigned owner, linked to the business processes that run on them. The requirements of the held catalogues ISO/IEC 27001 and ISO/IEC 27002 appear on these assets.