NISDESK · DE
NIS2 Compliance in Germany
Germany hosts the EU's largest base of NIS2-affected SMEs across energy, health, manufacturing and digital infrastructure — all supervised by BSI.
Are you in scope?
NIS2 covers medium and large organisations in 18 sectors. Fines reach €10M or 2% of global turnover. Check your scope, obligations and a readiness score for free.
Get the free NIS2 checklist for Germany
Free PDF delivered to your inbox. No spam — unsubscribe anytime.
National authority & CSIRT
In Germany, NIS2 supervision is handled by BSI (Bundesamt für Sicherheit in der Informationstechnik). The national CSIRT is CERT-Bund. Significant incidents must be reported within 24 h (early warning), 72 h (notification) and one month (final report) per NIS2 Article 23.
NIS2 sectors in Germany
Each sector has specific obligations. Explore them for Germany:
Frequently asked questions
Which sectors are covered by NIS2 in Germany?
NIS2 covers 18 sectors: Annex I (highly critical — energy, transport, banking, financial markets, health, water, digital infrastructure, ICT service management, public administration, space) and Annex II (other critical — postal services, waste management, chemicals, food, manufacturing, digital providers, research). Transposed via NIS2UmsuCG (Umsetzungsgesetz, 2024); BSI is the federal competent authority, Länder cooperate for regional entities.
Who supervises NIS2 compliance in Germany?
In Germany, the primary competent authority is BSI (Bundesamt für Sicherheit in der Informationstechnik). The national CSIRT is CERT-Bund, which handles significant incident notifications and cybersecurity coordination.
What are the NIS2 incident reporting deadlines in Germany?
Organisations must submit an early warning to CERT-Bund within 24 hours of a significant incident, a formal notification within 72 hours, and a final report within one month — per NIS2 Article 23.
What are the NIS2 fines in Germany?
Essential entities face fines up to €10 million or 2% of global annual turnover. Important entities face up to €7 million or 1.4% of global annual turnover. Exact enforcement varies by national transposition.
Official sources
- NIS2 Directive (EU) 2022/2555 — EUR-Lex
- DORA Regulation (EU) 2022/2554 — EUR-Lex
- ENISA — EU Agency for Cybersecurity
Last reviewed: 2026-07-03
For decision-support purposes only. Exact scope depends on national transposition — use our free scope checker for a personalised assessment.