Don’t do SECURITY. Do business SECURELY.

Germany’s NIS2 Implementation Act comes into force

Germany’s NIS2 Implementation Act takes effect, significantly expanding the number of organisations subject to cyber security duties.

Germany’s NIS2 Implementation Act comes into force today, amending the BSI Act and extending cyber security obligations to many more organisations.

Key points

  • Applies generally to organisations with 50 or more employees or €10m or more turnover in listed sectors.
  • Entities must register with the Federal Office for Information Security (BSI).
  • Risk management measures and incident reporting duties apply.
  • Management bodies are responsible for approving and overseeing cyber security measures.

UK organisations with German subsidiaries, or supplying in-scope German entities, should confirm whether they are covered and prepare for supply chain security requests.

Source: NIS2UmsuCG, BGBl. 2025 I Nr. 301 (Bundesgesetzblatt)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights