12 March 2026 Update - The transposition of NIS 2 in Germany
Germany has not yet completed the formal transposition of Directive (EU) 2022/2555 into its national legal order.
Although the legislative process has advanced considerably and draft legislation has been developed, the German implementing statute has not yet been enacted. Germany remains in a transitional phase in which the existing cybersecurity regulatory framework continues to apply pending the adoption of the new legislative package commonly referred to as the NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG).
The NIS 2 Directive required Member States to adopt and publish national implementing legislation by 17 October 2024. Germany did not meet this deadline. As a result, the European Commission initiated infringement proceedings against Germany and several other Member States for failure to notify the complete transposition of the directive.
On 28 November 2024, the Commission issued a letter of formal notice to Germany for failure to transpose the directive within the prescribed deadline. Subsequently, on 7 May 2025, the Commission escalated the procedure by issuing a reasoned opinion, requiring Germany to complete the legislative process within a specified period or face potential referral to the Court of Justice of the European Union.
The German government responded by preparing a comprehensive legislative reform known as the NIS-2-Umsetzungsgesetz (NIS2UmsuCG). This legislative package is designed to transpose the directive primarily through extensive amendments to the BSI Act, while also modifying numerous other statutory instruments relating to cybersecurity governance and critical infrastructure protection.
The draft law was adopted by the Federal Cabinet and subsequently introduced into the parliamentary legislative process. The proposal aims to align German cybersecurity law with the structural requirements of the NIS 2 Directive, particularly with respect to the expanded scope of regulated sectors and the strengthened supervisory framework. The proposed reform represents one of the most significant changes to German cybersecurity law since the adoption of the IT-Security Act 2.0.
A central feature of the proposed legislation is the substantial expansion of the population of regulated entities. Under the earlier NIS-based framework, approximately two thousand operators of critical infrastructure and digital service providers were subject to cybersecurity supervision. Under the NIS 2 framework, this number is expected to increase dramatically.
Current estimates suggest that between 25 000 and 30 000 organizations in Germany will fall within the scope of the new regulatory framework once the legislation enters into force. These entities will include organizations operating in sectors such as energy, transport, health, digital infrastructure, public administration, financial market infrastructure, and several manufacturing sectors.
The legislation adopts the classification system introduced by the NIS 2 Directive, distinguishing between essential entities and important entities. Essential entities will be subject to a more intensive supervisory regime, including proactive audits and inspections by regulatory authorities, whereas important entities will generally be subject to reactive supervision.
The proposed German legislation introduces explicit obligations for members of the management body to oversee cybersecurity governance and risk management measures. This shift reflects the broader regulatory philosophy of the NIS 2 Directive, which treats cybersecurity as an element of corporate governance rather than merely a technical operational matter.
The proposed reform preserves the central role of the Federal Office for Information Security (BSI) as the primary supervisory authority responsible for cybersecurity governance at the federal level. The BSI will continue to function as the national cybersecurity authority, the national single point of contact within the European cybersecurity cooperation framework, and the central authority responsible for coordinating incident response and threat intelligence. The reform also strengthens the supervisory powers of the BSI, including the authority to conduct inspections, require corrective measures, and impose administrative penalties in cases of non-compliance.
Once the legislation has been enacted and promulgated in the Federal Law Gazette, the government must adopt a series of implementing regulations specifying the technical and procedural requirements applicable to regulated entities.
The regulatory authorities will need to identify and register the organizations falling within the scope of the new framework. This process is expected to significantly expand the supervisory responsibilities of the Federal Office for Information Security.
Our remarks about the delay for the transposition of NIS 2 in Germany
Germany’s transposition of the NIS 2 Directive is one of the most complex in the European Union. Germany already possesses one of the most mature cybersecurity regulatory frameworks in Europe. The complexity stems from the need to integrate a new European regulatory architecture into a dense and highly structured national legal system that already regulates cybersecurity through multiple overlapping statutes, regulatory authorities, and sectoral regimes.
Germany has already developed a sophisticated cybersecurity regime over several legislative cycles. The foundation of this regime is the Act on the Federal Office for Information Security (BSI-Gesetz), which has been amended repeatedly, most notably by the IT-Security Act (2015) and the IT-Security Act 2.0 (2021). These reforms introduced extensive cybersecurity obligations for operators of critical infrastructure, digital service providers, and so-called “companies of special public interest.” As a result, the German cybersecurity regulatory landscape already contained detailed definitions, reporting obligations, and supervisory powers before the adoption of NIS 2. Transposing the directive requires reconciling the directive’s regulatory concepts with an existing and highly developed legal framework.
Under the existing German framework, roughly two thousand operators of critical infrastructure were subject to cybersecurity supervision by the Federal Office for Information Security (BSI). The NIS 2 Directive expands the regulatory perimeter dramatically. Estimates suggest that between twenty-five thousand and thirty thousand organisations in Germany may fall within the scope of the new regime once it is fully implemented. This enormous increase in regulated entities requires a fundamental reconfiguration of the supervisory architecture. The BSI must be equipped to oversee a regulatory population more than ten times larger than under the previous regime, which requires adjustments to administrative procedures, supervisory practices, and enforcement mechanisms.
Germany’s constitutional system distributes regulatory authority between the federal government and the Länder (federal states). Although cybersecurity policy is largely coordinated at the federal level, many sectors subject to the NIS 2 Directive fall under regulatory regimes administered by state authorities or sectoral regulators. This creates the need to carefully delineate the competences of the Federal Office for Information Security, sector regulators, and regional authorities. Legislative drafting must therefore take into account constitutional constraints and administrative competences in order to avoid jurisdictional conflicts within the federal system.
In Germany, cybersecurity regulation intersects with several other complex areas of law, including critical infrastructure protection, telecommunications regulation, financial supervision, and public-sector information security. The NIS 2 Directive overlaps with other European regulatory instruments, like the Digital Operational Resilience Act (DORA) and the Critical Entities Resilience (CER) Directive. German lawmakers must therefore ensure that the national implementing legislation avoids duplication or regulatory conflicts between these frameworks. This requires careful legislative coordination across multiple ministries and regulatory authorities.
The NIS 2 Directive significantly strengthens the role of national cybersecurity authorities and introduces a more demanding supervisory framework. In Germany this means expanding the regulatory powers of the Federal Office for Information Security while also redefining its relationship with sector regulators and other federal agencies. The institutional consequences of these reforms require adjustments to administrative structures and operational procedures.
Germany faces the challenge of integrating the directive’s governance based approach to cybersecurity risk management into its corporate regulatory environment. The NIS 2 Directive places substantial responsibility on the management bodies of regulated entities, requiring them to oversee cybersecurity risk management and ensure compliance with security obligations. Translating these governance requirements into German corporate law and regulatory practice requires careful legal drafting and coordination with existing frameworks governing corporate responsibility and risk management.
Taken together, these factors explain why the German implementation of the NIS 2 Directive has proven particularly complex. Germany must transpose a far reaching European cybersecurity directive, and must reconcile it with an already sophisticated national regulatory system, a federal administrative structure, and multiple overlapping regulatory regimes. The result is a legislative process that is significantly more demanding than in Member States with simpler cybersecurity legal frameworks.
The German case illustrates a broader regulatory phenomenon. The more advanced and institutionalized a national regulatory system becomes, the more complex the process of integrating new supranational legislation into that system tends to be.
Germany – NIS 2 Directive Implementation.
1. National strategy on the security of network and information systems.
This strategy outlines Germany’s national framework for cybersecurity governance, resilience, and protection of network and information systems.
2. Single point of contact.
Federal Office for Information Security (BSI) - Bundesamt für Sicherheit in der Informationstechnik)
Address: Godesberger Allee 185–189, 53175 Bonn, Germany
Contact: Email: lagezentrum@bsi.bund.de
Phone: +49 228 99 9582-5110
3. National competent authority for DSPs.
Federal Office for Information Security (BSI) - (Bundesamt für Sicherheit in der Informationstechnik)
Contact: Email: lagezentrum@bsi.bund.de
Phone: +49 228 99 9582-5110
Address: Godesberger Allee 185–189, 53175 Bonn, Germany
4. National competent authorities for OES.
Federal Office for Information Security (BSI) - (Bundesamt für Sicherheit in der Informationstechnik)
Contact: Email: lagezentrum@bsi.bund.de
Phone: +49 228 99 9582-5110
Address: Godesberger Allee 185–189, 53175 Bonn, Germany
5. National CSIRT.
BSI Computer Emergency Response Team (CERT-Bund)
Contact: Email: lagezentrum@bsi.bund.de
Phone: +49 228 99 9582-5110
Address: Federal Office for Information Security (BSI), Godesberger Allee 185–189, 53175 Bonn, Germany
EU - Transposition, Member States