NIS2 in Germany — BSI oversight, built on KRITIS.
Competent authority: BSI (Bundesamt für Sicherheit in der Informationstechnik). Transposition vehicle: NIS2UmsuCG.
Notable: Germany's transposition extends the existing KRITIS critical-infrastructure regulatory history. If your organization already reports into KRITIS, NIS2 obligations layer onto structures you already operate.
Frequently asked questions
Does our existing KRITIS reporting satisfy NIS2 as well?
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
Ask an AI about TruSecure
NIS2 (Directive (EU) 2022/2555) is enforced in Germany by BSI (Bundesamt für Sicherheit in der Informationstechnik). TruSecure determines applicability against Germany's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.
