NIS2 Germany Transposition Status, Fines and Who Enforces It

Germany’s NIS2 transposition is complete. The German NIS2 implementation act entered into force on 6 December 2025 with no transition period, and the BSI has since moved into an active enforcement phase on registration. If you run compliance for a company with German operations, three numbers frame the exposure. Fines reach €10 million or 2 percent of worldwide group turnover, the registration deadline expired on 6 March 2026, and § 38 BSIG makes managing directors personally liable. Berlin took 14 months longer than the directive allowed to pass the law, then gave companies zero days to comply with it. Pages describing the German statute as a draft, and some were still doing so in March 2026, are out of date.

ObligationLegal basisApplies since / deadlineWho it applies to
Risk management measures§ 30 BSIG6 December 2025, no transition periodParticularly important and important entities
Incident reporting§ 32 BSIG6 December 2025Particularly important and important entities
BSI registration§ 33 BSIGStatutory deadline 6 March 2026, expired. Reported administrative toleration to 31 July 2026All in-scope entities
Management approval, oversight and training§ 38 BSIG6 December 2025Geschäftsleitung (management body)
Fines§ 65 BSIG, enforced by the BSI (§ 59)In force. Up to €10M / 2% of group turnoverTiered by entity category and breach

The directive and the German law carry different years, which is where most of the date confusion starts. NIS2 itself is Directive (EU) 2022/2555, adopted on 14 December 2022. The law that transposes it in Germany is a 2025 statute, and within that statute three dates matter. It was signed on 2 December, published in the Federal Law Gazette on 5 December, and entered into force on 6 December. Several marketing pages claim promulgation on 6 December. The official gazette says 5 December. Pedantic, until you are calculating a deadline that runs from entry into force.

Germany Transposed NIS2 on 6 December 2025 With No Transition Period

The German NIS2 law is fully in force. Its formal name is the Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung (Act transposing the NIS 2 Directive and regulating key aspects of information security management in the federal administration), published as BGBl. 2025 I Nr. 301 and informally called the NIS2UmsuCG. In practice you will work with Article 1 of that act, which enacts an entirely new BSI-Gesetz, or BSIG (Federal Office for Information Security Act), replacing the 2009 statute of the same name. Nearly every business obligation, from risk management to fines, sits there.

The EU deadline for NIS2 transposition in Germany and every other member state was 17 October 2024. Germany missed it by roughly 14 months. Companies, by contrast, received keine Übergangsfrist (no transition period). Every duty in the law, including management liability, applied from day one.

The German Law Captures Around 29,500 Entities, Six Times More Than Before

The BSI’s official estimate is that roughly 29,500 companies plus federal administration bodies fall under the new BSIG, up from about 4,500 under the previous regime. Secondary estimates run from 25,000 to 40,000, but the official figure is the one to plan around.

The scope test starts at EU level, not with German specifics. You are generally in scope with 50 or more employees, or more than €10 million turnover and a €10 million balance sheet, in one of 18 sectors. If you have not run the EU two-part test yet, do that before reading further, because the German layer only modifies the answer.

The German layer changes the reach more than the mechanics. Manufacturing (verarbeitendes Gewerbe) is newly captured, the single biggest driver of the sixfold jump and the reason much of the Mittelstand is in scope for the first time. The terminology also shifts. Where the directive says essential and important entities, § 28 BSIG says besonders wichtige Einrichtungen (particularly important entities) and wichtige Einrichtungen (important entities). Particularly important maps to the directive’s essential tier, generally 250 or more employees or over €50 million turnover and a €43 million balance sheet in a high-criticality sector. Germany adds a third category with no directive equivalent, Betreiber kritischer Anlagen (operators of critical installations), the legacy KRITIS operators, automatically classed as particularly important.

The law also cuts narrower in places. Local government, educational institutions and long-term care are excluded, and DORA-regulated financial entities are exempt from the § 30 risk management duties but still must register. § 28 Abs. 3 exempts “negligible” (geringfügig) covered activities without defining negligible, which Morrison Foerster flags as a source of legal uncertainty rather than comfort.

