Loading…
Loading…
The NIS2UmsuCG is Germany's national transposition of EU Directive 2022/2555 (NIS2), which expanded the EU's network and information security perimeter from the 2016 NIS1 baseline to cover a much wider sectoral and entity scope. Germany missed the EU's 17 October 2024 transposition deadline by more than a year — Berlin was already under infringement-procedure pressure from the European Commission for non-transposition before Bundestag passage. The final statute brings Germany into formal compliance and now sets the de-facto template for the remaining EU Member States still in transposition limbo.
The key mechanisms:
advisory cyber-security agency to the central national NIS2 competent authority with binding supervision over covered entities, registration powers, audit rights, and administrative-fine authority.
("essential" Category 1 and "important" Category 2) covering 18 sectors: energy, transport, banking, financial-market infrastructure, health, drinking-water, wastewater, digital infrastructure (cloud, data-centre, content-delivery, trust-service, DNS, TLD), ICT-service management, public administration, space, postal, waste management, manufacture of chemicals, manufacture of food, manufacture of certain critical products (medical devices, electronics, motor vehicles), digital providers (online marketplaces, search engines, social platforms), and research.
to BSI for significant incidents, 72-hour incident-notification with initial assessment, and a final report within one month — with intermediate status reports on request.
senior management for cybersecurity-risk-management failures, plus a mandatory training obligation; this is the most material delta from the prior IT-Sicherheitsgesetz 2.0 (2021) regime, which had much weaker individual-accountability provisions.
regardless of headcount/turnover thresholds where they form part of a covered essential or important entity's supply chain.
from 6 December 2025 with no phased entry into force, although BSI has indicated supervisory forbearance in the first months for entities acting in good faith on registration.
The NIS2UmsuCG pairs with the KRITIS-Dachgesetz (filed 2026-03-17), which transposes the companion CER Directive (2022/2557) for physical-security and resilience of critical infrastructure — together giving Germany an integrated cyber + physical critical-infrastructure regulatory stack for the first time.
Act 266/2025 (filed 2025-08-04) was a CER-Directive transposition, not NIS2. Germany — the EU's largest economy and host to most pan- European data-centre and cloud capacity — going live forces all remaining Member States to accelerate their own transpositions or face widening compliance asymmetry.
change from the pre-NIS2 regime of ~4,500 KRITIS operators under IT-SiG 2.0. BSI staffing, audit, and registration-processing capacity is the binding operational constraint over 2026-2028.
vendors selling into Germany.** AWS, Microsoft Azure, Google Cloud, Oracle Cloud, and SaaS providers with German enterprise customers inherit downstream supply-chain due-diligence obligations from their essential/important-entity customers. Same for OT vendors (Siemens Energy, ABB, Schneider Electric, Honeywell) and IoT product manufacturers — directly stacks on CRA (Reg 2024/2847) cyber-product obligations.
DAX/MDAX cybersecurity governance — expect a 2026-2027 wave of board cyber-governance committee formation and CISO-elevation cycles, comparable to the post-Sarbanes-Oxley audit-committee build-out in the US in the early 2000s.
Commission's infringement actions against the other 17 non- transposing Member States gain political weight; expect a 2026 transposition wave across France, Spain, Italy, the Netherlands, Belgium, and the Nordics.
setting numerical entity-classification thresholds for the 18 sectors — drafts expected H1 2026.
3.0 — whether NIS2UmsuCG replaces or supplements ITSG 2.0 provisions on cross-sector incident sharing.
agency; whether it actually levies administrative fines at the NIS2-permitted ceilings (up to 2% of global turnover for essential entities) is the credibility test for the regime.
to KRITIS operators in practice face binding due-diligence audits, given BSI staffing constraints.
(cyber) supervisory boundaries are clean in practice or generate jurisdictional friction between BSI and BBK.