NIS2 in Germany — the BSI, a registration window that has closed, and KRITIS continuity.
Germany transposed NIS2 through the NIS2-Umsetzungs- und Umsetzungsgesetz (NIS2UmsuCG), in force since 6 December 2025. The BSI — the Federal Office for Information Security — is the competent authority and national CSIRT, and opened its registration portal on 6 January 2026. Around 29,500 entities are expected in scope, by most estimates the largest entity pool of any member state. For entities in that pool that have not yet registered, the window has already closed: the deadline ran to 31 July 2026, extended at the BSI's own request from the original 6 March.
What makes Germany distinctive is not the new law but the depth of structure underneath it. NIS2 does not replace KRITIS — it extends the regime to more sectors and lower thresholds, with the BSI's authority, portal and enforcement powers carried forward. Teams already reporting into KRITIS are extending documented practice, not inventing it.
Who it applies to
Essential and important entities across the NIS2 sectors, with Germany's implementation extending KRITIS-grade obligations to a broader pool — more sectors, lower thresholds for medium-sized enterprises. Entities already classified under KRITIS are in scope with structures they already operate; new entities assess against the expanded thresholds. Registration runs through the BSI's portal (window closed 31 July 2026), and the incident regime runs in three stages: early warning within 24 hours, the incident report within 72 hours, the final report within one month.
The clock
Competent authority: BSI (Bundesamt für Sicherheit in der Informationstechnik). Transposition: NIS2-Umsetzungs- und Umsetzungsgesetz (NIS2UmsuCG).
| When | What happens |
|---|---|
| 6 Dec 2025 | NIS2UmsuCG enters into force · BSI authority confirmed |
| 6 Jan 2026 | BSI registration portal opens |
| 31 Jul 2026 | Registration deadline — extended from 6 March at the BSI's request · now closed |
| Ongoing | Early warning 24 h · report 72 h · final report one month |
KRITIS 2.0 — evolution, not replacement
Germany's NIS2 implementation is effectively KRITIS 2.0 — a deepening and widening of the existing critical-infrastructure regime rather than a clean-slate replacement. The BSI's authority, the classification system and the enforcement mechanisms carry forward from KRITIS. What changes is the reach: more sectors, lower thresholds, explicit supply-chain requirements, and an entity pool around 29,500 strong. For teams already operating under KRITIS, NIS2 means extending documented practices to new areas rather than inventing them from zero — and TruSecure maps that delta control by control instead of restarting the program.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Germany transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register with the BSI (window closed 31 July 2026 — late filers act now) | Entity profile · registration status tracked, facts filed without further delay |
| Maintain documented risk management and cybersecurity measures | Control library mapped to the NIS2UmsuCG · evidence collected continuously, not assembled at audit time |
| Report incidents within statutory timeframes | Incident workflow · clocked reporting to the BSI, templates for each deadline tier |
| Conduct regular audits and supply-chain risk assessments | Audit trail · supplier-risk workspace, third-party controls monitored and evidenced |
| Update risk-management documentation annually | Living documentation · reviews scheduled, change detection triggers updates between cycles |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- BSI classification
- essential · energy sector
- Registration
- BSI portal · filed 21 Feb 2026
- KRITIS history
- pre-existing classification · NIS2 overlay applied
- Controls evidenced
- 142/156 · 14 open, each with owner and deadline
- Incident reports
- 3 filed in last 12 months · all within statutory timeframes
- Export
- sealed · sha256:7f2b...9e4a
Where teams usually start
With a demo walked through by TruSecure — your KRITIS-to-NIS2 delta mapped against the NIS2UmsuCG requirements, the expanded entity scope assessed, and the controls you already operate extended to cover the new obligations. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Germany by BSI (Bundesamt für Sicherheit in der Informationstechnik). TruSecure determines applicability against Germany's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.