Nobody will tell you which side of the line you are on. Classification runs on self-identification, and the BSI does not send scope notices the way the old KRITIS regime did. The misjudgement rate is measurable. The Schwarz Digits Cyber Security Report 2026 found 48 percent of firms underestimate their NIS2 exposure, and among small firms with 10 to 49 employees but more than €10 million turnover, the ones the size test actually captures, 92 percent wrongly assume they are out of scope. Our NIS2 Applicability Checker walks through the sector and size test in a few minutes, which is cheaper than learning the answer from an audit letter.

One adjacent regime to keep separate. The KRITIS-Dachgesetz, in force since 17 March 2026, transposes the CER Directive and covers physical resilience, supervised by the BBK rather than the BSI, with fines up to €1 million and its own registration deadline of 17 July 2026. KRITIS operators sit under both laws and register with both authorities via a joint platform. BSIG is the cyber track. The Dachgesetz is the physical one.

More Than 10,000 Companies Have Missed the BSI NIS2 Registration Deadline

The statutory deadline for Germany NIS2 registration was 6 March 2026, three months after entry into force. By the end of May 2026, per Kleeberg’s count, roughly 18,500 of the 29,500 in-scope entities had registered, leaving around 11,000 in default. Per figures compiled by Deutsche Presse-Agentur, two weeks before the cut-off only 4,856 entities had registered. A late surge of some 6,600 pushed the total to about 11,500 by 7 March, a curve familiar from every tax deadline ever set.

Registration under § 33 BSIG is a two-step process. You first need a Mein Unternehmenskonto (MUK) account, which itself requires an ELSTER organisation certificate, and then register in the BSI portal, live since 6 January 2026, providing among other things a 24/7 contact point, sector and entity category, KRITIS status and company size. Budget for the ELSTER certificate lead time, not just the form.

One reported development needs careful reading. LocateRisk reports the BSI has granted trade associations a toleration for late registrations until 31 July 2026, which Kleeberg characterises as administrative forbearance (behördliche Duldung), not a change to the statutory deadline. The 6 March deadline stands, and missing it was already an offence when it passed. What the toleration signals is a window in which late registration is unlikely to be punished, and that window has two weeks left.

Missing registration is a standalone fineable offence under § 65, up to €500,000, with no security incident required to trigger it. Late registration remains possible and signals cooperation. Continued silence signals the opposite, to an authority that § 33 also empowers to register an entity on its own initiative.

Fines Match the Directive Exactly, Up to €10 Million or 2 Percent of Group Turnover

Fines under § 65 BSIG reach €10 million or 2 percent of total worldwide annual turnover, whichever is higher, for particularly important entities, and €7 million or 1.4 percent for important entities. The usual expectation is German gold-plating, and there is none at the top tier. Germany mirrored the directive’s ceilings to the euro.

The German signature is below the top tiers. § 65 runs a graduated schedule down through €5 million, €2 million, €1 million, €500,000 and €100,000 for lesser breaches, a seven-step catalogue modelled on the GDPR’s structure. Registration and documentation failures sit in the €500,000 tier, minor cooperation failures at €100,000.

The turnover basis deserves more attention than the headline numbers. Under § 65 Abs. 8, “Gesamtumsatz” means the worldwide turnover of the whole group the entity belongs to. A 60-person German subsidiary can be fined on the basis of its parent group’s entire worldwide turnover, and the BSI is allowed to estimate that number. In the other direction, § 65 Abs. 11 bars parallel BSIG and GDPR fines for the same conduct, though where an incident is also a data breach that boundary is contested.

The enforcer is the BSI (Bundesamt für Sicherheit in der Informationstechnik) in Bonn, acting as both supervisor and fining authority under § 59, with energy-sector supervision partly routed through the EnWG and the BNetzA. Supervision runs on two tracks. Particularly important entities face proactive oversight, including unannounced audits and information requests without cause, while important entities are supervised only on concrete suspicion or after a reported incident. As a last resort, § 61 lets the BSI temporarily ban a particularly important entity from providing its critical services.

Managing Directors Are Liable to Their Own Company With Their Personal Assets

Yes, directors can be held personally liable under NIS2 in Germany. § 38 BSIG requires the Geschäftsleitung (management body) to approve and oversee the § 30 risk management measures, and makes managers liable to their own company for damage caused by breaching that duty. In our assessment this paragraph, not the fine schedule, is what should reach the board agenda, because it converts a corporate compliance question into a personal balance-sheet question.

The duty is broad and non-delegable. The BSI reads “management body” to include managing directors, board members, CFOs and general partners, though in a two-tier board only the executive Vorstand is captured. Operational execution can be delegated to a CISO. The oversight duty cannot. One drafting oddity matters here. The enacted text says management must “implement” (umsetzen) the measures, which Morrison Foerster flags as a likely editorial error since the explanatory memorandum speaks only of approval, but until corrected the stricter word is the one in the statute. The § 30 measures themselves track the directive’s Article 21 baseline, which we cover in the NIS2 requirements guide.

The liability itself runs through corporate law. Managers are liable to the entity under the rules for its legal form, § 93 AktG for an AG, § 43 GmbHG for a GmbH, with the BSIG as a fallback only where no such rule exists. § 38 Abs. 3 adds a personal training duty, per the explanatory memorandum at least every three years, and the managing director attends personally rather than sending the CISO.

Whether the company can waive these claims is genuinely unsettled. ISiCO notes the express statutory waiver ban in earlier drafts was dropped from the final text, so waivers may be permissible in principle, with effectiveness left to case law. Several other advisers counter that general corporate-law limits still apply, under which a waiver is typically possible only around three years after the claim arises, by shareholder resolution, and an up-front blanket waiver does not protect the manager. The practical read is the same either way. Do not build a personal risk position on a waiver. D&O cover is no safer a foundation, since many policies exclude cyber or gross negligence, and techplustrends notes that German rules prohibit a company reimbursing a manager’s personal administrative fine arising from gross negligence.

Germany Stayed Off the July 2026 CJEU Referral List

No, Germany is not being taken to the EU Court of Justice over NIS2. On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the CJEU for failing to transpose, seeking lump sums plus daily penalty payments. Germany avoided the referral precisely because it completed transposition in December 2025. The laggard narrative had a long run, but it ended with the December law.

Germany was in the infringement pipeline before that, with a letter of formal notice on 28 November 2024 and a reasoned opinion on 7 May 2025 as one of 19 member states. The December law closed that chapter. We track the four referred states in our analysis of the NIS2 CJEU referral. A caveat for anyone planning a multi-year compliance build. Brussels is separately proposing to simplify NIS2 incident reporting through the Digital Omnibus package, routing notifications through a single ENISA-run entry point, but the proposal leaves entity scope and the risk management duties untouched. Nothing about the BSIG obligations already in force changes.

Late Registration Beats Continued Default

The work splits into five pieces, each with a date or threshold attached.

  1. The scope question comes first, against the 50-employee and €10 million thresholds and the 18 sectors, then the German tier on top. The NIS2 Checker covers the sector and size logic, and the outcome determines the fine tier and supervision track.
  2. If in scope and unregistered, register. The reported toleration runs to 31 July 2026, and unregistered entities sit in a standalone €500,000 fine tier. The MUK account and ELSTER certificate come first and take time.
  3. § 38 belongs on the next management agenda, as documented approval of the § 30 measures, an oversight routine, and training booked for every member of the Geschäftsleitung, personally.
  4. Have a broker read the D&O policy against cyber exclusions and fine-reimbursement clauses, given the unsettled waiver position.
  5. Companies operating critical installations sit on the KRITIS-Dachgesetz track as well, with its own BBK registration deadline of 17 July 2026.

Where the work exceeds what an internal team can carry, our directory lists NIS2 providers in Germany.

RegDossier

Making EU compliance almost enjoyable. Almost.

EU regulatory updates in your inbox every two weeks. Free.

Get the next briefing

Similar Posts