Skip to main content
NIS2 · GERMANY

NIS2 in Germany — the BSI, a registration window that has closed, and KRITIS continuity.

Germany transposed NIS2 through the NIS2-Umsetzungs- und Umsetzungsgesetz (NIS2UmsuCG), in force since 6 December 2025. The BSI — the Federal Office for Information Security — is the competent authority and national CSIRT, and opened its registration portal on 6 January 2026. Around 29,500 entities are expected in scope, by most estimates the largest entity pool of any member state. For entities in that pool that have not yet registered, the window has already closed: the deadline ran to 31 July 2026, extended at the BSI's own request from the original 6 March.

What makes Germany distinctive is not the new law but the depth of structure underneath it. NIS2 does not replace KRITIS — it extends the regime to more sectors and lower thresholds, with the BSI's authority, portal and enforcement powers carried forward. Teams already reporting into KRITIS are extending documented practice, not inventing it.

Who it applies to

Essential and important entities across the NIS2 sectors, with Germany's implementation extending KRITIS-grade obligations to a broader pool — more sectors, lower thresholds for medium-sized enterprises. Entities already classified under KRITIS are in scope with structures they already operate; new entities assess against the expanded thresholds. Registration runs through the BSI's portal (window closed 31 July 2026), and the incident regime runs in three stages: early warning within 24 hours, the incident report within 72 hours, the final report within one month.

The clock

Competent authority: BSI (Bundesamt für Sicherheit in der Informationstechnik). Transposition: NIS2-Umsetzungs- und Umsetzungsgesetz (NIS2UmsuCG).

NIS2 in Germany · timeline
WhenWhat happens
6 Dec 2025NIS2UmsuCG enters into force · BSI authority confirmed
6 Jan 2026BSI registration portal opens
31 Jul 2026Registration deadline — extended from 6 March at the BSI's request · now closed
OngoingEarly warning 24 h · report 72 h · final report one month

KRITIS 2.0 — evolution, not replacement

Germany's NIS2 implementation is effectively KRITIS 2.0 — a deepening and widening of the existing critical-infrastructure regime rather than a clean-slate replacement. The BSI's authority, the classification system and the enforcement mechanisms carry forward from KRITIS. What changes is the reach: more sectors, lower thresholds, explicit supply-chain requirements, and an entity pool around 29,500 strong. For teams already operating under KRITIS, NIS2 means extending documented practices to new areas rather than inventing them from zero — and TruSecure maps that delta control by control instead of restarting the program.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Germany transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Germany requirements · how TruSecure answers them
What the law asksWhere it is answered
Register with the BSI (window closed 31 July 2026 — late filers act now)Entity profile · registration status tracked, facts filed without further delay
Maintain documented risk management and cybersecurity measuresControl library mapped to the NIS2UmsuCG · evidence collected continuously, not assembled at audit time
Report incidents within statutory timeframesIncident workflow · clocked reporting to the BSI, templates for each deadline tier
Conduct regular audits and supply-chain risk assessmentsAudit trail · supplier-risk workspace, third-party controls monitored and evidenced
Update risk-management documentation annuallyLiving documentation · reviews scheduled, change detection triggers updates between cycles

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Germany NIS2 readiness file · excerptSample data
BSI classification
essential · energy sector
Registration
BSI portal · filed 21 Feb 2026
KRITIS history
pre-existing classification · NIS2 overlay applied
Controls evidenced
142/156 · 14 open, each with owner and deadline
Incident reports
3 filed in last 12 months · all within statutory timeframes
Export
sealed · sha256:7f2b...9e4a

Where teams usually start

With a demo walked through by TruSecure — your KRITIS-to-NIS2 delta mapped against the NIS2UmsuCG requirements, the expanded entity scope assessed, and the controls you already operate extended to cover the new obligations. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Germany by BSI (Bundesamt für Sicherheit in der Informationstechnik). TruSecure determines applicability against Germany's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Does our existing KRITIS reporting satisfy NIS2 as well?
There is substantial overlap — TruSecure maps the specific delta rather than treating it as a green-field program.