Skip to content

Regulatory Framework

Legal SourceStatusRelevance
NIS 2 Directive (EU) 2022/2555In force since 16.01.2023EU framework directive
NIS2UmsuCG (Omnibus Act)In force since 06.12.2025German implementation
BSIG (Revised)In force since 06.12.2025Central obligations
Implementing Regulation (EU) 2024/2690In force since 07.11.2024Directly applicable to DNS service providers, MSPs and others: technical and methodological requirements for the risk management measures (precedence under §30(3) BSIG) and thresholds for significant security incidents (Art. 3 et seq. Implementing Regulation)
KRITIS Umbrella Act (KRITIS-DachG)In force since 17.03.2026Physical resilience (CER implementation)

Applicability

The BSIG distinguishes two categories. The decisive factors are the entity type (Annexes 1 and 2 BSIG) and company size (§28 BSIG):

CategoryCriteria (simplified)Fine range (§65 BSIG)
Essential entities (besonders wichtige Einrichtungen)Annex 1, at least 250 employees or both annual turnover above €50M and annual balance sheet total above €43M; regardless of size, operators of critical facilities, among othersUp to €10M; for entities with total turnover of more than €500M, up to 2% of worldwide total turnover
Important entities (wichtige Einrichtungen)Annex 1 or 2, at least 50 employees or annual turnover and annual balance sheet total each above €10MUp to €7M; for entities with total turnover of more than €500M, up to 1.4% of worldwide total turnover

Small Companies and Suppliers

Micro and small enterprises are in principle not covered – except in size-independent special cases. As suppliers to regulated entities, however, they are routinely obliged by contract to implement security measures. Size classes, special cases and scenarios: Applicability & Size Classes.

§30 BSIG – Ten Risk Management Measures

No.MeasureDocumentation
1Concepts relating to risk analysis and to information technology securityRisk Management
2Incident handlingIncident Management
3Business continuity, such as backup management and disaster recovery, and crisis managementBusiness Continuity
4Supply chain securitySupply Chain Security
5Security measures in acquisition, development and maintenance, including vulnerability management and disclosureVulnerability Management
6Effectiveness assessment concepts and proceduresEffectiveness Review
7Basic training and awareness measures in the field of information technology securityTraining & Awareness
8Concepts and processes for the use of cryptographic proceduresCryptography
9Concepts for personnel security, access control and the management of ICT systems, products and processesAccess Control
10Multi-factor or continuous authentication, secured voice, video and text communication, secured emergency communicationAccess Control

Additional Obligations

SectionObligationDocumentation
§§28, 29 BSIGClassification as an essential or important entityApplicability & Size Classes
§32 BSIGReporting obligations for significant security incidentsIncident Management
§33 BSIGRegistration obligation with BSIOrganizationally implemented
§38 BSIGImplementation, supervision and training obligations of managementGovernance

KRITIS-DachG Deadlines

  • 17.03.2026 – Entry into force (Act of 11.03.2026, BGBl. 2026 I No. 66)
  • 17.07.2026 – CER Directive deadline by which Member States identify their critical entities (Art. 6(1) (EU) 2022/2557) – not a deadline for operators
  • Registration – at the latest three months after a facility qualifies as a critical facility (§8(1) KRITIS-DachG). Which facilities are critical will only be determined by the statutory ordinance under §4(3) and §5(1) KRITIS-DachG, which according to the BBK is still being drafted and coordinated and has not yet been promulgated in the Federal Law Gazette (as of 19.09.2026). Until it enters into force, the BSI KRITIS Ordinance (BSI-KritisV) determines critical facilities for the purposes of the BSIG (§66 BSIG; §12 BSI-KritisV).
  • The KRITIS-DachG complements NIS2 with physical resilience and transposes the EU CER Directive ((EU) 2022/2557) into German law.

NIS2 vs CRA Demarcation

CriterionNIS2CRA
Regulatory subjectOperators (entities)Products with digital elements
Legal formDirective (national transposition)Regulation (directly applicable)
FocusOperational security (risk management)Product security (security by design)
ReportingBSI (24h / 72h / 1 month after the 72h notification)Coordinating CSIRT and ENISA via the single reporting platform (24h / 72h / 14 days after a corrective measure or 1 month)

CRA Synergy

CRA-compliant processes (vulnerability management, incident response, supply chain) largely fulfil the corresponding NIS2 requirements. Details in the CRA Compliance Documentation.

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT